samaritan0/dfir-agentic-suite

An autonomous Digital Forensics & Incident Response toolkit built on Claude's skill and MCP ecosystem

16Stars on the repository
10Mods indexed here, across every type
5mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

dfir-orchestrator

01

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Agentic DFIR orchestrator that autonomously investigates security incidents by chaining forensic skills (IOC extraction, Windows artifact triage, timeline correlation, YARA generation) with an autonomous reasoning loop, persistent case state, and human-in-the-loop approvals. Use this skill whenever the user mentions…

not rated 16 5mo ago A 157 tokens

ioc-extractor

02

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Extract and enrich Indicators of Compromise (IOCs) from any input — log files, alerts, emails, pastes, forensic tool output, threat intel reports, or raw text. Extracts IPs, domains, URLs, file hashes (MD5/SHA1/SHA256), email addresses, CVE IDs, Bitcoin/Ethereum addresses, MITRE ATT&CK technique IDs, and…

not rated 16 5mo ago A 183 tokens

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Parse, normalize, and correlate forensic timelines from Plaso/log2timeline (l2tcsv, jsonline), Hayabusa (CSV/JSONL), Chainsaw (JSON), and raw log files (syslog, auth.log, JSON-formatted logs, Windows XML event logs). Produces unified UTC timelines, detects attack sequences, and maps findings to MITRE ATT&CK. Use this…

not rated 16 5mo ago A 165 tokens

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Parse and correlate Windows forensic artifacts from EZTools (Eric Zimmerman), KAPE, Chainsaw, Hayabusa, and raw event logs. Handles CSV output from EvtxECmd, MFTECmd, PECmd (Prefetch), AmcacheParser, AppCompatCacheParser, SBECmd (ShellBags), LECmd (LNK files), JLECmd (Jump Lists), and RECmd (Registry). Also parses…

not rated 16 5mo ago A 217 tokens

yara-rule-generator

05

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Generate YARA rules from behavioral descriptions, malware samples, forensic findings, or threat intelligence reports. Produces well-structured YARA rules with metadata, string patterns, and conditions. Supports PE-specific features (imports, exports, sections, imphash), magic byte detection, and condition logic. Can…

not rated 16 5mo ago A 164 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: