query_history
Query security event history — binary first-seen events, quarantine blocks, alerts, and process starts. Filterable by event type, time range, and binary ID.
How to use it
Project documentation lists query_history for the Appcontrol MCP Go MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.
Install Appcontrol MCP Go
claude mcp add appcontrol C:\MCP\appcontrol-mcp.exeOther tools in Appcontrol MCP Go (8)
Get detailed info for one or more binaries by ID (batch with comma-separated IDs) — path, hash, signature, publisher, first-seen time, and running status.
Get CPU, GPU, and temperature sensor info for the monitored system.
Get time-series resource metrics — system-wide (CPU, memory, disk, GPU, temps) or per-binary with top-N/min-value filtering to find heavy resource consumers.
Get service stats, current timestamp, and uptime/idle intervals showing when the PC was on, off, or idle.
List tracked binaries with filters — unsigned-only, currently-running, first-seen-after date, path substring, or publisher ID.
List currently running processes with binary ID, name, path, PID, and start time. Filterable by fields.
List code-signing publishers (certificate identities) — name, country, and linked binary/rule counts.
List quarantine rules — blocked binaries and publishers with rule type and creation time.