Winforensics MCP
UnclaimedA comprehensive MCP server for Windows digital forensics on KALI Linux
Install
claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcpSet up this server
More in Developer Tools
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
40 of 40 tools
Documented tools (40)
From project documentation. A server handshake does not verify each tool’s description or behavior.
api_analyze_imports
Full PE import analysis with pattern detection and MITRE ATT&CK mapping
api_detect_patterns
Detect attack patterns from PE import tables
api_lookup
Look up Windows API signature (26,944 APIs with params, DLL, category)
api_search_category
Browse APIs by category (e.g., "Process Injection", "File Management")
apmx_correlate_handles
Track handle producer/consumer chains across API calls
apmx_detect_patterns
Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs
apmx_get_call_details
Detailed records with parameter values, return values, timestamps
apmx_get_calls
Extract API calls with filtering, pagination, and time range support
apmx_get_calls_around
Context window of calls around a specific record
apmx_get_injection_info
Enriched injection chain extraction (target PID, shellcode size, technique)
apmx_parse
Parse .apmx64/.apmx86 capture - process info, modules, call counts
apmx_search_params
Search all records for a specific parameter value
build_timeline
Build unified timeline from multiple artifact sources
die_analyze_file
Analyze file for packers, compilers, protectors, .NET
die_get_packer_info
Get info about packer (difficulty, unpack tools)
die_scan_directory
Batch scan directory for packed executables
disk_parse_amcache
Parse Amcache.hve for SHA1 hashes and timestamps
disk_parse_mft
Parse $MFT with ADS metadata and timestomping detection
disk_parse_prefetch
Parse Prefetch for execution evidence
disk_parse_srum
Parse SRUDB.dat for app resource and network usage
disk_parse_usn_journal
Parse $J for file operations and deleted files
file_analyze_pe
Static PE analysis - hashes, imports, exports, packer detection
hunt_ioc
Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel
hunt_ioc_pack
Hunt behavioral IoCs across text exports, filenames, and PCAP payloads
investigate_execution
Correlate Prefetch/Amcache/SRUM to prove binary execution
investigate_user_activity
Correlate Browser/ShellBags/LNK/RecentDocs for user activity
ioc_pack_list
List bundled and external IoC packs with license metadata
pcap_find_suspicious
Detect C2 indicators, beaconing, DNS tunneling
pcap_get_conversations
Extract TCP/UDP conversations with byte counts
pcap_get_dns
Extract DNS queries and responses
pcap_get_http
Extract HTTP requests with URLs, methods, user-agents
pcap_get_stats
Get PCAP statistics - packet counts, protocols, top talkers
pcap_search
Search packet payloads for strings or regex patterns
vt_lookup_domain
Get domain reputation and categorization
vt_lookup_file
Calculate file hashes and look up on VirusTotal
vt_lookup_hash
Look up file hash (MD5/SHA1/SHA256) on VirusTotal
vt_lookup_ip
Get IP address reputation and geolocation
yara_list_rules
List available/bundled YARA rules
yara_scan_directory
Batch scan directory for malware
yara_scan_file
Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)
Tool change history
FAQ
Questions about Winforensics MCP Server
- How do I connect Winforensics MCP Server to Claude?
- The listing records `claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcp` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Code as compatible clients.
- Is Winforensics MCP Server free?
- The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Winforensics MCP Server do?
- Winforensics MCP Server documents 40 tools to the agent, including api_analyze_imports, api_detect_patterns, api_lookup. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.