{"repo":"calebevans/mulder","free":true,"listed":false,"github":"https://github.com/calebevans/mulder","clone":"git clone https://github.com/calebevans/mulder.git","description":"Agentic DFIR","language":"Python","stars":26,"topics":["ai","ai-agents","claude-code","dfir","digital-forensics","forensics","incident-response","mcp","sans-sift","threat-hunting"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"mulder Mulder takes a directory of forensic evidence (disk images, memory dumps, PCAPs, event logs) and runs a five-phase autonomous investigation with hard quality gates between each phase. It produces structured incident reports with MITRE ATT&CK mappings, IOC exports, and a full audit trail. An adversarial \"Alternative Narrative\" phase challenges every finding before the report is generated. All tool invocations go through typed MCP interfaces - never through a shell - and an append-only audit log validates every evidence citation at the API boundary, making findings with fabricated evidence citations structurally impossible to submit. Results Four autonomous investigations against real forensic datasets, unmodified from tool output. Each case has an interactive HTML report on GitHub Pages (sidebar navigation, dark/light theme, audit trail). See the examples index for all report links. Case Systems Evidence Sources Tool Calls Findings Runtime Tokens Report ------ --------- ---------- --------- ------------ ---------- --------- -------- -------- Rocba 1 8 GB 67 292 7 (1 high) 66 min 313K HTML SRL-2015 4 30 GB 159 610 29 (4 crit, 9 high) 126 min 300K HTML SRL-2018 11 120 GB 457 1,508 55 (11 crit, 19 high) 336 min 698K HTML NIST Data Leakage 4 8 GB 88 723 33 (15 high) 102 min 330K HTML The NIST Data Leakage case has a detailed accuracy report validated against published NIST ground truth: 60% full match, 90% detection rate, 5% false positive rate. The single false positive in","default_branch":null,"files":null,"tree":[],"storefront":"/r/calebevans","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/calebevans/mulder/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}