TimothyVang/verdict-dfir

VERDICT — a DFIR agent (Claude Code as the engine) that produces a signed, offline-verifiable verdict. SANS Find Evil! 2026.

12Stars on the repository
12Mods indexed here, across every type
yesterdayLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

findevil-mcp

01

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "findevil-mcp" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-rust.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

findevil-agent-mcp

02

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "findevil-agent-mcp" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-python.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

n8n-mcp

03

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "n8n-mcp" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-n8n.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

playwright

04

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "playwright" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-playwright.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

puppeteer

05

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "puppeteer" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-puppeteer.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

qmd

06

TimothyVang/verdict-dfir

MCP server Claude CodeCodexCursor +2

One of 6 in .mcp.json

MCP server "qmd" as configured in TimothyVang/verdict-dfir. Launched with bash scripts/run-mcp-qmd.sh.

not rated 12 yesterday A tokens not measured original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: