Definition
The practice of investigating a laptop or device after a break-in to find traces left behind specifically by AI coding assistants — such as saved conversation logs, cached login tokens, and memory files — which attackers can steal to impersonate developers or access connected systems. Until recently, security teams had no standard tools built for this specific evidence class.
Why it matters
AI coding assistants now hold as much sensitive access as a developer's own accounts, so a breach investigation that ignores 'AI agent leftovers' will miss a major theft vector and may under-report the true scope of a compromise.