DFIR
Verified IntegrationClient Configuration
— Connect DFIR to Claude Desktop or Cursor in seconds{
"mcpServers": {
"dfir": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-dfir"
],
"env": {}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).System Overview
Equips AI agents with a comprehensive suite of tools for memory, disk, and artifact forensics within an isolated Docker environment.
7/23/2026
Open Source
stdio / SSE RPC
Frequently Asked Questions
Architecture and operational details for DFIR
It integrates popular forensic tools like Volatility3 for memory forensics and The Sleuth Kit for disk forensics. Additionally, it offers file searching (strings, grep, find), archive extraction, automatic Windows symbol downloading, Linux symbol search, and utilities for hashing files.
Related MCP Servers
Browse all servers →Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.
Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.
Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.