Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
老害フォレンジッカーはAI羊の夢を見るか?
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
tadmaddad
August 07, 2026
Technology
990
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
老害フォレンジッカーはAI羊の夢を見るか?
AIの悪用が現実化しつつある中、デジタルフォレンジックの観点からAI Artifactの調査可能性を紹介したLT資料です。
tadmaddad
August 07, 2026
Other Decks in Technology
See All in Technology
AIによるクリエイティブ生成を行う上での試行錯誤
plaidtech
PRO
0
160
「ピッケル本」日本語版は4.0(第6版)が出版されるべき / pickaxe4-nagoyark05
kakutani
2
180
Claude in Chrome 入門 / Introduction to Claude in Chrome
cielo1985
0
860
Reactの設計論
uhyo
24
14k
SREは、MCPとAutopilotをこう使え!
kazumax55
3
890
The Knowledge Spine: A Machine-Executable Ontology for Governed Marketing Activation
vananth22
0
100
AI時代の「技術的負債」の変質ー概念の終焉と再解釈、エージェントと共に向かう先
nwiizo
1
2.9k
アプリログインとWeb認証基盤をつなぐ ASWebAuthenticationSession 作法
shimastripe
1
340
AI に書かせたその API、 “信頼” できますか?
nagix
0
120
ユーザー価値を届け続けるためにウォンテッドリーが大切にしている文化
kotaminato
0
180
aws-iot-platform-architecture-use-cases.pdf
ma2shita
0
310
LTのテーマ どうきめてる?〜5つの型と私のやり方〜
yama3133
1
110
Featured
See All Featured
HDC tutorial
michielstock
2
870
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
550
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
290
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
The agentic SEO stack - context over prompts
schlessera
0
940
Are puppies a ranking factor?
jonoalderson
2
3.9k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.6k
Testing 201, or: Great Expectations
jmmastey
46
8.3k
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
890
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
280
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
360
30k
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
3.7k
Transcript
老害フォレンジッカーは AI羊の夢を見るか? 既に悪用が始まっているAI、その痕跡を誰が追うのか @tadmaddad
既に悪用が始まっているAI Everyone uses AI. Who investigates it?
AI時代のインシデント対応は変わるのか? - Hugging Face侵害(2026) - <攻撃側> • GPT-5.6 Sol •
Pre-release Model • 数万回規模の自動アクション ↓ <調査側> • 17,000+ Events • AIによるフォレンジック分析 • GLM-5.2(Open Weight) 出典:Hugging Face - “Anatomy of a frontier-lab agent intrusion” (2026)
もし、 うちのAIが やらかしたら? Who prompted it? What did it do?
Where is the evidence? どのアーティファクトを調べますか?
AIも結局、Artifactを残す Browser History Local Storage Local Endpoint Prefetch AI Platform
AI Artifact Amcache history.jsonl Network .claude paste - cache Enterprise Systems … Generated Content
AI Agent Artifact 例 ※ 例は、Claude Codeのプロンプト履歴(%USERPROFILE%¥.claude¥history.jsonl)を再現したもの。
Claude Codeにおける「.claude」ディレクトリ構成 %USERPROFILE¥.claude history.jsonl すべてのプロンプト入力履歴 paste-cache / image-cache 大容量の貼り付けテキストや画像のキャッシュ file-history
変更前のファイルのバックアップ(スナップショット) ※上記は、調査に有用なアーティファクト例
history.jsonlの構造 履歴例(1) 通常の履歴 {"display":"TODOアプリを作ってください。 ", "pastedContents":{}, "timestamp":1768701527321, "project":"C:¥¥projectTODO", "sessionId":“b6f87447-97a9-4b1a-9629-134ca07a1b24"} ユーザが入力したプロンプト
プロンプト入力日時(UNIX Time) プロジェクトの作業パス プロジェクトのセッションID
history.jsonlの構造 履歴例(2) 文字列貼り付けがあった場合 ユーザが貼り付けを行った場合 {"display":"[Pasted text #1 +12 lines]", "pastedContents":{"1":
{"id":1,"type":"text","content":"ここには色々書かれているが上限が何バイトかは不明。"}}, "timestamp":1774254722391, "project":"C:¥¥projectTODO", ユーザが貼り付けた内容 "sessionId":"9f11122b-51c3-4b86-b297-82dcae1ca285"}
history.jsonlのファイル構造 履歴例(3) 制限を超えた文字列貼り付けがあった場合 ユーザが貼り付けを行った場合 {"display":"[Pasted text #1 +69 lines]", "pastedContents":{"1":
{"id":1,"type":"text","contentHash":"24a23645c705f34e"}}, "timestamp":1774256872304, "project":"C:¥¥"projectTODO” ユーザが貼り付けた内容が保存さ sessionId":"9f12121b-51c3-4b86-b287-82dcae1ca285"} れたファイル名(ハッシュ値) ※この例では、paste-cacheフォルダ配 下に<ハッシュ値>.txtが作成される。
file-historyのディレクトリ構成 %USERPROFILE¥.claude file-history history.jsonlのセッションIdと 紐づく 9f01121b-51c3-4b86-b197-82dcae1ca285 2a396e91647521de@v1 スナップショット 2a396e91647521de@v2
アーティファクト収集ツール Washizukami-Collectorでの収集 artifacts: - name: "Claude Code history.jsonl" category: "AI
Tools" target_path: '%USERPROFILE%¥.claude¥history.jsonl' method: NTFS - name: "Claude Code paste-cache" category: "AI Tools" target_path: '%USERPROFILE%¥.claude¥paste-cache¥*' method: NTFS - name: "Claude Code image-cache" category: "AI Tools" target_path: '%USERPROFILE%¥.claude¥image-cache¥*' method: NTFS - name: "Claude Code file-history" category: "AI Tools" target_path: '%USERPROFILE%¥.claude¥file-history¥*' method: NTFS Washizukami(鷲掴) は、Rust で実装された Windows 向けのファストフォレンジック証拠収集ツールです。 https://github.com/tadmaddad/Washizukami-Collector