x746b-winforensics
Enables Windows digital forensics analysis by parsing EVTX event logs, registry hives, and remotely collecting artifacts via WinRM for incident response workflows.
- Score
- 75.4672 signals
- Evidence
- 20 stars · 4 forks
- Last commit
- as last read from GitHub; most reads are from 2 Sep 2026 or later
- Listed
Install
No one-command install. Set it up from its source.
Alternatives · MCPs
- thomasxm-crowdsentinel206 stars · 32 forks94.345
- velociraptor-mcp94 stars · 22 forks91.271
- procmon-mcp80 stars · 5 forks86.027
What it is
MCP server Windows Forensics, catalogued on PulseMCP. Enables Windows digital forensics analysis by parsing EVTX event logs, registry hives, and remotely collecting artifacts via WinRM for incident response workflows.
When to use it
Enables Windows digital forensics analysis by parsing EVTX event logs, registry hives, and remotely collecting artifacts via WinRM for incident response workflows.
Notes
Listed from the PulseMCP registry. The registry does not state a license. Check it before production use.