dfir agents

20 tagged dfir, measured the same way as everything else here.

Browse within: digital-forensics 13forensics 13incident-response 13code 7scripts 7

TazWake/Public

Agent Claude Code

Use this agent when working with Docker, Kubernetes, or any container-related tasks including building Dockerfiles, creating docker-compose configurations, troubleshooting container deployments, optimizing container performance, designing container architectures, or needing guidance on containerization best practices.…

44 12d ago A 250 tokens original CC0-1.0

TazWake/Public

Agent Claude Code

Use this agent when you need to plan, organize, or manage cybersecurity projects and changes. This includes creating project plans, developing documentation, establishing build processes, validating deliverables, and ensuring task completion. Examples: Context: User needs to plan the implementation of a new security…

44 12d ago A 232 tokens original CC0-1.0

TazWake/Public

Agent Claude Code

Use this agent when creating, modifying, or enhancing digital forensic tools, incident response scripts, memory analysis plugins, evidence collection utilities, or any DFIR-related automation. Examples: Context: User is developing a new Volatility plugin for detecting process hollowing. user: 'I need to create a…

44 12d ago A 243 tokens original CC0-1.0

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively after all artifact agents complete and before generatereport. Takes all findings from state.json and stress-tests each one against other artifact sources to confirm, escalate, demote, or dismiss. Applies evidence corroboration chains, stacked anomaly validation, and temporal proximity analysis. Returns…

4 2mo ago A 75 tokens original MIT

evtx-analyst

05

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when summarizeevtx returns a csvpath for Security.evtx, System.evtx, or Sysmon logs. Windows event log forensic specialist covering the full attacker lifecycle - authentication anomalies, lateral movement, credential theft, persistence, defense evasion, and NTLM/Kerberos attacks. Returns condensed…

4 2mo ago A 84 tokens original MIT

sigma-analyst

06

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when sigmahunt returns findingscreated. Chainsaw/Sigma threat detection specialist - validates ATT&CK technique attribution, reduces false positives, correlates Sigma hits with disk/memory/registry findings, and reconstructs the attack timeline from rule-confirmed evidence. Returns condensed…

4 2mo ago A 72 tokens original MIT