winforensics-mcp
A comprehensive MCP server for Windows digital forensics on KALI Linux
WinForensics MCP is a comprehensive forensic toolkit that runs on Linux and natively parses Windows artifacts using pure Python libraries. It covers EVTX logs, registry, execution artifacts, file system, user activity, network forensics, and malware detection. High-level orchestrators enable efficient investigations like execution analysis, user activity correlation, IOC hunting, and timeline building.
Features
Compatibility
Quick start
Use cases
Alternatives
Related searches
Comments
- DDakota WilsonMay 26, 2026
Windows digital forensics on Kali Linux via MCP — investigation tools in AI workflows.
- EEllis JohnsonApr 1, 2026
Good for digital forensics investigators who want AI assistance with Windows evidence.
- DDakota ThompsonMar 17, 2026
Works for authorized forensic investigations on Windows artifacts.
- JJesse LewisMar 8, 2026
Kali Linux base means standard forensics tooling is available alongside MCP.