- Conduid
- Marketplace
- #digital-forensics
MCP servers tagged digital-forensics
17 live MCP servers tagged "digital-forensics", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with digital-forensics.
Cti Expert
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code / Codex. 120+ commands, 57 techniques, 79 typed MCP tools, deterministic case pipeline + ICD-203 repo…
Mulder
Agentic DFIR
Huntkit
Investigation toolkit for Claude Code: case management, OSINT, structured analytic techniques, chain-of-custody evidence capture, and bundled threat-intel MCP servers.
Valhuntir
Valhuntir CLI — AI-augmented incident response platform
Vigia Intent Analysis
DFIR intentionality engine for SIFT. Verdicts sealed before any LLM sees the evidence. Detects fabricated artifacts and false flags — not just what happened, but who benefits f…
AI Watermarks Reality Check
Test what AI watermark and provenance evidence exists, whether it verifies, and what survives publishing.
Verdict Dfir
VERDICT — a DFIR agent (Claude Code as the engine) that produces a signed, offline-verifiable verdict. SANS Find Evil! 2026.
AgentProvenance
Security-oriented three-axis observability for sandboxed AI agents: model intent, app context, and runtime telemetry into verifiable evidence graphs for risk, forensics, and audit.
Dfireballz
AI-native digital forensics & cybercrime investigation platform. 7 MCP servers (Volatility3, Ghidra, Wireshark, OSINT, threat-intel & more) orchestrated by Claude, ChatGPT, or Oll…
Notes Recover
Copy-first Apple Notes recovery and review toolkit for macOS, with AI-assisted triage, evidence-backed case Q&A, and a read-mostly MCP server for Codex / Claude Code style local a…
Framecite
Local, payload-redacted PCAP troubleshooting over MCP with deterministic packet citations—no Wireshark or TShark required.
SAVVYDFIR MCP
AI-driven DFIR framework: an MCP server that turns Claude Code into an autonomous digital-forensics analyst on SANS SIFT - correlates disk + memory evidence, enforces a determinis…
Cyber Incident Investigation And Triage MCP Server
AI-native MCP server for natural-language cyber incident investigation and triage across Windows, Linux, and macOS artifacts, plus Volatility3 memory forensics and Hashcat. Mount…
Find Evil
Autonomous, audit-traced incident-response agent for the SANS SIFT Workstation. The agent has no shell — evidence tampering and hallucinated findings are architecturally impossibl…
Steganography MCP
128-tool MCP server for steganography analysis — LSB detection, chi-square steganalysis, RS analysis, JPEG/F5/JSteg/OutGuess detection, BPCS, video & GIF stego, network covert cha…
CASE UCO SDK
Multi-language SDK (Python, C#, Java, Rust) for building validated CASE/UCO JSON-LD graphs for digital forensics and cyber-investigation. AI-agent ready with MCP server. Support f…
Spoor
Autonomous DFIR agent driving SANS SIFT forensic tools via an MCP server + LangGraph, with guardrails and a hash-chained audit trail.