apmx_get_calls

MCP tool from Winforensics MCP by x746b

Extract API calls with filtering, pagination, and time range support

How to use it

Project documentation lists apmx_get_calls for the Winforensics MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.

Install Winforensics MCP

$claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcp
FULL WINFORENSICS MCP LISTING

Other tools in Winforensics MCP (39)

api_analyze_imports

Full PE import analysis with pattern detection and MITRE ATT&CK mapping

api_detect_patterns

Detect attack patterns from PE import tables

api_lookup

Look up Windows API signature (26,944 APIs with params, DLL, category)

api_search_category

Browse APIs by category (e.g., "Process Injection", "File Management")

apmx_correlate_handles

Track handle producer/consumer chains across API calls

apmx_detect_patterns

Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs

apmx_get_call_details

Detailed records with parameter values, return values, timestamps

apmx_get_calls_around

Context window of calls around a specific record

apmx_get_injection_info

Enriched injection chain extraction (target PID, shellcode size, technique)

apmx_parse

Parse .apmx64/.apmx86 capture - process info, modules, call counts

apmx_search_params

Search all records for a specific parameter value

build_timeline

Build unified timeline from multiple artifact sources

die_analyze_file

Analyze file for packers, compilers, protectors, .NET

die_get_packer_info

Get info about packer (difficulty, unpack tools)

die_scan_directory

Batch scan directory for packed executables

disk_parse_amcache

Parse Amcache.hve for SHA1 hashes and timestamps

disk_parse_mft

Parse $MFT with ADS metadata and timestomping detection

disk_parse_prefetch

Parse Prefetch for execution evidence

disk_parse_srum

Parse SRUDB.dat for app resource and network usage

disk_parse_usn_journal

Parse $J for file operations and deleted files

file_analyze_pe

Static PE analysis - hashes, imports, exports, packer detection

hunt_ioc

Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel

hunt_ioc_pack

Hunt behavioral IoCs across text exports, filenames, and PCAP payloads

investigate_execution

Correlate Prefetch/Amcache/SRUM to prove binary execution

investigate_user_activity

Correlate Browser/ShellBags/LNK/RecentDocs for user activity

ioc_pack_list

List bundled and external IoC packs with license metadata

pcap_find_suspicious

Detect C2 indicators, beaconing, DNS tunneling

pcap_get_conversations

Extract TCP/UDP conversations with byte counts

pcap_get_dns

Extract DNS queries and responses

pcap_get_http

Extract HTTP requests with URLs, methods, user-agents

pcap_get_stats

Get PCAP statistics - packet counts, protocols, top talkers

pcap_search

Search packet payloads for strings or regex patterns

vt_lookup_domain

Get domain reputation and categorization

vt_lookup_file

Calculate file hashes and look up on VirusTotal

vt_lookup_hash

Look up file hash (MD5/SHA1/SHA256) on VirusTotal

vt_lookup_ip

Get IP address reputation and geolocation

yara_list_rules

List available/bundled YARA rules

yara_scan_directory

Batch scan directory for malware

yara_scan_file

Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)