{"repo":"nebulae/trudi","free":true,"listed":false,"github":"https://github.com/nebulae/trudi","clone":"git clone https://github.com/nebulae/trudi.git","description":"Autonomous DFIR agent — SANS SIFT Workstation MCP server for incident response","language":"Python","stars":28,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"TRUDI Threat Response Unit for Digital Investigation Autonomous DFIR agent built on the SANS SIFT Workstation. TRUDI runs a complete incident response investigation — disk triage, memory forensics, Windows artifact parsing, IOC enrichment, YARA hunting — and produces a structured analyst report with a full audit trail, without prompting for confirmation at each step. A separate model directs the investigation phase-by-phase, and an adversarial reviewer challenges every conclusion before it reaches the report. TRUDI only reports what survives review. Built for the Find Evil! hackathon — SANS Institute / Devpost, April–June 2026. --- Contents This README: How it works · Prerequisites · Setup · API keys · Starting a case · Live monitoring (experimental) · What gets produced · Trace dashboard · Submission components · Tool namespaces · YARA rules · Evidence constraints · Test suite · Repository layout · License Documentation: Doc What's in it ----- -------------- Try It Out Step-by-step: browse a finished run (no key) or drive a fresh investigation end-to-end Architecture Components, MCP boundary, guardrail tiers, security boundaries (Mermaid source · diagram PNG) Project Description The Devpost story — design rationale, reasoning loop, gates, curiosity budget Dataset Documentation Every case's provenance, evidence source, findings, and answer key Accuracy Report False positives, missed artifacts, hallucinations caught, confidence calibration, spoliation Live-monitoring demo (exp","default_branch":null,"files":null,"tree":[],"storefront":"/r/nebulae","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nebulae/trudi/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}