ProcMon MCP
未认领An MCP to expose process monitoring and ETW tracing functionally to AI agents to assist in security work
安装
$
uvx procmon-mcp工具(18 个)
analyze_pe
Static PE imports and exports
capture_snapshot
Point-in-time process, module, and network snapshot
check_elevation
Capability matrix
find_pe_files
Recursive PE file discovery
get_minifilters
fltmc filter and instance output
get_network_connections
TCP/UDP endpoints by process
get_process_details
Modules, threads, command line, memory
get_security_events
Security log (IDs 4688, 4624, 4672, 4648)
get_system_info
OS build and AV snapshot
list_drivers
Kernel drivers via WMI
list_etw_providers
Parse logman query providers
list_processes
Processes with optional name/PID filter
list_services
Win32 services with paths
query_event_log
Get-WinEvent FilterHashtable query
request_elevation
UAC helper for a shell command
start_etw_trace
Start a kernel ETW trace (requires elevation)
stop_etw_trace
Stop trace and convert ETL output
timed_capture
Repeated snapshots over a duration