关于
WinForensics is a powerful Model Context Protocol (MCP) server designed to streamline Windows digital forensics investigations with AI assistance. It allows forensic analysts to parse, analyze, and query various Windows artifacts, such as Event Logs (EVTX) and Registry hives, directly from AI clients like Claude CLI or Gemini CLI. The server also supports remote artifact collection via WinRM, provides built-in forensic reference knowledge, and enables efficient hunting for suspicious activities, enhancing the speed and depth of forensic analysis.