Procmon
18-tool Windows process monitoring MCP server for security researchers, covering ETW tracing, PE analysis, event logs, services, a
Provides AI assistants with deep access to Windows internals through 18 tools spanning live process state monitoring, ETW kernel tracing, PE file import/export analysis, Windows Event Log retrieval, service enumeration, driver inspection, and minifilter analysis. Designed for security researchers and reverse engineers working on controlled systems. Published on PyPI as procmon-mcp and executable via uvx without installation; requires Windows administrator privileges.
Source
Repository: https://github.com/0xhackerfren/procmon-mcp
Maintain Procmon?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[Procmon on getagentictools](https://getagentictools.com/mcp/0xhackerfren-procmon-mcp?ref=badge)