mac_forensics-mcp
Related Servers
Alternatives to mac_forensics-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceA governed MCP server for digital-forensics and incident-response (DFIR) work, exposing curated forensic tools (Volatility 3, Plaso, RegRipper, etc.) through a single FastMCP HTTP endpoint with bearer-token authentication and tamper-evident audit logging.MIT
- AlicenseNot gradedqualityDmaintenanceA local MCP server that wraps common forensic command-line tools for CTF/forensics competitions into MCP tools, enabling automated analysis of disk images, memory dumps, network captures, SQLite databases, archives, and steganography.1MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that transforms Claude Code into an autonomous DFIR analyst by providing typed, audited forensic tools for disk, memory, timeline, registry, and IOC analysis on the SANS SIFT Workstation.Apache 2.0
- AlicenseBqualityBmaintenanceMulti-tier memory forensics MCP server combining a fast Rust engine with Volatility3 coverage for analyzing memory dumps.156MIT
- FlicenseAqualityCmaintenanceMCP server for read-only forensic analysis of evidence files using local utilities (file, ExifTool, strings, Volatility).3-
- AlicenseNot gradedqualityCmaintenanceA local observation-only MCP server for macOS that provides secure, atomic evidence capture with strict target approval and manifest-based output.1MIT
TDQS
Scored across 23 tools
Each tool targets a distinct forensic artifact or operation (e.g., timeline vs. statistics vs. search), with detailed descriptions that clearly differentiate them. There is no functional overlap or ambiguity.
All tool names follow a uniform 'mac_verb_noun' pattern using snake_case, with verbs like build, get, search, parse, list, etc. No mixing of styles or inconsistent conventions.
With 23 tools, the count is slightly above the typical 3-15 range but justified by the breadth of macOS forensics, covering logs, databases, plists, file system events, and more.
The toolkit covers major forensic artifacts: file system, logs, user accounts, browser history, application usage, permissions, and plists. Includes discovery and correlation tools, leaving no obvious gaps for standard triage.