Luduan
LUDUAN is an LLM-powered digital forensics agent that autonomously plans investigations, operates forensic tools, analyzes evidence, and validates findings across heterogeneous data sources.
LUDUAN
LUDUAN is an LLM-powered autonomous agent designed for digital forensics and electronic evidence investigation.
Rather than simply placing a language model in front of a collection of forensic tools, LUDUAN is built to let an agent participate in the investigation itself: understanding the objective, observing the environment, planning the next action, operating tools, analyzing results, discovering new leads, and validating conclusions against evidence.
Investigate farther. Observe deeper. Understand more.
Why LUDUAN
Digital investigations rarely depend on a single tool.
Investigators constantly move between filesystems, databases, logs, applications, operating systems, binary artifacts, remote hosts, and specialized forensic utilities.
The difficult part is often not executing a command, but deciding:
- what should be examined next;
- what an observation actually means;
- which artifact is worth following;
- how evidence from different sources is connected;
- and whether a conclusion is sufficiently supported.
LUDUAN approaches this problem as a continuous agent-driven investigation.
Given an investigation objective and available evidence, the agent dynamically decides what to examine next based on the current environment and previously collected findings instead of following a completely predefined script.
Core Capabilities
Autonomous Investigation
LUDUAN operates through an iterative investigation loop:
Observe → Analyze → Plan → Act → Collect Evidence → Verify → Re-plan
The investigation path evolves as new evidence is discovered.
Multi-source Forensics
LUDUAN is designed to investigate heterogeneous digital evidence, including:
- filesystems and disk data;
- Windows and Linux environments;
- SQLite and other databases;
- Android applications and application data;
- logs and configuration files;
- binary artifacts;
- network traffic;
- servers and remote environments;
- mobile and other electronic evidence.
Evidence from different sources can be brought into the same investigation context and correlated by the agent.
Tool-driven Agent
Forensic utilities are exposed as capabilities available to the agent.
Instead of requiring the user to manually execute every step, LUDUAN can select and combine filesystem operations, search, database queries, shell commands, reverse-engineering utilities, and other specialized capabilities according to the investigation state.
Tool outputs then become observations for subsequent reasoning.
Evidence-first Reasoning
LUDUAN is designed around evidence rather than model output alone.
During an investigation it can preserve structured information such as:
- Observations
- Facts
- Evidence
- Candidates
- Action History
- Verification Results
A final finding should be traceable back to actual artifacts and investigation actions rather than existing only as an LLM-generated statement.
Dynamic Investigation
Real investigations are rarely linear.
A file may lead to a database. A configuration entry may reveal another directory. A log record may completely change the direction of the investigation.
LUDUAN continuously updates its investigation state as new observations and evidence become available, allowing the agent to navigate previously unknown environments.
Verification
A hypothesis generated by an LLM is not evidence.
LUDUAN separates candidate discovery from final verification and uses underlying artifacts, tool outputs, and deterministic checks wherever possible to reduce the impact of hallucinations on forensic conclusions.
Use Cases
LUDUAN can be used for:
- Digital Forensics
- Digital Investigation
- Server Forensics
- Mobile Application Analysis
- APK Analysis
- Filesystem and Database Investigation
- Log Analysis
- CTF / Forensics
- Forensics Education
- AI + DFIR Research
Philosophy
The central question behind LUDUAN is not:
Can an AI answer a forensic question?
It is:
Can an AI investigate an unfamiliar environment, discover the necessary evidence by itself, and demonstrate why its conclusion is correct?
For this reason, the core of LUDUAN is not a chat interface.
It is an agent runtime built around Environment, Tools, Evidence, State, Planning, and Verification.
The long-term goal is to move AI in digital forensics beyond question answering and toward agents that can meaningfully participate in real investigation workflows.
The Name
LUDUAN (甪端) is a legendary creature from ancient Chinese mythology, traditionally described as capable of traveling immense distances and understanding languages and matters from distant places.
The name represents three ideas behind the project:
Explore farther · Observe deeper · Understand broadly
LUDUAN — Digital Forensics Agent
https://luduan.digiforensics.cn