// 4 ZERO-DAY · 6 CVE · 9 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
The SANS FOR577 course integrated two Python scripts into its Day 5 material on October 8, 2026, for forensic analysis of residues left by AI coding agents. Released by instructor Jim Clausing, the tools extract data from OpenCode and Hermes SQLite databases and log files without altering original evidence. This marks the first time an incident response training framework systematically addresses the traceability of actions performed by autonomous AI agents on developer workstations.

The SANS FOR577 course integrated two Python scripts into its Day 5 material on October 8, 2026, for forensic analysis of residues left by AI coding agents. The tools, released by course instructor Jim Clausing, extract data from the SQLite databases and log files of OpenCode and Hermes without altering the original evidence. This is the first time an incident response training framework has systematically addressed the traceability of actions performed by autonomous AI agents on developer workstations.

Key Takeaways
  • Clausing published opencode-chat-replay.py and hermes_forensic_extract.py to the clausing/scripts GitHub repository.
  • Both scripts create a temporary snapshot of the SQLite database, including -wal and -shm files, before analysis, preserving the original evidence.
  • The first tool reconstructs chat sessions, tool calls, and API payloads from the OpenCode database; the second extracts data from three distinct Hermes sources: state.db, request_dump_*.json, and application logs.
  • The scripts require Python 3.10 or later and use only the standard library, eliminating external dependencies.
  • The updated course covers 8 AI coding agents: Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code.

The Paradox of Forensic Self-Generation

Clausing made explicit an aspect that complicates the technical reading of these tools. The AI agents themselves generated the code now used to investigate them. "I absolutely had OpenCode write the opencode script and Hermes wrote the hermes script," he wrote in the SANS Internet Storm Center post. This self-generation mechanism introduces an unquantifiable variable into the dossier: the traceability of the source code back to the generative agent, rather than to a traditional human author.

The difference between the two scripts, the author notes, stems directly from this heterogeneous provenance. OpenCode structured its own tool with a flexible output renderer supporting Markdown, JSON, and JSONL, with a default cap of 2,000 characters for tool call content. Hermes instead produced an extractor oriented toward JSON Lines with an _extraction_type field for record categorization.

"These are forensic review tools, not tools for running or replaying an agent's actions"
— Jim Clausing, SANS ISC Diary

What the Scripts Extract from the Filesystem

opencode-chat-replay.py interrogates the path ~/.local/share/opencode/opencode.db, adapting to two relational schemas: the legacy structure with separate message and part tables, and the consolidated session_message table introduced in newer versions. The output reconstructs the chronological sequence of user requests, model responses, and tool invocations with their respective payloads.

hermes_forensic_extract.py operates on three distinct surfaces: the SQLite database ~/.hermes/state.db, request dump files ~/.hermes/sessions/request_dump_*.json, and text logs ~/.hermes/logs/*.log. The combination of these three sources allows correlation of the agent's internal state with network traces and application events.

Both scripts implement the snapshot_db function, which copies the database and associated files to a temporary directory before opening. The mechanism is read-only with respect to the original evidence: the source database is never opened in a mode that would alter its journal or WAL.

Immediate Actions for Analysts

Analysts managing workstations with installed AI agents must verify the presence of the paths ~/.local/share/opencode/opencode.db and ~/.hermes/state.db in acquired forensic images. These files represent primary evidence sources that risk being overwritten or ignored if not explicitly included in collection procedures.

For analysis, Python 3.10 or later is required. The scripts require no external dependency installation: simply download the files from the clausing/scripts repository and run them on the working copy. The --max-tool-output 0 parameter removes the 2,000-character cap in opencode-chat-replay.py, useful when tool call payloads exceed the default threshold.

The JSONL/NDJSON format of hermes_forensic_extract.py, with the _extraction_type field, lends itself to import into structured analysis tools like jq or SIEM platforms that support JSON Lines parsing. The Markdown output of opencode-chat-replay.py is optimal for human-readable reports to include in investigation documentation.

The snapshot_db function must be considered a minimum requirement, not optional: even on filesystems with active journaling, opening the SQLite database in standard mode can alter the -wal and -shm files, compromising the temporal integrity of the evidence.

FOR577 Course Context and Limitations

The new Day 5 content in FOR577 covers 8 AI coding agents: Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code, in addition to the two with specific scripts. The decision to focus forensic work on OpenCode and Hermes reflects their integration into the teaching material, but the dossier does not quantify their prevalence relative to the other six.

The brief does not surface documented use cases of these scripts in real investigations. Their nature is explicitly educational and experimental. Likewise, the exact commit dates in the GitHub repository are not attested in the SANS post, other than by inference from the 20261008 temporal reference.

Frequently Asked Questions

Can the scripts be used in court as evidence?

The dossier does not address the legal validity of the tools. The read-only snapshot mechanism handles the technical chain of custody, but the source does not cite forensic validation processes or laboratory certifications.

Why only Python 3.10+?

According to the SANS post, the choice stems from the use of standard library features that require that minimum version. The specific APIs imposing this constraint are not specified.

Do other AI agents leave similar traces?

FOR577 covers 8 agents beyond OpenCode and Hermes, but the dossier does not indicate whether equivalent extraction tools exist for them or if their storage formats are publicly documented.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. isc.sans.edu
  2. github.com