Skip to main content
Glama
Ghosthunter5599

Forensics MCP Server

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
system_health_checkA

Inspects real-time host forensic capability readiness, storage, and chain-of-custody status.

extract_metadataB

Extracts file metadata, computes cryptographic hashes (MD5, SHA-1, SHA-256, SHA-512), and detects MIME-type masquerading.

extract_stringsC

Extracts printable ASCII & Unicode strings from an evidence artifact.

scan_iocsC

Scans an evidence artifact for Indicators of Compromise: IPs, C2 URLs, email addresses, suspicious commands, and Base64 payloads.

check_threat_intelB

Queries threat intelligence databases (with safe offline fixture fallback) for a file hash.

Prompts

Interactive templates invoked by user choice

NameDescription
triage_suspicious_file
triage_memory_dump

Resources

Contextual data attached and managed by the client

NameDescription
res_capabilities
res_custody
res_health
res_evidence

TDQS

A3.5/5.0

Scored across 5 tools

Disambiguation5/5

Each tool targets a distinct forensic task: system readiness, metadata extraction, string extraction, IOC scanning, and threat intel lookup. There is no functional overlap, and the descriptions clearly delineate their purposes.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern (e.g., system_health_check, extract_metadata, scan_iocs), using snake_case throughout. The naming is predictable and aligns with forensic terminology.

Tool Count5/5

Five tools is appropriate for a forensic server covering host readiness, file analysis, and threat detection. Each tool serves a necessary function without redundancy or gaps in the core workflow.

Completeness4/5

The toolset covers essential forensic steps: health check, metadata extraction, string extraction, IOC scanning, and threat intel. A minor gap is the absence of a tool for parsing specific artifact types (e.g., registry hives or logs), but the set is sufficient for basic evidence triage.

Maintenance

ActivityMaintained
ResponsivenessNo issues