digital forensics agents

13 tagged digital forensics, measured the same way as everything else here.

Browse within: dfir 13forensics 13incident-response 13

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively after all artifact agents complete and before generatereport. Takes all findings from state.json and stress-tests each one against other artifact sources to confirm, escalate, demote, or dismiss. Applies evidence corroboration chains, stacked anomaly validation, and temporal proximity analysis. Returns…

4 2mo ago A 75 tokens original MIT

evtx-analyst

02

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when summarizeevtx returns a csvpath for Security.evtx, System.evtx, or Sysmon logs. Windows event log forensic specialist covering the full attacker lifecycle - authentication anomalies, lateral movement, credential theft, persistence, defense evasion, and NTLM/Kerberos attacks. Returns condensed…

4 2mo ago A 84 tokens original MIT

sigma-analyst

03

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when sigmahunt returns findingscreated. Chainsaw/Sigma threat detection specialist - validates ATT&CK technique attribution, reduces false positives, correlates Sigma hits with disk/memory/registry findings, and reconstructs the attack timeline from rule-confirmed evidence. Returns condensed…

4 2mo ago A 72 tokens original MIT