EvidenceGene Court
Related Servers
Alternatives to EvidenceGene Court
No user-submitted related servers found.
Related Servers
- AlicenseBqualityDmaintenanceEnables autonomous DFIR investigation by turning the SIFT toolchain into evidence-safe MCP functions, with self-correction, corroboration, and traceable audit trails.34MIT
- AlicenseNot gradedqualityDmaintenanceA production-grade, type-safe MCP server for memory forensics via Volatility 3, enabling LLM-assisted incident response without timeouts or evidence spoliation.1MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to conduct evidence-grounded forensic triage of compromised hosts, with architectural safeguards against evidence spoliation and hallucinated findings, supporting self-correction and chain of custody.MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that transforms Claude Code into an autonomous DFIR analyst by providing typed, audited forensic tools for disk, memory, timeline, registry, and IOC analysis on the SANS SIFT Workstation.Apache 2.0
- AlicenseNot gradedqualityBmaintenanceA high-performance MCP Server for Disk Forensics that enables AI agents to analyze disk images through the Model Context Protocol.2MIT
- AlicenseNot gradedqualityBmaintenanceEnables autonomous digital forensics and incident response by wrapping SIFT Workstation tools as MCP tools and orchestrating a multi-agent AI pipeline for evidence analysis and remediation planning.2MIT
TDQS
Scored across 11 tools
Each tool targets a distinct forensic operation, though vol_pslist and vol_psscan both enumerate processes, differing only in technique. The descriptions clarify this, but the overlap is still a minor source of potential confusion.
The tool names mostly follow a predictable convention with domain prefixes like verify_, vol_, and disk_, but cross_validate_processes and artifact_query break the pattern, making the set slightly inconsistent.
With 11 tools, the server is well-scoped for a forensics toolkit. Each tool earns its place, covering integrity checks, memory analysis, disk analysis, and result browsing without unnecessary bloat.
The set covers the core forensic workflow: evidence integrity, audit verification, memory artifact extraction, disk timelines, and cross-validation. However, it lacks common operations like file extraction or advanced memory analysis, leaving minor gaps.