depalmar/ai-dfir-toolkit

A vendor-neutral collection of Sigma, YARA, and Suricata rules for detecting compromise of LLM applications, MCP servers, ML supply chains, AI infrastructure, AI-powered insider threats, and RAG/vector database attacks.

These files are depalmar/ai-dfir-toolkit's own configuration. They tell Claude Code and Codex how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.

23Stars on the repository
1Files it configures its agents with
6,013Tokens loaded in every session
2Agents configured

Instructions