Equips AI agents with a comprehensive suite of tools for memory, disk, and artifact forensics within an isolated Docker environment.
Sponsored
DFIR provides an MCP server designed to empower AI agents with advanced digital forensics capabilities. It integrates leading forensics tools like Volatility3 for memory analysis and The Sleuth Kit for disk forensics, running them securely within isolated Docker containers. The server exposes these tools via the MCP stdio transport, enabling AI agents to perform detailed investigations, automatically manage symbol downloads, and record findings in structured analyst notes, complete with persistent command history.
주요 기능
01Disk forensics via The Sleuth Kit
02Automatic Windows symbol downloading and conversion
03Persistent command history and analyst note generation
041 GitHub stars
05Memory forensics via Volatility3
06File search with strings, grep, and find
사용 사례
01Automating digital forensics investigations with AI agents
02Performing memory and disk image analysis
03Extracting and analyzing artifacts from compromised systems