Skip to main content
Glama
x746b

Windows Forensics MCP Server

by x746b

user_parse_shellbags

Parse ShellBags to reveal folder navigation history, including network shares and ZIP archives, with access timestamps for forensic analysis.

Instructions

Parse ShellBags to reveal folder navigation history, including UNC network shares and the interior of ZIP archives browsed in Explorer. Parses BOTH the UsrClass.dat BagMRU and the matching NTUSER.DAT BagMRU (auto-detected), since some entries exist in only one hive. Reports long folder names, created/modified times and 'last_viewed' (last interacted). Answers: Which folders did the user access? When did they browse suspicious paths? What network shares and archives did they open?

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum number of results
ntuser_pathNoOptional explicit path to the profile's NTUSER.DAT. Auto-detected from the UsrClass.dat location when omitted.
path_filterNoFilter results by path substring (case-insensitive)
usrclass_pathYesPath to UsrClass.dat (typically in Users/<user>/AppData/Local/Microsoft/Windows/UsrClass.dat). An NTUSER.DAT path is also accepted.
include_ntuserNoAlso parse the NTUSER.DAT BagMRU (Desktop namespace, where network share browsing is often recorded). Set false to parse only the given hive.
suspicious_onlyNoOnly return suspicious folder accesses (temp, AppData, network shares, etc.)
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses that the tool parses both hives, auto-detects NTUSER.DAT, handles ZIP archives, and reports timestamps. It implies a read-only, non-destructive operation. However, it does not mention potential failure modes, access requirements, or performance characteristics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise at six sentences, front-loaded with the primary action. Every sentence adds unique value: artifact type, data sources, capabilities, and the questions it answers. No fluff or repetition.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has 6 parameters and no output schema. The description explains the artifact and the types of data returned (folder names, times, last_viewed) but does not describe the exact output structure (e.g., list of objects with fields per result). It also does not explain how parameters like 'limit' or 'path_filter' affect the output. For a tool with no output schema, the description should be more explicit about return format.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. The description adds value by explaining the significance of parsing both hives and the auto-detection logic, which maps to the 'include_ntuser' and 'ntuser_path' parameters. It also provides context for the output fields, helping the agent understand the meaning of parameters like 'suspicious_only' and 'path_filter'.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool parses ShellBags to reveal folder navigation history, including UNC shares and ZIP archives. It specifies parsing both UsrClass.dat and NTUSER.DAT with auto-detection, and explicitly answers the questions the tool addresses. This is a specific verb+resource combination that distinguishes it from sibling tools like user_parse_lnk_files.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context for when to use the tool (when investigating folder access history, network shares, archives) but does not explicitly state when not to use it or mention alternatives. The agent can infer usage from the listed questions, but no direct guidance on sibling tools or exclusion criteria is given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/x746b/winforensics-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server