VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.
Velociraptor MCP is a POC Model Context Protocol bridge for exposing LLMs to MCP clients.
Initial version has several Windows orientated triage tools deployed. Best use is querying usecase to target machine name.
e.g
can you give me all network connections on MACHINENAME and look for suspicious processes?
can you tell me which artifacts target the USN journal
https://docs.velociraptor.app/docs/server_automation/server_api/
Generate an api config file:
velociraptor --config /etc/velociraptor/server.config.yaml config api_client --name api --role administrator,api api_client.yaml
The easiest configuration is to run your venv python directly calling mcp_velociraptor_bridge.
"mcpServers": {
"velociraptor": {
"command": "/path/to/venv/bin/python",
"args": [
"/path/to/mcp_velociraptor_bridge.py"
]
}
}
}
Due to the nature of DFIR, results depend on amount of data returned, model use and context window.
I have included a function to find artifacts and dynamically create collections but had mixed results. I have been pleasantly surprised with some results and disappointed when running other collections that cause lots of rows.
Please let me know how you go and feel free to add PR!
can you give me all network connections on MACHINENAME and look for suspicious processes?
can you tell me which artifacts target the USN journal
{
"mcpServers": {
"mcp-velociraptor": {
"command": "/path/to/venv/bin/python",
"args": [
"/path/to/mcp_velociraptor_bridge.py"
]
}
}
}Related projects feature coming soon
Will recommend related projects based on sub-categories