mem-forensics-mcp
Related Servers
Alternatives to mem-forensics-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceA production-grade, type-safe MCP server for memory forensics via Volatility 3, enabling LLM-assisted incident response without timeouts or evidence spoliation.1MIT
- AlicenseNot gradedqualityCmaintenanceA governed MCP server for digital-forensics and incident-response (DFIR) work, exposing curated forensic tools (Volatility 3, Plaso, RegRipper, etc.) through a single FastMCP HTTP endpoint with bearer-token authentication and tamper-evident audit logging.MIT
- AlicenseNot gradedqualityFmaintenanceMCP server for reverse engineering Windows executables and related binary formats, offering static analysis, Ghidra-assisted function recovery, plugin-driven tooling, and optional isolated Windows runtime execution.3 npm241MIT
- AlicenseBqualityDmaintenanceComprehensive forensic analysis MCP server enabling AI agents to analyze files, Chromium and Firefox browser artifacts, with VirusTotal, DIE, Binwalk integrations.51MIT
- FlicenseAqualityCmaintenanceMCP server for read-only forensic analysis of evidence files using local utilities (file, ExifTool, strings, Volatility).3-
- AlicenseNot gradedqualityFmaintenanceEnables automated memory forensics analysis using Volatility 3, supporting Windows, Linux, and macOS memory dumps through a modular plugin interface.1MIT
TDQS
Scored across 15 tools
While most tools target distinct high-level tasks, the generic `memory_run_plugin` overlaps with specialized tools like `memory_find_injected_code` and `memory_get_command_history`, since these can also be replicated via plugin execution. Additionally, `memory_full_triage` and `memory_analyze_image` both serve as entry points for analysis, creating potential confusion despite different workflows.
All tools consistently use the `memory_` prefix and snake_case, with most following a verb_noun pattern (e.g., `list_sessions`, `dump_process`). However, `memory_full_triage` deviates as an adjective_noun phrase, and the mix of `list` vs. `get` for similar enumeration actions (e.g., `list_plugins` vs. `get_process_tree`) introduces minor inconsistency.
With 15 tools, the server sits at the upper boundary of the optimal 3-15 range, but each tool covers a meaningful part of the memory forensics workflow. Administrative tools (list_sessions, get_status, list_plugins) are not redundant, and the count remains manageable for agent navigation.
The toolkit covers major memory forensics tasks including image analysis, process inspection, anomaly detection, code injection, C2 discovery, credential extraction, and memory dumping. The generic `memory_run_plugin` provides extensibility to Vol3 plugins, but a dedicated file extraction tool is missing (only listing is available), and registry analysis is not directly exposed.