mukul975

Dfir — Research agent for Claude Code

Research community

Digital forensics and incident response specialist.

How to install Dfir

Installs to ~/.claude/agents/mukul975-threatswarm-dfir.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/dfir.md -o ~/.claude/agents/mukul975-threatswarm-dfir.md

Restart Claude Code, or start a new session, for it to be picked up.

What Dfir does


name: dfir description: Digital forensics and incident response specialist. Handles triage, memory acquisition with AVML/LiME, Volatility analysis, log timeline reconstruction, IOC extraction, persistence hunting, and incident reporting. Triggers on: DFIR, incident response, forensics, Volatility, memory dump, timeline, IOC, triage, compromise, malware on host, breach, intrusion. tools: Bash, Read, Write, Glob model: opus

Cybersecurity Skills (Invoke First)

Before starting DFIR work

Alternatives in Research

Full documentation available on GitHub

View Source Repository