MCP Servers / other / winforensics-mcp

winforensics-mcp

JSON →
none18other

A comprehensive MCP server for Windows digital forensics on KALI Linux

Install
How to run this server
[ { "cmd": "pip install -e", "imports": [] } ]
server path: winforensics-mcp
Tools
What this server exposes
investigate_execution
Correlates Prefetch + Amcache + SRUM to answer 'Was this binary executed?'
investigate_user_activity
Correlates Browser + ShellBags + LNK + RecentDocs for user activity timeline
hunt_ioc
Searches for IOC (hash/filename/IP/domain) across ALL artifact sources + optional YARA scanning
hunt_ioc_pack
Hunts behavioral IoCs from bundled/external metadata packs such as impacket-iocs
build_timeline
Builds unified forensic timeline from multiple sources
ingest_parsed_csv
Import Eric Zimmerman tool CSV output (MFTECmd, PECmd, AmcacheParser)
Configuration
Environment & auth
authnone
envVIRUSTOTAL_API_KEY
Resources
winforensics-mcp — MCP Server · libregistry