dfir cursor rules

9 tagged dfir, measured the same way as everything else here.

Browse within: code 6scripts 6

docker-building

01

TazWake/Public

Cursor rule Cursor

Rules for building and reviewing Docker components, including dockerfiles, docker-compose.yml and related files.

44 12d ago A 19 tokens original CC0-1.0

malware-analysis

02

TazWake/Public

Cursor rule Cursor

This agent should be used whenever analysing suspicious files or creating scripts to analyse suspicious files.

44 12d ago A 17 tokens original CC0-1.0

python-coding

03

TazWake/Public

Cursor rule Cursor

Python best practices and patterns for modern software development with Flask and SQLite.

44 12d ago A 0 tokens original CC0-1.0

case-uco-sdk

04

vulnmaster/CASE-UCO-SDK

Cursor rule Cursor

CASE/UCO SDK usage patterns for building digital forensics investigation graphs.

9 yesterday A 1,772 tokens original Apache-2.0

extension-authoring

05

vulnmaster/CASE-UCO-SDK

Cursor rule Cursor

Guidance for authoring CASE/UCO extension ontologies per the CDO Community Playground Guide.

9 yesterday A 0 tokens original Apache-2.0

cursorrules

06

kismatkunwar89/SAVVYDFIR-MCP

Cursor rule Cursor

IMPORTANT: This project has a knowledge graph. ALWAYS use the code-review-graph MCP tools BEFORE using Grep/Glob/Read to explore the codebase. The graph is faster, cheaper (fewer tokens), and gives you structural context (callers, dependents, test coverage) that file scanning cannot.

4 2mo ago A 422 tokens copy · 100% MIT