Winforensics MCP
未认领A comprehensive MCP server for Windows digital forensics on KALI Linux
安装
claude mcp add winforensics-mcp --scope user -- uv run winforensics-mcp更多Developer Tools服务器
浏览完整目录安全概况
已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理
40 个工具中显示 40 个
文档中列出的工具 (40)
内容来自项目文档。服务器握手不会验证每个工具的说明或行为。
api_analyze_imports
Full PE import analysis with pattern detection and MITRE ATT&CK mapping
api_detect_patterns
Detect attack patterns from PE import tables
api_lookup
Look up Windows API signature (26,944 APIs with params, DLL, category)
api_search_category
Browse APIs by category (e.g., "Process Injection", "File Management")
apmx_correlate_handles
Track handle producer/consumer chains across API calls
apmx_detect_patterns
Detect attack patterns (injection, hollowing, credential dumping) with MITRE ATT&CK IDs
apmx_get_call_details
Detailed records with parameter values, return values, timestamps
apmx_get_calls
Extract API calls with filtering, pagination, and time range support
apmx_get_calls_around
Context window of calls around a specific record
apmx_get_injection_info
Enriched injection chain extraction (target PID, shellcode size, technique)
apmx_parse
Parse .apmx64/.apmx86 capture - process info, modules, call counts
apmx_search_params
Search all records for a specific parameter value
build_timeline
Build unified timeline from multiple artifact sources
die_analyze_file
Analyze file for packers, compilers, protectors, .NET
die_get_packer_info
Get info about packer (difficulty, unpack tools)
die_scan_directory
Batch scan directory for packed executables
disk_parse_amcache
Parse Amcache.hve for SHA1 hashes and timestamps
disk_parse_mft
Parse $MFT with ADS metadata and timestomping detection
disk_parse_prefetch
Parse Prefetch for execution evidence
disk_parse_srum
Parse SRUDB.dat for app resource and network usage
disk_parse_usn_journal
Parse $J for file operations and deleted files
file_analyze_pe
Static PE analysis - hashes, imports, exports, packer detection
hunt_ioc
Hunt IOC (hash/filename/IP/domain) across all artifacts; yarascan=True adds YARA threat intel
hunt_ioc_pack
Hunt behavioral IoCs across text exports, filenames, and PCAP payloads
investigate_execution
Correlate Prefetch/Amcache/SRUM to prove binary execution
investigate_user_activity
Correlate Browser/ShellBags/LNK/RecentDocs for user activity
ioc_pack_list
List bundled and external IoC packs with license metadata
pcap_find_suspicious
Detect C2 indicators, beaconing, DNS tunneling
pcap_get_conversations
Extract TCP/UDP conversations with byte counts
pcap_get_dns
Extract DNS queries and responses
pcap_get_http
Extract HTTP requests with URLs, methods, user-agents
pcap_get_stats
Get PCAP statistics - packet counts, protocols, top talkers
pcap_search
Search packet payloads for strings or regex patterns
vt_lookup_domain
Get domain reputation and categorization
vt_lookup_file
Calculate file hashes and look up on VirusTotal
vt_lookup_hash
Look up file hash (MD5/SHA1/SHA256) on VirusTotal
vt_lookup_ip
Get IP address reputation and geolocation
yara_list_rules
List available/bundled YARA rules
yara_scan_directory
Batch scan directory for malware
yara_scan_file
Scan file with 718 YARA rules (Mimikatz, CobaltStrike, webshells, APT, ransomware)