D

DFIR

Verified Integration
Author: @Androsh7Category: ServerApplication
JSON-RPC 2.0
Protocol Standard
Sub-second
Execution Latency
Active
Operational Status

Client Configuration

— Connect DFIR to Claude Desktop or Cursor in seconds
{
  "mcpServers": {
    "dfir": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-dfir"
      ],
      "env": {}
    }
  }
}
Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).
Architecture & Capabilities

System Overview

Equips AI agents with a comprehensive suite of tools for memory, disk, and artifact forensics within an isolated Docker environment.

Indexed Date

7/23/2026

License

Open Source

Protocol Layer

stdio / SSE RPC

Frequently Asked Questions

Architecture and operational details for DFIR

It integrates popular forensic tools like Volatility3 for memory forensics and The Sleuth Kit for disk forensics. Additionally, it offers file searching (strings, grep, find), archive extraction, automatic Windows symbol downloading, Linux symbol search, and utilities for hashing files.

Related MCP Servers

Browse all servers →
C
@carboneio
Carbone

Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.

ClaudeSearchDatabase+65 FAQs
Learn more
C
@sebastienrousseau
CloudCDN

Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.

ClaudeSearchDatabase+65 FAQs
Learn more

Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.

ClaudeSearchDatabase+55 FAQs
Learn more