Model Context Protocol server for Velociraptor DFIR integration
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-socfortress-velociraptor-mcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Velociraptor MCP Server A production-ready **Model Context Protocol (MCP) server** for seamless integration between Velociraptor DFIR and Large Language Models (LLMs). [](https://github.com/socfortress/velociraptor-mcp-server/actions) [](https://www.python.org/downloads/) [](https://www.youtube.com/@taylorwalton_socfortress/videos) [](https://www.socfortress.co/contact_form.html) > **Why?** > Combine the power of Velociraptor's comprehensive digital forensics and incident response capabilities with the reasoning capabilities of large language models—enabling natural language queries and intelligent analysis of your forensic data. --- ## ✨ Key Features - 🚀 **Production-ready**: Proper package structure, logging, error handling, and configuration management - 🔐 **Secure**: JWT token management with automatic refresh - 🌐 **HTTP/2 Support**: Built on modern async HTTP client with connection pooling - 📊 **Comprehensive API**: Access Velociraptor artifacts, hunts, collections, and more - 🎛️ **Configurable**: Environment variables, CLI arguments, and fine-grained tool filtering - 📦 **Pip installable**: Install directly from GitHub releases or source --- ## Table of Contents - [Quick Start](#quick-start) - [Installation](#installation) - [Configuration](#configuration) - [Usage](#usage) - [Available Tools](#available-tools) - [Development](#development) - [CI/CD](#continuous-integration) - [Deployment](#deployment) - [Security](#security-considerations) - [Contributing](#contributing) - [License](#license) --- ## Quick Start ### 1. Install #### From GitHu…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.