sysinternals-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_PORT | No | Port for HTTP transport. Example: 11074 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| autorunscC | Scan startup programs, scheduled tasks, services, drivers, and browser extensions. Wraps Sysinternals Autorunsc with CSV output parsing. Return Format{"success": bool, "entries": list[dict], "count": int, "error": str | None} |
| autorunsc_scheduleB | Scan only scheduled tasks autoruns (fast subset). Return Format{"success": bool, "entries": list[dict], "count": int} |
| handle64B | List open handles and file locks on the system. Wraps Sysinternals Handle64. Return Format{"success": bool, "handles": list[dict], "count": int, "error": str | None} |
| handle64_by_pidA | List open handles for a specific process by PID. Return Format{"success": bool, "handles": list[dict], "count": int} |
| pslistB | List processes with PID, CPU time, thread count, and handle count. Wraps Sysinternals Pslist. Return Format{"success": bool, "processes": list[dict], "count": int, "error": str | None} |
| pslist_detailC | List details for processes matching a name. Return Format{"success": bool, "processes": list[dict], "count": int} |
| listdllsB | List all loaded DLLs across all processes with version info. Wraps Sysinternals ListDLLs. Return Format{"success": bool, "processes": list[dict], "count": int, "error": str | None} |
| listdlls_by_pidB | List loaded DLLs for a specific process by PID. Return Format{"success": bool, "dlls": list[dict], "count": int} |
| tcpvconA | List all TCP/UDP connections with owning process. Wraps Sysinternals Tcpvcon with CSV output parsing. Return Format{"success": bool, "connections": list[dict], "count": int, "error": str | None} |
| sigcheckB | Verify file digital signatures, version info, and optionally check VirusTotal. Wraps Sysinternals Sigcheck with CSV output parsing. Return Format{"success": bool, "files": list[dict], "count": int, "error": str | None} |
| accesschkC | Check effective permissions on files, directories, registry keys, or services. Wraps Sysinternals AccessChk. Return Format{"success": bool, "entries": list[dict], "count": int, "error": str | None} |
| accesschk_serviceC | Check effective permissions on a specific Windows service. Return Format{"success": bool, "entries": list[dict], "count": int} |
| psloggedonC | List users logged on locally and optionally via network connections. Wraps Sysinternals PsLoggedon. Return Format{"success": bool, "users": list[dict], "count": int, "error": str | None} |
| psloggedon_serverB | List users logged on to a remote server. Return Format{"success": bool, "users": list[dict], "count": int} |
| psfileB | List files opened by remote systems via network shares. Wraps Sysinternals PsFile. Return Format{"success": bool, "files": list[dict], "count": int, "error": str | None} |
| psfile_closeC | Close a file opened by a remote system. Return Format{"success": bool, "message": str} |
| coreinfoB | Show CPU topology, NUMA node layout, cache sizes, and feature flags. Wraps Sysinternals Coreinfo. Return Format{"success": bool, "cpu_topology": list[dict], "features": list[dict], "error": str | None} |
| duA | Show disk usage for a directory tree, broken down by subdirectory. Wraps Sysinternals DU. Uses verbose (-v) output for per-directory breakdown. Return Format{"success": bool, "directories": list[dict], "total": dict, "error": str | None} |
| du_quickA | Quick disk usage summary for a directory (one level, no recursion into children). Return Format{"success": bool, "directories": list[dict], "total": dict} |
| psinfoB | Show detailed system information: OS version, uptime, hotfixes, services. Wraps Sysinternals PsInfo. Return Format{"success": bool, "sections": dict, "raw": str, "error": str | None} |
| psinfo_remoteB | Show system info for a remote computer. Return Format{"success": bool, "sections": dict, "raw": str} |
| rammap_physicalA | Show physical memory usage breakdown by category. RAMMap-style view: active, standby, modified, modified-no-write, transition, zeroed, free, and bad page counts. Also reports total, available, cached, and page-file sizes. Uses a single PowerShell script that queries WMI and performance counters. No binary download required. Return Format{"success": bool, "categories": dict, "totals": dict, "error": str | None} |
| rammap_processesB | Show per-process memory usage: working set, private bytes, shareable, pagefile. RAMMap-style process list sorted by working set descending. Uses Get-Process with WMI extensions for private working set data. No binary download required. Return Format{"success": bool, "processes": list[dict], "count": int, "total_ws_mb": float, "error": str | None} |
| rammap_file_backedB | Show file-backed page cache summary from system working set. Reports cached file extensions, top mapped files, and system cache totals. Uses WMI queries against the operating system cache manager. Return Format{"success": bool, "cache_total_mb": float, "sections": list[dict], "error": str | None} |
| rammap_summaryA | Combined memory diagnostic: physical breakdown + top processes + file cache. One-shot equivalent of calling rammap_physical, rammap_processes (top 10), and rammap_file_backed. Return Format{"success": bool, "physical": dict, "top_processes": list[dict], "file_cache": dict} |
| rammap_treemapA | Generate a WizTree-style interactive treemap of process memory usage. Creates a self-contained HTML file with an embedded D3.js squarified treemap, colored by process category (system, browser, dev, media, etc.) with hover tooltips showing PID, working set, and private bytes. The HTML is fully self-contained (loads D3 from CDN) and opens in any browser. Return Format{"success": bool, "file_path": str, "processes": int, "total_mb": float} Examples |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 26 tools
Most tools target distinct Sysinternals utilities or have clear variant suffixes (local/remote, by_pid, quick, schedule), but some overlap exists (e.g., pslist vs pslist_detail, accesschk vs accesschk_service) where boundaries rely on subtle description cues.
All tool names use consistent snake_case with underscores for variants (e.g., _by_pid, _remote, _service, _quick), and there is no mixing of camelCase or other naming conventions.
With 26 tools, the set exceeds the typical 3-15 range; many are niche variants (e.g., five rammap_* tools, multiple duplicate base operations) making it heavy and potentially overwhelming for an agent to navigate.
The set covers a wide range of Windows diagnostics (processes, DLLs, handles, network, autoruns, memory, disk), but lacks action-oriented tools (e.g., process termination, service control) and some Sysinternals utilities (e.g., pskill, psloglist), leaving minor gaps.