trudi

nebulae/trudi
★ 11 stars Python AI/LLM Updated today
Autonomous DFIR agent — SANS SIFT Workstation MCP server for incident response
View on GitHub → 🔍 Audit Wallet Slippage →

Quick Install

Copy the config for your editor. Some servers may need additional setup — check the README.

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "trudi": {
      "command": "uvx",
      "args": [
        "trudi"
      ]
    }
  }
}

Or install with pip: pip install trudi

README Excerpt

**Threat Response Unit for Digital Investigation** Autonomous DFIR agent built on the SANS SIFT Workstation. TRUDI runs a complete incident response investigation — disk triage, memory forensics, Windows artifact parsing, IOC enrichment, YARA hunting — and produces a structured analyst report with a full audit trail, without prompting for confirmation at each step.

Tools (10)

ABUSEIPDB_API_KEYANTHROPIC_API_KEYVIRUSTOTAL_API_KEYattribute_actorsbinwalkchainsawcoverage_reportdair_assesssleuthkittcpxtract