Skip to main content

Velociraptor MCP

Velociraptor MCP is a POC Model Context Protocol bridge for exposing LLMs to MCP clients.

Initial version has several Windows orientated triage tools deployed. Best use is querying usecase to target machine name.

e.g

can you give me all network connections on MACHINENAME and look for suspicious processes?

can you tell me which artifacts target the USN journal

Installation

1. Setup an API account

https://docs.velociraptor.app/docs/server_automation/server_api/

Generate an api config file:

velociraptor --config /etc/velociraptor/server.config.yaml config api_client --name api --role administrator,api api_client.yaml

2. Clone mcp-velociraptor repo and test API

  • copy api_client.yaml to preferred config location and ensure configuration correct (pointing to appropriate IP address).
  • modify test_api.py to appropriate location.
  • Run test_api.py to confirm working
  • Modify mcp_velociraptor_bridge.py to correct API config

3. Connect to Claude desktop or MCP client of choice

The easiest configuration is to run your venv python directly calling mcp_velociraptor_bridge.

  "mcpServers": {
    "velociraptor": {
      "command": "/path/to/venv/bin/python",
      "args": [
        "/path/to/mcp_velociraptor_bridge.py"
      ]
    }
  }
}

image

3. Caveats

Due to the nature of DFIR, results depend on amount of data returned, model use and context window.

I have included a function to find artifacts and dynamically create collections but had mixed results. I have been pleasantly surprised with some results and disappointed when running other collections that cause lots of rows.

Please let me know how you go and feel free to add PR!

can you give me all network connections on MACHINENAME and look for suspicious processes? image image image

can you tell me which artifacts target the USN journal image

Metadata

Release files for iflow-mcp_mgreen27-mcp-velociraptor 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iflow-mcp_mgreen27-mcp-velociraptor 0.1.0
File Size Uploaded
iflow_mcp_mgreen27_mcp_velociraptor-0.1.0.tar.gz 8.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iflow-mcp_mgreen27-mcp-velociraptor 0.1.0
File Interpreter ABI Platform
iflow_mcp_mgreen27_mcp_velociraptor-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 18.2 kB

Release files / iflow_mcp_mgreen27_mcp_velociraptor-0.1.0.tar.gz

Download URL iflow_mcp_mgreen27_mcp_velociraptor-0.1.0.tar.gz
Size 8.6 kB
Tags Source
SHA-256 checksum
How to use checksums
22b23c20cd23a1a3fbb5cb16469495d84df84b4b20f9f2ef664fa0b5dbdf542d
BLAKE2b-256 checksum
How to use checksums
fed5cf5ccf103a342370f304cf676f01d7209ec4f4de6b10842537694510d63a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.10.2 {"installer":{"name":"uv","version":"0.10.2","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / iflow_mcp_mgreen27_mcp_velociraptor-0.1.0-py3-none-any.whl

Download URL iflow_mcp_mgreen27_mcp_velociraptor-0.1.0-py3-none-any.whl
Size 9.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fd0458299ebdba5f671dc0b1bee8ac31586954db9fb8abcb629c89251a2f74e1
BLAKE2b-256 checksum
How to use checksums
895993c4aec3142e294d648542c55c503f570d7fa9d265aa4a9bca0b15cd3bd9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.10.2 {"installer":{"name":"uv","version":"0.10.2","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page