FVol MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@FVol MCP Servertriage /evidence/memory.raw with pstree, netscan, and malfind"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
FVol MCP Server
MCP server that exposes fvol (Rust port of Volatility 3) plugins as tools for Claude and other MCP clients. Fork of Volatility-MCP-Server.
Setup
Requires Linux, Python 3.10+, and the fvol binary (releases).
git clone https://github.com/XSS3cut10n3r/FVol-MCP-Server.git
pip install -r FVol-MCP-Server/requirements.txt
claude mcp add fvol -e FVOL_PATH=/path/to/fvol -- python3 /path/to/FVol-MCP-Server/fvol_mcp_server.pyEnvironment variables:
FVOL_PATH: fvol binary (default:fvolonPATH)FVOL_SYMBOL_DIRS: symbol dirs for Linux/macOS images,;-separatedFVOL_TIMEOUT: seconds per run (default 600,0= none)
Related MCP server: Volatility MCP Server
Tools
get_image_info, run_pstree, run_pslist, run_psscan, run_netscan, run_malfind, run_cmdline, run_dlllist, run_handles, run_filescan, run_memmap, run_custom_plugin (any plugin, any args), list_available_plugins, list_memory_dumps.
Resources: fvol://plugins, fvol://help/{plugin}.
Prompt
LLMs will invent PIDs, addresses and "findings" if you let them. Start with a prompt like this:
Your task is to perform memory forensics on <PATH TO IMAGE> using the fvol MCP tools. Strategy:
- Start with `get_image_info` to identify the OS, then triage: `run_pstree`, `run_cmdline`, `run_netscan`, `run_malfind`
- Compare `run_pslist` against `run_psscan` to find hidden or terminated processes
- Drill into suspicious processes with `run_dlllist`, `run_handles` and `run_memmap` using their PID
- For any other plugin use `run_custom_plugin`; check `fvol://help/{plugin}` for its options first
- Only report what the tool output shows. Quote the PID, offset or row for every claim. NEVER guess values
- If a plugin errors or returns nothing, say so; don't fill the gap with assumptions
- Write a report.md at the end: timeline, suspicious processes, network indicators, IOCs, and the commands behind each findingLicense
MIT. fvol is separate and licensed under VSL 1.0.
This server cannot be deployed
Maintenance
Related MCP Connectors
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
MCP server for progressive tool usage at any scale (see https://klavis.ai)
A paid remote MCP for agent memory MCP, built to return verdicts, receipts, usage logs, and audit-re
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to perform memory forensics analysis using Volatility 3 through natural language prompts. Supports process listing, network connection analysis, and other memory artifact inspection from memory images.52Apache 2.0
- AlicenseNot gradedqualityFmaintenanceEnables automated memory forensics analysis using Volatility 3, supporting Windows, Linux, and macOS memory dumps through a modular plugin interface.1MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that transforms Claude Code into an autonomous DFIR analyst by providing typed, audited forensic tools for disk, memory, timeline, registry, and IOC analysis on the SANS SIFT Workstation.Apache 2.0
- AlicenseNot gradedqualityDmaintenanceA local MCP server that wraps common forensic command-line tools for CTF/forensics competitions into MCP tools, enabling automated analysis of disk images, memory dumps, network captures, SQLite databases, archives, and steganography.1MIT