AgentIndex icon
AgentIndex
ToolsCategoriesTrendingNewCompare
Submit Tool
Home/
Dev Tooling/
winforensics-mcp
winforensics-mcp logo

winforensics-mcp

Active·★ 18·MIT·Updated 2026-05-21
★ Trending★ API Integration

A comprehensive MCP server for Windows digital forensics on KALI Linux

WinForensics MCP is a comprehensive forensic toolkit that runs on Linux and natively parses Windows artifacts using pure Python libraries. It covers EVTX logs, registry, execution artifacts, file system, user activity, network forensics, and malware detection. High-level orchestrators enable efficient investigations like execution analysis, user activity correlation, IOC hunting, and timeline building.

#blueteam-tools#dfir#forensics-tools#mcp-server#mcp-servers#windows-forensics
$ Install
$ curl -LsSf https://astral.sh/uv/install.sh | sh && source ~/.bashrc && uv tool install winforensics-mcp
↗ Visit site★ GitHub
01

Features

01Core forensics: EVTX log parsing, registry analysis, remote collection via WinRM
02Execution artifacts: PE analysis, Prefetch, Amcache, SRUM parsing
03File system artifacts: MFT, USN Journal, timeline building
04User activity: Browser history, LNK files, ShellBags, RecentDocs
05Malware detection: YARA scanning, VirusTotal lookup, DiE packer detection
02

Compatibility

Linux
Linux
Verified via docs
03

Quick start

1
$ curl -LsSf https://astral.sh/uv/install.sh | sh
2
$ source ~/.bashrc
3
$ uv tool install winforensics-mcp
04

Use cases

↳Determine if a specific binary was executed on a Windows system
↳Reconstruct user activity timeline from browser, shellbags, and shortcuts
↳Search for indicators of compromise (hashes, filenames, IPs, domains) across all artifacts
05

Alternatives

fastmcp logo
fastmcp★ 25.4k
🚀 The fast, Pythonic way to build MCP servers and clients.
vs →
MCP-Chinese-Getting-Started-Guide logo
MCP-Chinese-Getting-Started-Guide★ 3.5k
Model Context Protocol(MCP) 编程极速入门
vs →
FunASR logo
FunASR★ 16.6k
Industrial-grade speech recognition toolkit: 170x realtime, 50+ languages, speaker diarization, emotion detection, streaming, and OpenAI-compatible API.
vs →
nuclear logo
nuclear★ 17.7k
Streaming music player that finds free music for you
vs →
semble logo
semble★ 4.5k
Fast and Accurate Code Search for Agents
vs →
thunderbit-mcp-server logo
thunderbit-mcp-server★ 13
AI-powered web scraping and structured data extraction. CLI + MCP server + Claude Code plugin for the Thunderbit Open API.
vs →
ninjaone-mcp logo
ninjaone-mcp★ 16
MCP server for NinjaOne — device monitoring, patching, scripting, and alert management tools for AI assistants
vs →
onetool-mcp logo
onetool-mcp★ 19
🧿 One MCP for developers - no tool tax, no context rot. 100+ tools including Brave, Google, Context7, Excalidraw, AWS, Version Checker, Excel, File Ops, Database, Playwright, Chrome DevTools and many more.
vs →
See all alternatives →

Related searches

winforensics-mcp AlternativesBest Dev Tooling Tools 2026Open Source Dev Toolingwinforensics-mcp Tutorialwinforensics-mcp Vs Competitorsblueteam-toolsdfirforensics-tools

Comments

Log in to leave a comment
  • D
    Dakota WilsonMay 26, 2026

    Windows digital forensics on Kali Linux via MCP — investigation tools in AI workflows.

  • E
    Ellis JohnsonApr 1, 2026

    Good for digital forensics investigators who want AI assistance with Windows evidence.

  • D
    Dakota ThompsonMar 17, 2026

    Works for authorized forensic investigations on Windows artifacts.

  • J
    Jesse LewisMar 8, 2026

    Kali Linux base means standard forensics tooling is available alongside MCP.

On this page
01Features02Compatibility03Quick start04Use cases05Alternatives
Stats
GitHub Stars★ 18
Last commit1w ago
StatusActive
LicenseMIT
CategoryDev Tooling
Trend (30d)
+0.7↑ 0.7%
Links
Documentation↗Discussion↗Issues↗Releases↗

Deploy on DigitalOcean — Get $200 Free Credit

Ad
© 2026 AgentIndex.app|Built by a 10-year iOS Developer.
QYSGitHubBuy me a coffee ☕

Browse by Category

Code AssistantWorkflow AutomationRAG / Knowledge BaseMulti-AgentBrowser AutomationLLM InfraDev ToolingObservability

Not affiliated with Anthropic, OpenAI or Microsoft.