mulder — security grade CAUTION, quality 60/100

Security audit verdict: CAUTION · quality 60/100

Flagged: sudo usage, privileged Docker. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by calebevans · MCP Server · ★ 88

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mulder safe to install? View the security audit →

About mulder

mulder 🏆 1st Place - SANS Institute Find Evil Hackathon 2026 Mulder takes a directory of forensic evidence (disk images, memory dumps, PCAPs, event logs) and runs a five-phase autonomous investigation with hard quality gates between each phase. It produces structured incident reports with MITRE ATT&CK mappings, IOC exports, and a full audit trail. An adversarial "Alternative Narrative" phase challenges every finding before the report is generated. All tool invocations go through typed MCP interfaces - never through a shell - and an append-only audit log validates every evidence citation at the API boundary, making findings with fabricated evidence citations structurally impossible to submit. Results Four autonomous investigations against real forensic datasets, unmodified from tool output. Each case has an interactive HTML report on GitHub Pages (sidebar navigation, dark/light theme, audit trail). See the examples index for all report links.

aiai-agentsclaude-codedfirdigital-forensicsforensicsincident-responsemcpsans-siftthreat-hunting

Quick Facts

Stars88
Forks19
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score59.7089953969702/100
Open Issues16
Last Updated2026-10-04
Created2026-04-08
Platformsclaude-code, mcp, python
Est. Tokens~16k

mulder alternative? Top 6 similar tools

Looking for a mulder alternative? If you're comparing mulder with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Valhuntir by AppliedIR · ⭐ 106

    Valhuntir CLI — AI-augmented incident response platform

  • huntkit by assafkip · ⭐ 51

    Investigation toolkit for Claude Code: case management, OSINT, structured analytic techniques, chain-of-custod

  • daymon by daymonio · ⭐ 365

    Daymon puts your favorite AI to work 24/7. It schedules, remembers, and orchestrates your own virtual team. Fr

  • deepcontext-mcp by Wildcard-Official · ⭐ 278

    DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent

  • Wazuh-MCP-Server by gensecaihq · ⭐ 246

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • ai_for_the_win by depalmar · ⭐ 162

    Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red tea

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is mulder?

mulder is Agentic DFIR. It is categorized as a MCP Server with 88 GitHub stars.

What programming language is mulder written in?

mulder is primarily written in Python. It covers topics such as ai, ai-agents, claude-code.

How do I install or use mulder?

You can find installation instructions and usage details in the mulder GitHub repository at github.com/calebevans/mulder. The project has 88 stars and 19 forks, indicating an active community.

What license does mulder use?

mulder is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to mulder?

The top alternatives to mulder on Agent Skills Hub include Valhuntir, huntkit, daymon. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools