Winforensics MCP logo

Winforensics MCP

未申請

作者: x746b

A comprehensive MCP server for Windows digital forensics on KALI Linux

forensics-toolsblueteam-toolsmcp-serverwindows-forensicsdfir

インストール

$claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcp

サーバーをセットアップ

このサーバーには個別の設定が必要です。再利用可能な公開起動コマンドがないため、プロジェクトの手順に従ってください。

プロジェクトの手順

Developer Toolsの他のサーバー

ディレクトリ全体を見る

未申請リスティング

このMCPサーバーはあなたのものですか?

このリスティングは公開情報から自動的にインデックスされました。申請することで、ページの編集、互換性の設定、成長ツールのアンロックができます。2分以内に完了します。

このサーバーを申請する

セキュリティプロファイル

申請済みおよび認証済みのサーバーは毎週の静的スキャンを受け、コードが到達できる範囲(外部サービス、環境変数、シェルコマンド、エージェント設定フォルダ)と既知のアドバイザリを持つ依存関係が表示されます。このリスティングを申請すると利用できます。 セキュリティプロファイルの仕組み

40 件中 40 件

ドキュメントに記載されたツール (40)

プロジェクトのドキュメントに基づきます。サーバーのハンドシェイクは、各ツールの説明や動作を検証するものではありません。

api_analyze_imports

Full PE import analysis with pattern detection and MITRE ATT&CK mapping

api_detect_patterns

Detect attack patterns from PE import tables

api_lookup

Look up Windows API signature (26,944 APIs with params, DLL, category)

api_search_category

Browse APIs by category (e.g., "Process Injection", "File Management")

apmx_correlate_handles

Track handle producer/consumer chains across API calls

apmx_detect_patterns

Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs

apmx_get_call_details

Detailed records with parameter values, return values, timestamps

apmx_get_calls

Extract API calls with filtering, pagination, and time range support

apmx_get_calls_around

Context window of calls around a specific record

apmx_get_injection_info

Enriched injection chain extraction (target PID, shellcode size, technique)

apmx_parse

Parse .apmx64/.apmx86 capture - process info, modules, call counts

apmx_search_params

Search all records for a specific parameter value

build_timeline

Build unified timeline from multiple artifact sources

die_analyze_file

Analyze file for packers, compilers, protectors, .NET

die_get_packer_info

Get info about packer (difficulty, unpack tools)

die_scan_directory

Batch scan directory for packed executables

disk_parse_amcache

Parse Amcache.hve for SHA1 hashes and timestamps

disk_parse_mft

Parse $MFT with ADS metadata and timestomping detection

disk_parse_prefetch

Parse Prefetch for execution evidence

disk_parse_srum

Parse SRUDB.dat for app resource and network usage

disk_parse_usn_journal

Parse $J for file operations and deleted files

file_analyze_pe

Static PE analysis - hashes, imports, exports, packer detection

hunt_ioc

Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel

hunt_ioc_pack

Hunt behavioral IoCs across text exports, filenames, and PCAP payloads

investigate_execution

Correlate Prefetch/Amcache/SRUM to prove binary execution

investigate_user_activity

Correlate Browser/ShellBags/LNK/RecentDocs for user activity

ioc_pack_list

List bundled and external IoC packs with license metadata

pcap_find_suspicious

Detect C2 indicators, beaconing, DNS tunneling

pcap_get_conversations

Extract TCP/UDP conversations with byte counts

pcap_get_dns

Extract DNS queries and responses

pcap_get_http

Extract HTTP requests with URLs, methods, user-agents

pcap_get_stats

Get PCAP statistics - packet counts, protocols, top talkers

pcap_search

Search packet payloads for strings or regex patterns

vt_lookup_domain

Get domain reputation and categorization

vt_lookup_file

Calculate file hashes and look up on VirusTotal

vt_lookup_hash

Look up file hash (MD5/SHA1/SHA256) on VirusTotal

vt_lookup_ip

Get IP address reputation and geolocation

yara_list_rules

List available/bundled YARA rules

yara_scan_directory

Batch scan directory for malware

yara_scan_file

Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)

ツールの変更履歴

同じ設定での完全なチェック同士を比較します。ツールの列挙のみで実行はしていません。入力スキーマの変更は測定していません。

完全なツールチェックはまだありません。