incident response agents

20 tagged incident response, measured the same way as everything else here.

Browse within: dfir 13digital-forensics 13forensics 13

DeepBitsTechnology/claude-plugins

Agent

Detects and analyzes system threats, malware, and security vulnerabilities on Windows systems. Use for system scanning, browser hijacking detection, Windows registry analysis, suspicious file investigation, binary analysis, and threat reporting with remediation steps.

46 1mo ago A 51 tokens original Apache-2.0

devops-agent

02

CorpusIQ/corpusiq-docs

Agent

Deploy an autonomous DevOps/SRE agent for infrastructure health checks, deployment monitoring, incident response, log analysis, and cost optimization. Complete Hermes blueprint.

18 yesterday A 30 tokens

kevinmhorvath/threat-intel-toolkit

Agent

Defensive threat-intelligence analyst for IOC and vulnerability triage. Use PROACTIVELY whenever the user drops one or more indicators — an IP, domain, URL, or CVE — and wants to know if it's malicious, who's flagging it, how weaponized a CVE is, or how to prioritize it. Also use to build or refresh a local blocklist…

5 13d ago A 171 tokens

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively after all artifact agents complete and before generatereport. Takes all findings from state.json and stress-tests each one against other artifact sources to confirm, escalate, demote, or dismiss. Applies evidence corroboration chains, stacked anomaly validation, and temporal proximity analysis. Returns…

4 2mo ago A 75 tokens original MIT

evtx-analyst

05

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when summarizeevtx returns a csvpath for Security.evtx, System.evtx, or Sysmon logs. Windows event log forensic specialist covering the full attacker lifecycle - authentication anomalies, lateral movement, credential theft, persistence, defense evasion, and NTLM/Kerberos attacks. Returns condensed…

4 2mo ago A 84 tokens original MIT

sigma-analyst

06

kismatkunwar89/SAVVYDFIR-MCP

Agent Claude Code

Use proactively when sigmahunt returns findingscreated. Chainsaw/Sigma threat detection specialist - validates ATT&CK technique attribution, reduces false positives, correlates Sigma hits with disk/memory/registry findings, and reconstructs the attack timeline from rule-confirmed evidence. Returns condensed…

4 2mo ago A 72 tokens original MIT