Windows Forensics MCP Server - EVTX parsing, Registry analysis, PE analysis, API Monitor knowledge base, and remote artifact collection for DFIR
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"winforensics-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
<img src="icon.png" width="150" alt="WinForensics MCP"> # Windows Forensics MCP Server > **Windows DFIR from Linux** - A comprehensive forensics toolkit designed entirely for Linux environments with zero Windows tool dependencies. Parse Windows artifacts natively using pure Python libraries. --- ## Related Projects - **[mem_forensics-mcp](https://github.com/x746b/mem_forensics-mcp)** - Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage - **[mac_forensics-mcp](https://github.com/x746b/mac_forensics-mcp)** - macOS DFIR - Unified Logs, FSEvents, Spotlight, Plists, SQLite databases, Extended Attributes --- ## Features ### Core Forensics | Category | Capabilities | |----------|--------------| | **EVTX Logs** | Parse Windows Event Logs with filtering, search, and pre-built security queries | | **Registry** | Analyze SAM, SYSTEM, SOFTWARE, SECURITY, NTUSER.DAT hives | | **Remote Collection** | Collect artifacts via WinRM (password or pass-the-hash) | ### Execution Artifacts | Category | Capabilities | |----------|--------------| | **PE Analysis** | Static analysis with hashes (MD5/SHA1/SHA256/imphash), imports, exports, packer detection | | **Prefetch** | Execution evidence with run counts, timestamps, loaded files | | **Amcache** | SHA1 hashes and first-seen timestamps from Amcache.hve | | **SRUM** | Application resource usage, CPU time, network activity from SRUDB.dat | ### File System Artifacts | Category | Capabilities | |----------|--------------| | **MFT** | Master File Table parsing with ADS metadata and timestomping detection | | **USN Journal** | Change journal for file operations and deleted file recovery | | **Timeline** | Unified timeline from MFT, USN, Prefetch, Amcache, EVTX | ### User Activity | Category | Capabilities | |----------|--------------| | **Browser** | Edge, Chrome, Firefox history and downloads | | **LNK Files** | Windows shortcut analysis for recently accessed files | | **ShellBags** | Fo…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.