<?xml version="1.0" encoding="UTF-8"?><ns2:project xmlns:ns1="http://gtr.rcuk.ac.uk/gtr/api" xmlns:ns2="http://gtr.rcuk.ac.uk/gtr/api/project" xmlns:ns3="http://gtr.rcuk.ac.uk/gtr/api/fund" xmlns:ns4="http://gtr.rcuk.ac.uk/gtr/api/person" xmlns:ns5="http://gtr.rcuk.ac.uk/gtr/api/project/outcome" xmlns:ns6="http://gtr.rcuk.ac.uk/gtr/api/organisation" ns1:created="2026-07-08T08:44:08Z" ns1:href="http://gtr.ukri.org/gtr/api/projects/4831233E-E032-4729-95CE-A0DEB8378BC4" ns1:id="4831233E-E032-4729-95CE-A0DEB8378BC4"><ns1:links><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/persons/323956EC-0FB0-4D9E-BB25-9096C815CCA9" ns1:rel="PM_PER"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/4B1CFB07-8BD4-4246-8CC3-E97ED78BF079" ns1:rel="LEAD_ORG"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/4B1CFB07-8BD4-4246-8CC3-E97ED78BF079" ns1:rel="PARTICIPANT_ORG"/><ns1:link ns1:end="2025-07-30T23:00:00Z" ns1:href="http://gtr.ukri.org/gtr/api/funds/C01B171A-E085-4A64-B051-910CA6E2971A" ns1:rel="FUND" ns1:start="2025-03-31T23:00:00Z"/></ns1:links><ns2:identifiers><ns2:identifier ns2:type="RCUK">10157810</ns2:identifier></ns2:identifiers><ns2:title>EXIRAI: Evidence Extraction for Incident Response through Generative and Agentic AI</ns2:title><ns2:status>Closed</ns2:status><ns2:grantCategory>Collaborative R&amp;D</ns2:grantCategory><ns2:leadFunder>Innovate UK</ns2:leadFunder><ns2:abstractText>UK businesses have lost &amp;pound;44 billion over the past five years to undetected cybercrime, compliance failures, and delays in evidence analysis. Beyond the financial impact, these inefficiencies erode trust in investigative outcomes, with critical evidence often overlooked or misinterpreted. To eradicate threats and process evidence promptly, robust incident response practices are essential, but these require advanced expertise. Effective resolution depends on the precise handling of artefacts, systematic analysis, and the extraction of relevant evidence to support investigative claims. Unfortunately, current solutions rely on fragmented tools, lacking the contextual awareness needed to interpret evidence holistically, leaving investigations vulnerable to gaps and delays.

This project aims to develop a desktop application that empowers investigators and security teams by automating the processing of evidence during an investigation. The application allows for the rapid identification of critical evidence across both structured and unstructured data (emails, documents, and transaction records) using GenAI-driven techniques. Designed for simplicity, it supports both novice and expert users, bridging gaps in technical expertise and accelerating investigative workflows.

Built on an innovative framework that combines semantic analysis, anomaly detection, adaptive automation, and evidence-augmented retrieval, it simulates investigative scenarios to reveal high-risk insights and reduce investigation times from weeks to just minuted while significantly lowering operational costs. Beyond financial savings, it also tackles broader issues impacting individuals and society, playing a key role in restoring stakeholder trust in a world facing growing cyber risks.</ns2:abstractText></ns2:project>