SANS Releases New Forensic Scripts to Reconstruct AI Coding Assistant Activity
SANS added two open‑source scripts that locate chat histories and logs from popular AI coding assistants, giving responders a way to audit AI‑generated code. This matters because continuous AI‑usage monitoring is a core control objective for AI‑risk frameworks.
ADTP Breach Watch· October 8, 2026· SANS Internet Storm Center
SeverityInformational
Type📧 Advisory
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaSTechnology and SaaS developersEnterprises integrating AI coding assistantsUnknown
What happened
The SANS Internet Storm Center updated its FOR577 training material with two scripts that automatically gather artefacts (chat histories, prompt logs, configuration files) from eight widely used AI coding assistants. The scripts are intended for use in incident‑response investigations to surface AI‑related evidence.
Why it matters for trust and compliance
The release underscores the control objective of continuously monitoring AI system usage and retaining auditable logs, a requirement for AI‑governance frameworks such as NIST AI RMF and ISO/IEC 42001.
Enables continuous evidence collection for AI‑usage controls, supporting audit readiness.
Helps map AI artefact collection to governance objectives across multiple frameworks.
Who is affected
Technology and SaaS developersEnterprises integrating AI coding assistants
Recommended actions
Integrate the scripts into your incident‑response playbook and map collected artefacts to AI‑governance controls.
Validate that existing logging covers the same data points the scripts surface.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.