Run containerized digital forensics investigations with safe, callable SIFT tools.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Sift MCP (Docker edition)" yet — see the docs or source repo.
Use Sift MCP to perform an initial forensic analysis of this disk image. List partition details, file system types, suspicious deleted files, and recommend the next Sleuth Kit commands to run.
A structural overview of the disk image, suspicious artifacts, and recommended next forensic steps.
Use the Volatility 3 tools in Sift MCP to analyze this memory dump, identify running processes, network connections, suspicious injection indicators, and summarize high-risk findings.
A memory forensics summary including suspicious processes, connections, and possible malicious behavior indicators.
Use Sift MCP with Plaso to generate an event timeline from the provided evidence source, organize key activities chronologically, and highlight logins, file modifications, and outbound connections.
A chronologically ordered forensic timeline highlighting key security events and investigation leads.
Turn the SIFT toolchain into evidence-safe, auditable DFIR MCP workflows.
Turn AI into an autonomous DFIR analyst on SANS SIFT.
Detect NTFS timestomping safely for automated forensic triage without modifying evidence.
Wrap SANS SIFT forensic tools for structured incident response and threat analysis.
Use Sift for real-time fraud scoring, decisions, and event ingestion.
Perform read-only disk image triage with self-verifying, tamper-resistant forensic analysis.