Investigations, reports and papers. Each comes with the method, the results and what I'd do next.
Hashir Asad
Compares reading a forensic file-activity timeline from The Sleuth Kit on its own with having an open-source LLM, Falcon-7B-Instruct, interpret it. Tested against simulated malware activity, the model flagged files being suspiciously modified and encrypted, along with a suspicious new .exe and .txt file, as possible ransomware, making the threat easier to understand.