TimothyVang/verdict-dfir

VERDICT — a DFIR agent (Claude Code as the engine) that produces a signed, offline-verifiable verdict. SANS Find Evil! 2026.

12Stars on the repository
12Mods indexed here, across every type
yesterdayLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

dev-loop

01

TimothyVang/verdict-dfir

Skill Claude CodeCodex

Drive a coding task to a verified, 5-star finish with a bounded agentic OODA loop (observe, orient, plan, act) gated by TDD, an explicit Definition of Done, and a code-quality bar, then commit and open a PR to the dev remote. Runs in an isolated git worktree and keeps a durable plan/checklist on disk so an interrupted…

not rated 12 yesterday A 204 tokens original Apache-2.0

verdict

02

TimothyVang/verdict-dfir

Skill Claude CodeCodex

Run VERDICT DFIR end to end from Claude Code. Use when the operator says /verdict, run verdict, investigate evidence end to end, is there evil here, or wants a signed Verdict and report. The skill verifies setup, uses SIFT mode when available, falls back honestly when it is not, and reports dashboard/report paths…

not rated 12 yesterday A 78 tokens original Apache-2.0