Skip to content

Agent Archaeology

Reconstruct what AI agents saw, decided, and did.
A practical field manual for agentic events, tool use, conversations, sessions, traces, and evidence.

Why Agent Archaeology?

Agents now leave evidence across the whole workspace.

AI agents now operate across editors, terminals, browsers, filesystems, APIs, and internal tools. Their work can be useful, surprising, or risky. When an agentic event matters, teams need a practical way to reconstruct what happened: the prompt, the context, the tools, the actions, the outputs, and the evidence left behind.

What is an agentic event?

An agentic event is a bounded sequence where an AI agent receives context, makes choices, invokes tools or produces instructions, and leaves artifacts that can be preserved and reviewed.

Agent Evidence Sources

Telltale and the field manual focus on the agents that leave forensic evidence in session stores, tool logs, and workspace artifacts.

9
Supported Agents

Codex, OpenCode, Claude Code, Copilot, Gemini CLI, and more

13
Detection Categories

Secret access, execution, exfiltration, MCP injection, supply chain, and more

9
Detection & Telemetry Guides

Install, validation, inventory, rules, telemetry, schemas, and playbooks

8
Field Manuals

Traces, tools, MCP, sessions, boundaries, provenance, supply chain, glossary

Help build the knowledge base.

Contribute field notes, examples, workflows, checklists, and observations that help practitioners understand and investigate agentic systems.

Contribute Knowledge