Windows Forensics MCP Server
Related Servers
Alternatives to Windows Forensics MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to perform digital forensics analysis including memory analysis, file metadata inspection, and threat-intelligence lookups.3 npmISC
- FlicenseAqualityCmaintenanceEnables AI agents to perform digital forensics and incident response tasks by dynamically discovering and utilizing host tools for memory analysis, metadata extraction, threat detection, and file dissection.51-
- AlicenseNot gradedqualityBmaintenanceEnables autonomous digital forensics and incident response through 21 typed forensic tools covering disk, memory, registry, network, timeline, carving, and patterns, integrated with AI-driven reasoning and self-correction.MIT
- FlicenseNot gradedqualityCmaintenanceEnables local AI models to perform defensive cybersecurity analysis through narrowly scoped read-only tools for host posture, Windows security operations, file/IOC triage, code scanning, and allowlisted filesystem/network access while enforcing boundaries and audit trails.-
- AlicenseNot gradedqualityBmaintenanceEnables Windows event log forensics by wrapping Hayabusa, offering EVTX scanning, Sigma rule exploration, ATT&CK coverage analysis, and detection engineering resources.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to safely perform file operations, run terminal sessions, manage processes, search content, and inspect Git repositories on a local Windows machine under configurable permission and audit controls.Apache 2.0
TDQS
Scored across 45 tools
Most tools target a distinct artifact, but several overlap: api_analyze_imports and api_detect_patterns perform nearly identical PE import pattern detection, evtx_search and evtx_security_search both filter events by different criteria, and registry_search vs registry_query have ambiguous boundaries. The descriptions help, but an agent could easily misselect among these pairs.
The dominant convention is domain_verb_noun (evtx_, registry_, disk_parse_, user_parse_, apmx_), which is consistent. There are a few outliers like build_timeline, ingest_parsed_csv, ioc_pack_list, and windows_search_parse that break the pattern, but naming is still readable and not chaotic.
45 tools is well beyond the typical well-scoped range and feels heavy even for a broad forensics server. While the domain is wide, redundant tools (api_analyze_imports/api_detect_patterns) and six APMX-specific tools suggest the surface could be consolidated into a leaner set.
The set covers an impressive breadth of artifacts: EVTX, registry, PE/imports, APMX, Prefetch, Amcache, SRUM, MFT, USN, browser history, LNK, ShellBags, and cross-artifact correlation. Minor gaps exist (no memory forensics, ShimCache, or dedicated YARA scanning), but core forensic workflows are well supported.