dfir instructions

15 tagged dfir, measured the same way as everything else here.

Browse within: forensics 6incident-response 5

zeek AGENTS.md

01

zeek/zeek

Instructions file CodexOpenCode

AGENTS.md instructions for zeek/zeek, covering agents.md, building and running zeek, testing, security reporting and pull request (pr) submissions.

7.9k 3d ago A 303 tokens

Public AGENTS.md

02

TazWake/Public

Instructions file CodexOpenCode

Instructions for TazWake/Public, covering agents.md, repository purpose, working conventions and safety.

44 12d ago A 333 tokens original CC0-1.0

Public CLAUDE.md

03

TazWake/Public

Instructions file

Instructions for TazWake/Public, covering claude.md, environment notes, code best practices, general guidelines and bash script development.

44 12d ago B 2,612 tokens original CC0-1.0

depalmar/ai-dfir-toolkit

Instructions file

Instructions for depalmar/ai-dfir-toolkit, covering project context, what this is, commands, rules that are not negotiable and what a restricted runner cannot verify.

23 11d ago A 6,013 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Instructions file GitHub Copilot

Instructions for meltedinhex/analyst-ai-pack, covering analystaipack — github copilot instructions, how to help in this repo, safety rules (do not violate) and authoring or editing a skill.

22 1mo ago A 704 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Instructions file CodexOpenCode

Instructions for meltedinhex/analyst-ai-pack, covering agents.md — using analystaipack as an ai agent, what this repo is, how to pick a skill, how to run a skill and or directly.

22 1mo ago A 832 tokens original Apache-2.0

x746b/winforensics-mcp

Instructions file

Instructions for x746b/winforensics-mcp, covering role: windows dfir specialist, target, winforensics-mcp: orchestrators first, orchestrator parameters (always use) and investigation workflow.

20 15d ago A 3,006 tokens original MIT

sift-mcp AGENTS.md

08

AppliedIR/sift-mcp

Instructions file CodexOpenCode

Instructions for AppliedIR/sift-mcp, covering valhuntir — forensic investigation platform, getting started, available mcp servers, malware analysis escalation and investigation recording.

15 3mo ago A 2,318 tokens original MIT

Juwon1405/agentic-dart

Instructions file CodexOpenCode

Instructions for Juwon1405/agentic-dart, covering agents.md — agent guide for agentic-dart, project summary, repository map, preferred commands and full suite — every test must pass.

9 2mo ago A 1,035 tokens original MIT

Juwon1405/agentic-dart

Instructions file

Instructions for Juwon1405/agentic-dart, covering claude.md — ai assistant guide for agentic-dart, what this project is, repository map, run modes (know which one you are touching) and non-negotiables (do not break these).

9 2mo ago A 1,506 tokens original MIT

x746b/mem_forensics-mcp

Instructions file

Instructions for x746b/mem_forensics-mcp, covering role: memory forensics specialist, mem-forensics-mcp: triage first, architecture, investigation questions -> tools and workflow.

6 3mo ago A 1,224 tokens original MIT

kismatkunwar89/SAVVYDFIR-MCP

Instructions file

Instructions for kismatkunwar89/SAVVYDFIR-MCP, covering savvydfir-mcp - dfir investigation framework, what this is, critical rules, forensic knowledge in tool responses and investigation workflow (7 phases).

4 2mo ago A 10,844 tokens original MIT

DeepSIFT AGENTS.md

13

ahammadshawki8/DeepSIFT

Instructions file CodexOpenCode

AGENTS.md instructions for ahammadshawki8/DeepSIFT, covering agents.md — orientation for coding/judging agents, what deepsift is (one paragraph), why it is a strong submission (verify each), entry points and run it in 60 seconds (no api key needed for these).

0 2mo ago A 1,192 tokens original MIT

DeepSIFT CLAUDE.md

14

ahammadshawki8/DeepSIFT

Instructions file

Claude Code instructions for ahammadshawki8/DeepSIFT, covering deepsift — claude.md, project overview, architecture, how to start an investigation and 1. start the mcp server (in a separate terminal).

0 2mo ago A 7,692 tokens original MIT

baobao26/mcp-hayabusa

Instructions file

Claude Code instructions for baobao26/mcp-hayabusa, covering claude.md, project status, project goal, detection engineering knowledge base: structure and status and commands.

0 1mo ago A 5,356 tokens