capture_snapshot
Point-in-time process, module, and network snapshot
How to use it
capture_snapshot is exposed by the ProcMon MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the capture_snapshot tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install ProcMon MCP
uvx procmon-mcpOther tools in ProcMon MCP (17)
Static PE imports and exports
Capability matrix
Recursive PE file discovery
fltmc filter and instance output
TCP/UDP endpoints by process
Modules, threads, command line, memory
Security log (IDs 4688, 4624, 4672, 4648)
OS build and AV snapshot
Kernel drivers via WMI
Parse logman query providers
Processes with optional name/PID filter
Win32 services with paths
Get-WinEvent FilterHashtable query
UAC helper for a shell command
Start a kernel ETW trace (requires elevation)
Stop trace and convert ETL output
Repeated snapshots over a duration