Skip to main content
ArchWiz includes a dedicated forensic toolchain for tracing where code came from, assessing the impact of a change before you make it, and recovering lost implementations. This guide walks you through a complete forensic investigation using the provenance and restoration tools available in the monorepo.
1

Research file history with archaeo

Start any investigation by pulling the full history of a target file. archaeo shows commits, authors, and message summaries.
Expected output:
2

Check impact before changing with oracle

Before you edit a file, run oracle to see which other files and tests depend on it.
Expected output:
3

Run the forensic toolchain

Use forensic_toolchain.py to perform a full provenance scan. It orchestrates the fragment matcher, similarity scan, and correlation scout in one pass.
Expected output:
4

Trace file-path changes with correlation_scout

When a file has moved or been renamed, correlation_scout.py traces its path across history and links the old and new locations.
Expected output:
5

Match function-level provenance with fragment_matcher

Drill down to individual functions to see when they were introduced, modified, or copied from another file.
Expected output:
6

Resurrect lost code with restore_version

If a function or file was deleted or broken in a recent commit, use restore_version.py to recover a known-good version.
Expected output:
Always run oracle before restoring an old version. Restoring code without checking dependents can reintroduce outdated interfaces that break downstream modules.
Combine forensics with the knowledge indices for deeper reconnaissance. After running archaeo and oracle, query the index with archivist.py --file <target> --relationships to see the full dependency graph and cross-reference the historical timeline with structural impact.
For more on querying the knowledge base, see the Index rebuild guide. To understand how ArchWiz fits into the broader system, read the ArchWiz component overview.