by x746b · MCP Server · ★ 22
Windows Forensics MCP Server Windows DFIR from Linux - A comprehensive forensics toolkit designed entirely for Linux environments with zero Windows tool dependencies. Parse Windows artifacts natively using pure Python libraries. Related Projects memforensics-mcp - Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage macforensics-mcp - macOS DFIR - Unified Logs, FSEvents, Spotlight, Plists, SQLite databases, Extended Attributes Features Core Forensics Execution Artifacts File System Artifacts |--
| Stars | 22 |
| Forks | 4 |
| Language | YARA |
| Category | MCP Server |
| License | MIT |
| Quality Score | 75.1159175044566/100 |
| Last Updated | 2026-09-19 |
| Created | 2026-01-06 |
| Platforms | mcp |
| Est. Tokens | ~19k |
Explore other popular mcp server tools:
winforensics-mcp is A comprehensive MCP server for Windows digital forensics on KALI Linux. It is categorized as a MCP Server with 22 GitHub stars.
winforensics-mcp is primarily written in YARA. It covers topics such as blueteam-tools, dfir, forensics-tools.
You can find installation instructions and usage details in the winforensics-mcp GitHub repository at github.com/x746b/winforensics-mcp. The project has 22 stars and 4 forks, indicating an active community.
winforensics-mcp is released under the MIT license, making it free to use and modify according to the license terms.