Dfir — Research agent for Claude Code
Digital forensics and incident response specialist.
How to install Dfir
Installs to ~/.claude/agents/mukul975-threatswarm-dfir.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/dfir.md -o ~/.claude/agents/mukul975-threatswarm-dfir.md Restart Claude Code, or start a new session, for it to be picked up.
What Dfir does
name: dfir description: Digital forensics and incident response specialist. Handles triage, memory acquisition with AVML/LiME, Volatility analysis, log timeline reconstruction, IOC extraction, persistence hunting, and incident reporting. Triggers on: DFIR, incident response, forensics, Volatility, memory dump, timeline, IOC, triage, compromise, malware on host, breach, intrusion. tools: Bash, Read, Write, Glob model: opus
Cybersecurity Skills (Invoke First)
Before starting DFIR work
Alternatives in Research
- Digital Forensics And Incident Response Agent — You are a digital forensics and incident response (DFIR) specialist 213 ★
- Sub Market — Internal subagent 132 ★
- Doc Drift Auditor — Verify documentation accuracy against implementation using git forensics and code analysis with file paths, li 64 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Malware Analyst
Malware analysis specialist for static and dynamic analysis. Handles PE/ELF/APK binary triage, behavioral anal
Scope Investigate
SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — st
Petswipe Reviewer
Use proactively for code review, regression hunting, validation gaps, deployment impact analysis, and document
Cdp Ninja Jewel Heart
Network intelligence spy - request/response analysis, authentication flows, performance timing, WebSocket moni
OSS Researcher
OSS research agent — reads CONTRIBUTING.md, runs parallel PR-approval research and issue hunting, ranks issues
Pre Mortem
Pre-mortem incident analysis. Receives diff and codebase context, produces structured incident report.
Related Skills
Ir
Incident response workflow — triage, evidence collection, timeline, and IOC extraction
OpenVault
OpenVault: a bootstrap CLI that generates a retrieval-first Obsidian vault for SOC work (IR, DFIR, Threat Hunt
Franken Drone Geometry Reconstruction
Agent-native, evidence-grade operating substrate for turning owner-authorized drone video into metrically hone