Self-Assembling Forensic MCP Server

Self-Assembling Forensic MCP Server

Enables AI assistants to perform digital forensics analysis including memory analysis, file metadata inspection, and threat-intelligence lookups.

Category
访问服务器

README

Self-Assembling Forensic MCP Server

Self-Assembling Forensic MCP Server is an MCP (Model Context Protocol) server that gives AI assistants — Claude, Cursor, and any MCP-compatible client — real, executable digital-forensics capabilities: memory analysis, file metadata inspection, and threat-intelligence lookups. It is built with the NitroStack SDK and deployed on NitroCloud.

Table of Contents

Overview

The Problem

DFIR (digital forensics and incident response) teams rely on a fragmented toolbox — Volatility for memory forensics, exiftool for metadata, tshark for network capture, objdump for binary analysis, binwalk for carving, steghide for steganography — and no two machines carry the same set. Jump-boxes, SOC laptops, cloud sandboxes, and honeypot collectors all differ. Existing approaches either hardcode brittle integrations that crash when a tool is missing, or force bloated all-in-one distros just for consistency. Connecting a private, self-hosted LLM to this evidence via MCP has typically meant hand-wiring the integration per machine — if a utility is absent, the server breaks, causing costly delays during time-sensitive incidents.

The Solution

This framework adds a runtime capability-discovery layer that flips the integration model. At startup, the server inspects the host — probing binaries, environment paths, and container engines, including health checks like verifying an operational Docker daemon instead of relying on a fragile host Python install — to learn exactly what's usable.

It then runs three automated steps: Discovery & Verification (scan and validate local or containerized tools), Dynamic Mapping (map each tool's inputs/outputs to standard MCP tool definitions), and Context Assembly (self-assemble matching Tools, Resources, and triage Prompts).

Missing utilities are skipped gracefully rather than crashing the server, and evidence never leaves the local perimeter — making it suited to air-gapped, high-compliance environments. Because it's built on NitroStack's decorator-based SDK, this pattern can itself become a reusable template: scaling to new tools or commercial forensic suites needs only a manifest update, not a rebuild.

What is MCP?

The Model Context Protocol (MCP) is an open standard that lets AI assistants securely connect to external tools, data sources, and services. Instead of being limited to what it was trained on, an AI model can call MCP servers to fetch live data, run real analysis, and integrate with real systems. This project is one such MCP server, purpose-built for forensic evidence analysis.

Features

  • 🔌 MCP-native — works with any MCP-compatible client (Claude, Cursor, and more)
  • 🧠 Volatility-backed memory forensics — runs real Volatility 3 plugins against Windows memory dumps via an isolated Docker container (forensic-vol), avoiding host Python/environment conflicts entirely
  • 🛡️ Threat intelligence lookups — file hash reputation checks with a safe offline fixture for known test hashes
  • 📋 Chain-of-custody logging — every analysis operation is recorded to an append-only case log
  • 🩺 Self-reporting health checks — the server exposes its own operational status and tool availability as MCP resources
  • ⚡ Deployed on NitroCloud — reliable, hosted, and instantly shareable
  • 🔐 Secure by design — secrets (like API keys) stay in environment variables, never in code

Tools

(7 tools currently registered)

Tool Description
extract-metadata Extract metadata from a file using exiftool, compute a SHA-256 hash, and check for MIME-type mismatch
extract-strings Extract readable strings from a file and scan for suspicious patterns (IPs, URLs, keywords)
check-threat-intel Check a file hash's reputation against threat-intelligence databases
windows-image-info Get OS and memory-image metadata from a Windows memory dump via the Docker forensic-vol image (Volatility 3 windows.info). Requires Docker and a built forensic-vol image — call this first when analyzing a dump
windows-pslist List processes from a Windows memory dump via Docker forensic-vol (windows.pslist: PID, PPID, name, etc.)
windows-cmdline Extract process command lines from a Windows memory dump via Docker forensic-vol (windows.cmdline)
windows-registry-hivelist List registry hives in a Windows memory dump via Docker forensic-vol (windows.registry.hivelist)

All four windows-* tools share a single execution path (runPlugin()), which spawns Volatility inside the forensic-vol Docker container rather than relying on a host Python installation — this is what makes them resilient to the environment-pollution issues that break host-based Python/Volatility setups.

Resources

(7 resources currently registered)

Resource URI Description
Magic Bytes Reference signatures://magic-bytes Reference table of file extensions mapped to expected magic bytes and MIME types
Analysis Log case://analysis-log Append-only chain-of-custody log for all forensic analysis operations
Forensic Tools Health Check health://forensic-tools Verifies that all required forensic tools are installed and available
Volatility Plugin Map memory://volatility-plugins Maps MCP tools to the Volatility 3 plugins run via the Docker forensic-vol image
Analysis Report /widgets/analysis-report UI component for rendering an analysis report
Health Checks health://checks Current health status of all registered health checks
Widget Examples widget://examples Metadata and examples for all registered UI widgets

Prompts

(3 prompts currently registered)

Prompt Args Description
full-file-analysis filePath, evidenceType Comprehensive file-analysis workflow template
memory-dump-analysis dumpPath Chains windows-image-info, windows-pslist, windows-cmdline, and windows-registry-hivelist for a full memory-dump review (via Docker forensic-vol)
memory-help dumpPath Guidance on how to analyze a Windows memory dump with the four Volatility-backed tools (Docker)

Live Demo

🚀 Live MCP endpoint: https://forensics-6a5ab163-nexora-amrita-university-amritapuri-campus.app.nitrocloud.ai

Point your MCP client at the endpoint above to try it instantly.

Getting Started

Prerequisites

  • Node.js 18+
  • Docker (required for Volatility-backed tools — the forensic-vol image must be built before memory-analysis tools will run)
  • An MCP-compatible client (Claude Desktop, Cursor, etc.)

Installation

git clone https://github.com/your-username/forensic-artifact-investigator.git
cd forensics
npm install

Configuration

Copy the example environment file and add your own values (e.g. VIRUSTOTAL_API_KEY for live threat-intel lookups):

cp .env.example .env

Build the Volatility container (required for memory tools)

docker build -t forensic-vol -f docker/volatility.Dockerfile .

Run

npm run start

Connect to an MCP Client

{
  "mcpServers": {
    "self-assembling-forensic-mcp-server": {
      "url": "https://forensics-6a5ab163-nexora-amrita-university-amritapuri-campus.app.nitrocloud.ai"
    }
  }
}

Restart your client and the tools, resources, and prompts above will be available to your AI assistant.

Architecture Notes

  • Memory-forensics tools run entirely inside an isolated Docker container (python:3.12-slim + volatility3, ENTRYPOINT ["vol"]), avoiding the host-Python environment pollution that previously caused No module named 'encodings' errors under Studio's runtime.
  • All four Windows memory tools share one execution helper (runPlugin()) — there is no independent host python3/vol.py fallback path.
  • Health-check resources (health://forensic-tools, health://checks) let a calling model — or an operator — confirm which tools are actually usable on this deployment before attempting an analysis.
  • The case log (case://analysis-log) provides an append-only record suitable for chain-of-custody documentation.

Roadmap

The current deployment covers memory forensics, metadata/string extraction, and threat intelligence. Planned additions, gated the same way (only registered if the underlying binary/capability is detected):

  • analyze-binary-sections (objdump) — section headers and disassembly snippets
  • analyze-network-capture (tshark) — protocol hierarchy and IP conversation summaries
  • carve-embedded-files (binwalk) — embedded file/signature extraction
  • detect-hidden-data (steghide) — steganography detection
  • Extending the same detection-and-mapping model to standard commercial forensic suites (e.g. Cyber Triage's CLI), which would only require new registry entries, not a core architecture change

FAQ

What is an MCP server?

An MCP server implements the Model Context Protocol to expose tools, resources, and prompts that AI assistants can call, letting an AI model take real actions and access live data.

What does Self-Assembling Forensic MCP Server do?

It gives an AI assistant real forensic capabilities — Volatility-backed Windows memory analysis via Docker, file metadata and string extraction, and threat-intelligence hash lookups — self-assembled at startup based on what's actually available on the host, rather than a fixed, hardcoded tool list.

Which AI clients does this work with?

Any MCP-compatible client, including Claude Desktop and Cursor.

Why Docker for the memory-forensics tools?

Running Volatility inside an isolated container avoids environment-variable pollution (e.g. PYTHONHOME, PYTHONPATH) that breaks a host Python installation under certain runtimes. It collapses the failure surface to one simple check — is Docker installed and running — with a clean, reported skip if not.

How do I deploy my own MCP app?

Use Nitrostack to build, deploy, and host MCP apps without managing infrastructure.

Keywords

Digital Forensics · DFIR · Volatility · Memory Forensics · MCP · Model Context Protocol · MCP server · AI tools · AI agents · LLM tools · Claude MCP · Nitrostack · NitroCloud · Docker · Threat Intelligence

License

MIT © 2026


Built with ❤️ using the Model Context Protocol on Nitrostack.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选