depalmar/ai-dfir-toolkit

A vendor-neutral collection of Sigma, YARA, and Suricata rules for detecting compromise of LLM applications, MCP servers, ML supply chains, AI infrastructure, AI-powered insider threats, and RAG/vector database attacks.

This repository also configures its own agents. See what ai-dfir-toolkit tells them →

23Stars on the repository
2Mods indexed here, across every type
17d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex needs its repo

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

not rated 23 17d ago A SkillSpector: pass 197 tokens original Apache-2.0