Loading connector details…
Loading connector details…
Choose a unique username to continue using AgentHotspot
by mgreen27 • Automation & Orchestration
A proof-of-concept MCP bridge that exposes Velociraptor server functionality to MCP clients for Windows triage and forensic queries.
Collect and inspect network connections on a specific Windows host and flag suspicious processes.
Locate and enumerate forensic artifacts (for example, those targeting the USN journal) across managed hosts.
Run Velociraptor collections remotely via an MCP client and return triage results for analyst review.
This repository implements a POC Model Context Protocol (MCP) bridge to allow MCP clients (e.g., Claude desktop) to query Velociraptor servers and retrieve forensic/triage data from endpoints. It includes Windows-oriented collections and helper code to query machines by name (for example, list network connections or search for artifacts targeting the USN journal). Installation and API client setup instructions are provided, and the README calls out caveats about data volume, context windows, and dynamic collection creation.
Scores are informational only and provided “as is” without warranty. AgentHotspot assumes no liability for actions taken based on these ratings.