# SIFTAgent

> Use this tool when you need to automate and enhance digital forensic investigations with typed and audited tools. The SIFTAgent transforms Claude Code into an autonomous DFIR analyst, providing analysis capabilities for disk, memory, timeline, registry, and IOC examination. It accepts Claude Code inputs and outputs comprehensive forensic analysis results, ideal for use in incident response and threat hunting contexts.

Canonical page: https://skillsregistry.net/skills/abhishek2f24-siftagent  
JSON: https://api.skillsregistry.net/v1/skills/abhishek2f24-siftagent

## Description

An MCP server that transforms Claude Code into an autonomous DFIR analyst by providing typed, audited forensic tools for disk, memory, timeline, registry, and IOC analysis on the SANS SIFT Workstation.

## Trust

- **Trust score (0–1):** 0.68
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-09-01

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/ffn2cfd0no)
- **Repository:** <https://github.com/abhishek2f24/siftagent>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "abhishek2f24-siftagent"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/abhishek2f24-siftagent` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/abhishek2f24-siftagent/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
