Skip to main content
Glama
XSS3cut10n3r

FVol MCP Server

by XSS3cut10n3r

FVol MCP Server

MCP server that exposes fvol (Rust port of Volatility 3) plugins as tools for Claude and other MCP clients. Fork of Volatility-MCP-Server.

Setup

Requires Linux, Python 3.10+, and the fvol binary (releases).

git clone https://github.com/XSS3cut10n3r/FVol-MCP-Server.git
pip install -r FVol-MCP-Server/requirements.txt
claude mcp add fvol -e FVOL_PATH=/path/to/fvol -- python3 /path/to/FVol-MCP-Server/fvol_mcp_server.py

Environment variables:

  • FVOL_PATH: fvol binary (default: fvol on PATH)

  • FVOL_SYMBOL_DIRS: symbol dirs for Linux/macOS images, ;-separated

  • FVOL_TIMEOUT: seconds per run (default 600, 0 = none)

Related MCP server: Volatility MCP Server

Tools

get_image_info, run_pstree, run_pslist, run_psscan, run_netscan, run_malfind, run_cmdline, run_dlllist, run_handles, run_filescan, run_memmap, run_custom_plugin (any plugin, any args), list_available_plugins, list_memory_dumps.

Resources: fvol://plugins, fvol://help/{plugin}.

Prompt

LLMs will invent PIDs, addresses and "findings" if you let them. Start with a prompt like this:

Your task is to perform memory forensics on <PATH TO IMAGE> using the fvol MCP tools. Strategy:

- Start with `get_image_info` to identify the OS, then triage: `run_pstree`, `run_cmdline`, `run_netscan`, `run_malfind`
- Compare `run_pslist` against `run_psscan` to find hidden or terminated processes
- Drill into suspicious processes with `run_dlllist`, `run_handles` and `run_memmap` using their PID
- For any other plugin use `run_custom_plugin`; check `fvol://help/{plugin}` for its options first
- Only report what the tool output shows. Quote the PID, offset or row for every claim. NEVER guess values
- If a plugin errors or returns nothing, say so; don't fill the gap with assumptions
- Write a report.md at the end: timeline, suspicious processes, network indicators, IOCs, and the commands behind each finding

License

MIT. fvol is separate and licensed under VSL 1.0.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform memory forensics analysis using Volatility 3 through natural language prompts. Supports process listing, network connection analysis, and other memory artifact inspection from memory images.
    52
    Apache 2.0
  • A
    license
    Not graded
    quality
    F
    maintenance
    Enables automated memory forensics analysis using Volatility 3, supporting Windows, Linux, and macOS memory dumps through a modular plugin interface.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that transforms Claude Code into an autonomous DFIR analyst by providing typed, audited forensic tools for disk, memory, timeline, registry, and IOC analysis on the SANS SIFT Workstation.
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    A local MCP server that wraps common forensic command-line tools for CTF/forensics competitions into MCP tools, enabling automated analysis of disk images, memory dumps, network captures, SQLite databases, archives, and steganography.
    1
    MIT