Skip to main content
Glama
guyoverclocked

forensic-artifact-investigator

Related Servers

Alternatives to forensic-artifact-investigator

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      A governed MCP server for digital-forensics and incident-response (DFIR) work, exposing curated forensic tools (Volatility 3, Plaso, RegRipper, etc.) through a single FastMCP HTTP endpoint with bearer-token authentication and tamper-evident audit logging.
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      A local MCP server that wraps common forensic command-line tools for CTF/forensics competitions into MCP tools, enabling automated analysis of disk images, memory dumps, network captures, SQLite databases, archives, and steganography.
      1
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      Read-only MCP server for autonomous, spoliation-proof disk-image triage with self-correcting verification loop.
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Read-only MCP server that exposes Autopsy digital forensics case data as tools, enabling LLM clients like Cline to browse filesystems, query artifacts, and search keywords without modifying the case.
      1
      MIT
    • A
      license
      Not graded
      quality
      F
      maintenance
      Read-only MCP server that exposes deterministic NTFS timestomp detection tools for autonomous forensic triage, with architectural guarantees against evidence modification.
      MIT
    • A
      license
      B
      quality
      B
      maintenance
      Multi-tier memory forensics MCP server combining a fast Rust engine with Volatility3 coverage for analyzing memory dumps.
      15
      6
      MIT

    TDQS

    A4/5.0

    Scored across 3 tools

    Disambiguation5/5

    Each tool targets a distinct forensic operation: file metadata and hashing, string extraction, and memory dump analysis. There is no overlap in their purposes, making selection unambiguous.

    Naming Consistency4/5

    Tool names follow a clear verb_noun pattern: extract-metadata, extract-strings, analyze-memory-dump. The verbs differ (extract vs. analyze) but this is justifiable based on the action type, and the pattern is consistent throughout.

    Tool Count4/5

    Three tools is on the lower end, but each tool covers a broad, substantial forensic category. The count is appropriate for a focused investigator server, though could be slightly expanded.

    Completeness4/5

    The set covers core artifact investigation needs: metadata extraction (with MIME mismatch and hash), string/indicator extraction, and memory analysis. Minor gaps like disk image carving or network artifact analysis exist, but the major workflows are represented.

    Maintenance

    ActivityStale
    ResponsivenessNo issues