Loading connector details…
Loading connector details…
Choose a unique username to continue using AgentHotspot
by x746b • Uncategorized
A Linux-native comprehensive Windows forensics toolkit with zero Windows dependencies.
Perform Windows forensic analysis entirely from Linux environments without Windows dependencies.
Correlate multiple Windows artifact sources to investigate binary execution, user activity, or hunt indicators of compromise.
Integrated malware detection and threat intelligence including YARA scanning and VirusTotal lookups.
Windows Forensics MCP Server enables parsing and analysis of Windows artifacts entirely on Linux using pure Python libraries. It supports a wide range of forensic artifacts including event logs, registry hives, execution evidence, file system metadata, user activity, network forensics, API Monitor captures, and malware detection. The server offers orchestrators for high-level investigations and integrates threat intelligence and malware scanning tools, facilitating efficient and thorough DFIR workflows without requiring Windows tools.