AI-driven DFIR framework: an MCP server that turns Claude Code into an autonomous digital-forensics analyst on SANS SIFT - correlates disk + memory evidence, enforces a deterministic evidence-provenance gate, and produces auditable, hash-chained investigation reports.
> DFIR MCP server for SIFT Workstation that correlates disk and memory evidence, tracks provenance, and produces investigation reports. --- > **📌 Judged submission = tag [`v1.1.1`](https://github.com/kismatkunwar89/SAVVYDFIR-MCP/releases/tag/v1.1.1). Latest release = [`v1.2.2`](https://github.com/kismatkunwar89/SAVVYDFIR-MCP/releases/tag/v1.2.2).**