ioc_pack_list
List bundled and external IoC packs with license metadata
How to use it
Project documentation lists ioc_pack_list for the Winforensics MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.
Install Winforensics MCP
claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcpOther tools in Winforensics MCP (39)
Full PE import analysis with pattern detection and MITRE ATT&CK mapping
Detect attack patterns from PE import tables
Look up Windows API signature (26,944 APIs with params, DLL, category)
Browse APIs by category (e.g., "Process Injection", "File Management")
Track handle producer/consumer chains across API calls
Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs
Detailed records with parameter values, return values, timestamps
Extract API calls with filtering, pagination, and time range support
Context window of calls around a specific record
Enriched injection chain extraction (target PID, shellcode size, technique)
Parse .apmx64/.apmx86 capture - process info, modules, call counts
Search all records for a specific parameter value
Build unified timeline from multiple artifact sources
Analyze file for packers, compilers, protectors, .NET
Get info about packer (difficulty, unpack tools)
Batch scan directory for packed executables
Parse Amcache.hve for SHA1 hashes and timestamps
Parse $MFT with ADS metadata and timestomping detection
Parse Prefetch for execution evidence
Parse SRUDB.dat for app resource and network usage
Parse $J for file operations and deleted files
Static PE analysis - hashes, imports, exports, packer detection
Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel
Hunt behavioral IoCs across text exports, filenames, and PCAP payloads
Correlate Prefetch/Amcache/SRUM to prove binary execution
Correlate Browser/ShellBags/LNK/RecentDocs for user activity
Detect C2 indicators, beaconing, DNS tunneling
Extract TCP/UDP conversations with byte counts
Extract DNS queries and responses
Extract HTTP requests with URLs, methods, user-agents
Get PCAP statistics - packet counts, protocols, top talkers
Search packet payloads for strings or regex patterns
Get domain reputation and categorization
Calculate file hashes and look up on VirusTotal
Look up file hash (MD5/SHA1/SHA256) on VirusTotal
Get IP address reputation and geolocation
List available/bundled YARA rules
Batch scan directory for malware
Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)