Windows Forensics

Enables Windows digital forensics analysis by parsing EVTX event logs, registry hives, and remotely collecting artifacts via WinRM

x746b 19
Claude CodeClaude DesktopGeneric
View source ↗

A Windows digital forensics server that enables analysis of Windows artifacts including EVTX event logs and registry hives. Provides tools for parsing Security, System, and Sysmon logs with pre-built security event searches, analyzing SAM/SYSTEM/SOFTWARE registry hives for persistence mechanisms and user accounts, and remotely collecting artifacts via WinRM with password or pass-the-hash authentication. Designed for incident response workflows where analysts need to quickly extract and correlate forensic evidence from Windows systems.

Source

Repository: https://github.com/x746b/winforensics-mcp

Maintain Windows Forensics?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[Windows Forensics on getagentictools](https://getagentictools.com/mcp/x746b-winforensics-mcp?ref=badge)