Winforensics MCP logo

Winforensics MCP

未认领

作者:x746b

A comprehensive MCP server for Windows digital forensics on KALI Linux

forensics-toolsblueteam-toolsmcp-serverwindows-forensicsdfir

安装

$claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcp

此服务器需要专门配置。目前没有可复用的公开启动命令,请遵循项目说明。

项目说明

更多Developer Tools服务器

浏览完整目录

未认领列表

这个 MCP 服务器是你的吗?

此列表根据公开信息自动生成。认领后,你可以编辑页面、设置兼容性并解锁增长工具。全程不超两分钟。

认领此服务器

安全概况

已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理

40 个工具中显示 40 个

文档中列出的工具 (40)

内容来自项目文档。服务器握手不会验证每个工具的说明或行为。

api_analyze_imports

Full PE import analysis with pattern detection and MITRE ATT&CK mapping

api_detect_patterns

Detect attack patterns from PE import tables

api_lookup

Look up Windows API signature (26,944 APIs with params, DLL, category)

api_search_category

Browse APIs by category (e.g., "Process Injection", "File Management")

apmx_correlate_handles

Track handle producer/consumer chains across API calls

apmx_detect_patterns

Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs

apmx_get_call_details

Detailed records with parameter values, return values, timestamps

apmx_get_calls

Extract API calls with filtering, pagination, and time range support

apmx_get_calls_around

Context window of calls around a specific record

apmx_get_injection_info

Enriched injection chain extraction (target PID, shellcode size, technique)

apmx_parse

Parse .apmx64/.apmx86 capture - process info, modules, call counts

apmx_search_params

Search all records for a specific parameter value

build_timeline

Build unified timeline from multiple artifact sources

die_analyze_file

Analyze file for packers, compilers, protectors, .NET

die_get_packer_info

Get info about packer (difficulty, unpack tools)

die_scan_directory

Batch scan directory for packed executables

disk_parse_amcache

Parse Amcache.hve for SHA1 hashes and timestamps

disk_parse_mft

Parse $MFT with ADS metadata and timestomping detection

disk_parse_prefetch

Parse Prefetch for execution evidence

disk_parse_srum

Parse SRUDB.dat for app resource and network usage

disk_parse_usn_journal

Parse $J for file operations and deleted files

file_analyze_pe

Static PE analysis - hashes, imports, exports, packer detection

hunt_ioc

Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel

hunt_ioc_pack

Hunt behavioral IoCs across text exports, filenames, and PCAP payloads

investigate_execution

Correlate Prefetch/Amcache/SRUM to prove binary execution

investigate_user_activity

Correlate Browser/ShellBags/LNK/RecentDocs for user activity

ioc_pack_list

List bundled and external IoC packs with license metadata

pcap_find_suspicious

Detect C2 indicators, beaconing, DNS tunneling

pcap_get_conversations

Extract TCP/UDP conversations with byte counts

pcap_get_dns

Extract DNS queries and responses

pcap_get_http

Extract HTTP requests with URLs, methods, user-agents

pcap_get_stats

Get PCAP statistics - packet counts, protocols, top talkers

pcap_search

Search packet payloads for strings or regex patterns

vt_lookup_domain

Get domain reputation and categorization

vt_lookup_file

Calculate file hashes and look up on VirusTotal

vt_lookup_hash

Look up file hash (MD5/SHA1/SHA256) on VirusTotal

vt_lookup_ip

Get IP address reputation and geolocation

yara_list_rules

List available/bundled YARA rules

yara_scan_directory

Batch scan directory for malware

yara_scan_file

Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)

工具变更历史

比较相同配置的完整检查。只列出工具,未调用工具。此处不测量输入结构的变化。

尚无完整工具检查。