Agentropix is a governed Model Context Protocol (MCP) server for digital forensics and incident response. It wraps battle-tested DFIR tooling—Plaso, Volatility 3, Sleuth Kit, YARA, EZ Tools—behind safety-gated, auditable AI-agent tools that map evidence to MITRE ATT&CK for autonomous, court-defensible analysis.
> ## Autonomous DFIR triage on the SANS SIFT Workstation — that never lets the LLM rate its own findings. > Point it at a Windows disk or memory image. It drives **16 real SIFT forensic tools** through **one > MCP server (71 tools)**, correlates across a **7-agent swarm** on a quorum blackboard, and emits a