{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_ew67quv9nn9g","handle":"winforensics-mcp","url":"https://wellknown.network/agents/winforensics-mcp","links":{"self":"https://wellknown.network/agents/winforensics-mcp/record.json","html":"https://wellknown.network/agents/winforensics-mcp","markdown":"https://wellknown.network/agents/winforensics-mcp/record.md","api":"https://wellknown.network/api/v1/agents/winforensics-mcp","status":"https://wellknown.network/api/v1/agents/winforensics-mcp/status","claim":"https://wellknown.network/agents/winforensics-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/winforensics-mcp/claim.json","badge":"https://wellknown.network/agents/winforensics-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:winforensics-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"winforensics-mcp","summary":"Windows Forensics MCP Server - EVTX parsing, Registry analysis, PE analysis, API Monitor knowledge base, and remote artifact collection for DFIR","description":"<img src=\"icon.png\" width=\"150\" alt=\"WinForensics MCP\">\n\n# Windows Forensics MCP Server\n\n> **Windows DFIR from Linux** - A comprehensive forensics toolkit designed entirely for Linux environments with zero Windows tool dependencies. Parse Windows artifacts natively using pure Python libraries.\n\n---\n\n## Related Projects\n\n- **[mem_forensics-mcp](https://github.com/x746b/mem_forensics-mcp)** - Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage\n- **[mac_forensics-mcp](https://github.com/x746b/mac_forensics-mcp)** - macOS DFIR - Unified Logs, FSEvents, Spotlight, Plists, SQLite databases, Extended Attributes\n\n---\n\n## Features\n\n### Core Forensics\n| Category | Capabilities |\n|----------|--------------|\n| **EVTX Logs** | Parse Windows Event Logs with filtering, search, and pre-built security queries |\n| **Registry** | Analyze SAM, SYSTEM, SOFTWARE, SECURITY, NTUSER.DAT hives |\n| **Remote Collection** | Collect artifacts via WinRM (password or pass-the-hash) |\n\n### Execution Artifacts\n| Category | Capabilities |\n|----------|--------------|\n| **PE Analysis** | Static analysis with hashes (MD5/SHA1/SHA256/imphash), imports, exports, packer detection |\n| **Prefetch** | Execution evidence with run counts, timestamps, loaded files |\n| **Amcache** | SHA1 hashes and first-seen timestamps from Amcache.hve |\n| **SRUM** | Application resource usage, CPU time, network activity from SRUDB.dat |\n\n### File System Artifacts\n| Category | Capabilities |\n|----------|--------------|\n| **MFT** | Master File Table parsing with ADS metadata and timestomping detection |\n| **USN Journal** | Change journal for file operations and deleted file recovery |\n| **Timeline** | Unified timeline from MFT, USN, Prefetch, Amcache, EVTX |\n\n### User Activity\n| Category | Capabilities |\n|----------|--------------|\n| **Browser** | Edge, Chrome, Firefox history and downloads |\n| **LNK Files** | Windows shortcut analysis for recently accessed files |\n| **ShellBags** | Fo…","publisher":{"name":"xtk","url":null},"homepage":null,"repository":null,"version":"1.4.1","license":"MIT","protocols":["mcp"],"tags":["api-monitor","dfir","evtx","forensics","incident-response","malware","mcp","pe-analysis","registry","windows"],"pricing":null,"endpoints":[{"url":"pypi:winforensics-mcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","summary":"pypi","version":"pypi","description":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":0.882,"provenance":"derived"},{"slug":"dev.filesystem","name":"Filesystem","confidence":0.825,"provenance":"derived"},{"slug":"data.database","name":"Databases","confidence":0.802,"provenance":"derived"},{"slug":"infra.browser-automation","name":"Browser Automation","confidence":0.791,"provenance":"derived"}],"categories":["data","dev","infra"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"winforensics-mcp","registry":"pypi","observedAt":"2026-09-10T15:25:33.709Z","publishedAt":"2026-08-17T14:48:10.088739Z","latestVersion":"1.4.1"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"winforensics-mcp","url":"https://pypi.org/project/winforensics-mcp/","firstSeenAt":"2026-09-10T15:24:51.987Z","fetchedAt":"2026-09-10T15:24:51.987Z","normalizedAt":"2026-09-10T15:24:51.987Z"}]},"firstSeenAt":"2026-09-10T15:24:51.987Z","updatedAt":"2026-09-10T15:25:33.709Z"}