Skip to main content
Glama
sandraschi

sysinternals-mcp

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_PORTNoPort for HTTP transport. Example: 11074

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
extensions
{
  "io.modelcontextprotocol/ui": {}
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
autorunscC

Scan startup programs, scheduled tasks, services, drivers, and browser extensions.

Wraps Sysinternals Autorunsc with CSV output parsing.

Return Format

{"success": bool, "entries": list[dict], "count": int, "error": str | None}

autorunsc_scheduleB

Scan only scheduled tasks autoruns (fast subset).

Return Format

{"success": bool, "entries": list[dict], "count": int}

handle64B

List open handles and file locks on the system.

Wraps Sysinternals Handle64.

Return Format

{"success": bool, "handles": list[dict], "count": int, "error": str | None}

handle64_by_pidA

List open handles for a specific process by PID.

Return Format

{"success": bool, "handles": list[dict], "count": int}

pslistB

List processes with PID, CPU time, thread count, and handle count.

Wraps Sysinternals Pslist.

Return Format

{"success": bool, "processes": list[dict], "count": int, "error": str | None}

pslist_detailC

List details for processes matching a name.

Return Format

{"success": bool, "processes": list[dict], "count": int}

listdllsB

List all loaded DLLs across all processes with version info.

Wraps Sysinternals ListDLLs.

Return Format

{"success": bool, "processes": list[dict], "count": int, "error": str | None}

listdlls_by_pidB

List loaded DLLs for a specific process by PID.

Return Format

{"success": bool, "dlls": list[dict], "count": int}

tcpvconA

List all TCP/UDP connections with owning process.

Wraps Sysinternals Tcpvcon with CSV output parsing.

Return Format

{"success": bool, "connections": list[dict], "count": int, "error": str | None}

sigcheckB

Verify file digital signatures, version info, and optionally check VirusTotal.

Wraps Sysinternals Sigcheck with CSV output parsing.

Return Format

{"success": bool, "files": list[dict], "count": int, "error": str | None}

accesschkC

Check effective permissions on files, directories, registry keys, or services.

Wraps Sysinternals AccessChk.

Return Format

{"success": bool, "entries": list[dict], "count": int, "error": str | None}

accesschk_serviceC

Check effective permissions on a specific Windows service.

Return Format

{"success": bool, "entries": list[dict], "count": int}

psloggedonC

List users logged on locally and optionally via network connections.

Wraps Sysinternals PsLoggedon.

Return Format

{"success": bool, "users": list[dict], "count": int, "error": str | None}

psloggedon_serverB

List users logged on to a remote server.

Return Format

{"success": bool, "users": list[dict], "count": int}

psfileB

List files opened by remote systems via network shares.

Wraps Sysinternals PsFile.

Return Format

{"success": bool, "files": list[dict], "count": int, "error": str | None}

psfile_closeC

Close a file opened by a remote system.

Return Format

{"success": bool, "message": str}

coreinfoB

Show CPU topology, NUMA node layout, cache sizes, and feature flags.

Wraps Sysinternals Coreinfo.

Return Format

{"success": bool, "cpu_topology": list[dict], "features": list[dict], "error": str | None}

duA

Show disk usage for a directory tree, broken down by subdirectory.

Wraps Sysinternals DU. Uses verbose (-v) output for per-directory breakdown.

Return Format

{"success": bool, "directories": list[dict], "total": dict, "error": str | None}

du_quickA

Quick disk usage summary for a directory (one level, no recursion into children).

Return Format

{"success": bool, "directories": list[dict], "total": dict}

psinfoB

Show detailed system information: OS version, uptime, hotfixes, services.

Wraps Sysinternals PsInfo.

Return Format

{"success": bool, "sections": dict, "raw": str, "error": str | None}

psinfo_remoteB

Show system info for a remote computer.

Return Format

{"success": bool, "sections": dict, "raw": str}

rammap_physicalA

Show physical memory usage breakdown by category.

RAMMap-style view: active, standby, modified, modified-no-write, transition, zeroed, free, and bad page counts. Also reports total, available, cached, and page-file sizes.

Uses a single PowerShell script that queries WMI and performance counters. No binary download required.

Return Format

{"success": bool, "categories": dict, "totals": dict, "error": str | None}

rammap_processesB

Show per-process memory usage: working set, private bytes, shareable, pagefile.

RAMMap-style process list sorted by working set descending.

Uses Get-Process with WMI extensions for private working set data. No binary download required.

Return Format

{"success": bool, "processes": list[dict], "count": int, "total_ws_mb": float, "error": str | None}

rammap_file_backedB

Show file-backed page cache summary from system working set.

Reports cached file extensions, top mapped files, and system cache totals. Uses WMI queries against the operating system cache manager.

Return Format

{"success": bool, "cache_total_mb": float, "sections": list[dict], "error": str | None}

rammap_summaryA

Combined memory diagnostic: physical breakdown + top processes + file cache.

One-shot equivalent of calling rammap_physical, rammap_processes (top 10), and rammap_file_backed.

Return Format

{"success": bool, "physical": dict, "top_processes": list[dict], "file_cache": dict}

rammap_treemapA

Generate a WizTree-style interactive treemap of process memory usage.

Creates a self-contained HTML file with an embedded D3.js squarified treemap, colored by process category (system, browser, dev, media, etc.) with hover tooltips showing PID, working set, and private bytes.

The HTML is fully self-contained (loads D3 from CDN) and opens in any browser.

Return Format

{"success": bool, "file_path": str, "processes": int, "total_mb": float}

Examples

rammap_treemap(top_n=100, min_ws_mb=0.5)

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 26 tools

Disambiguation4/5

Most tools target distinct Sysinternals utilities or have clear variant suffixes (local/remote, by_pid, quick, schedule), but some overlap exists (e.g., pslist vs pslist_detail, accesschk vs accesschk_service) where boundaries rely on subtle description cues.

Naming Consistency5/5

All tool names use consistent snake_case with underscores for variants (e.g., _by_pid, _remote, _service, _quick), and there is no mixing of camelCase or other naming conventions.

Tool Count2/5

With 26 tools, the set exceeds the typical 3-15 range; many are niche variants (e.g., five rammap_* tools, multiple duplicate base operations) making it heavy and potentially overwhelming for an agent to navigate.

Completeness4/5

The set covers a wide range of Windows diagnostics (processes, DLLs, handles, network, autoruns, memory, disk), but lacks action-oriented tools (e.g., process termination, service control) and some Sysinternals utilities (e.g., pskill, psloglist), leaving minor gaps.

Maintenance

ActivityMaintained
ResponsivenessNo issues