Stomped

Summary

Stomped is not recommended for production environments due to its extremely low activity and lack of established maintenance, despite its niche utility in forensic analysis.
Price
GitHub Stars

Per-axis breakdown will be refreshed on the next collection.

GitHub Stars are excluded — popularity does not prove a project is still alive.

Checked 2026-06-16 · Formula & source · tool_master CSV

Stomped — ToolStack Analysis

Key Strengths

  • The tool provides an automated triage loop specifically for USN change journal analysis.
  • It utilizes a read-only architecture to ensure forensic integrity during investigations.
  • The integration with Claude Code facilitates autonomous DFIR operations within MCP environments.

Key Limitations

  • The project lacks a public GitHub repository, limiting transparency and collaborative review.
  • With 0 GitHub stars and minimal maintenance history, it poses a significant operational risk.
  • The tool is currently limited to the SANS SIFT Workstation environment, restricting broader use cases.

Angel — when it fits

  • If you need to automate USN journal analysis on SIFT, this tool hits different by automating the triage loop.
  • It’s basically a read-only agent, so you don't have to worry about it messing up your evidence files.
  • Integrating it with Claude Code for DFIR workflows is lowkey a game changer if you're already deep into the MCP ecosystem.

Devil — when it does not

  • Ngl, with 0 stars and no GitHub repo, you're pretty much on your own if this thing breaks in the middle of a case.
  • It’s a total ghost town project—don't expect any updates or community support when you run into bugs.

Stomped functions as an autonomous agent designed to detect timestomping and file laundering activities on SANS SIFT Workstations. By leveraging the USN change journal and a read-only architecture, it provides a self-correcting triage loop that simplifies complex forensic analysis. It is primarily intended for developers and security researchers who require seamless integration with the Model Context Protocol (MCP) to automate their digital forensics and incident response (DFIR) tasks.

Item Value
Type mcp
Price free
GitHub Stars 0
Latest Commit 2026-06-16T01:30:50Z
License MIT
Primary Language Python
TS Score 30 / 100
Official Link https://glama.ai/mcp/servers/bgs2v5vatk
GitHub N/A

Community reaction

HN users frequently discuss the potential of autonomous DFIR agents, noting the high value of automated USN journal analysis.
Some users express skepticism regarding the reliability of unverified, low-activity agents in critical forensic workflows.
Taken together, the tool is a promising experiment for enthusiasts, but a high-risk choice for professional forensic environments.
Source: Hacker News (90-day data)

FAQ

Is it free to use?
Yes, it is free to use.
How does it compare to similar tools?
There is currently no sufficient community or comparative data available to provide a detailed technical comparison with other DFIR tools.
Should I avoid it if the TS Score is low?
The TS Score is 30, indicating that maintenance is effectively stalled. It is not recommended for production environments and should be used only for testing or learning purposes.
Is it suitable for solo use?
It is suitable for solo researchers working on SIFT workstations, provided they are comfortable managing a project with minimal documentation and support.
Does it support Korean?
There is no information regarding native Korean language support for this tool.
Last Checked:
Source: GitHub · Official site

Related Tools

web-search-mcp

web-search-mcp

View
Jason-MCP

Jason-MCP

View
ProposalCraft

ProposalCraft

View