Agent Skills

Memory Forensics

Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage.

Install

Install and configure the MCP from https://github.com/x746b/mem_forensics-mcp now. Follow the repository's installation instructions, ask me for anything you can't complete yourself, and verify its tools load.
README

mem-forensics-mcp

Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage.


Architecture

Three-tier engine automatically routes each tool to the fastest backend:

LLM <-> [mem-forensics-mcp (Python)] <-> memoxide (Rust child, stdio MCP)
                                     <-> Volatility3 (Python library)
TierEngineSpeedCoverage
Tier 1Rust (memoxide)Fastpslist, psscan, cmdline, dlllist, malfind, netscan, cmdscan, search, readraw, rsds
Tier 2Python analyzersMediumProcess anomalies, C2 detection, credentials, YARA, VT integration
Tier 3Volatility3SlowerAny vol3 plugin (filescan, handles, svcscan, driverscan, ...)

Installation

Prerequisites

# Install uv (fast Python package manager)
curl -LsSf https://astral.sh/uv/install.sh | sh

# Ensure Python 3.10+
python3 --version

Install from PyPI

uv venv .venv
uv pip install --python .venv/bin/python3 mem-forensics-mcp

Install from source

git clone https://github.com/x746b/mem_forensics-mcp.git
cd mem_forensics-mcp

# Full install (recommended)
uv sync --extra full

# Minimal (Vol3 only, no YARA/VT)
uv sync --extra volatility3

Build Rust Engine (optional)

Prebuilt binaries ship for aarch64-linux and x86_64-linux in engines/memoxide/. The server auto-detects the host architecture. To build from source:

# Requires Rust toolchain (https://rustup.rs)
cd engines/memoxide-src
cargo build --release

# Binary lands at engines/memoxide-src/target/release/memoxide
# The server auto-detects it (prefers local build over prebuilt)

Configure Volatility3 (optional)

If Vol3 is installed at /opt/volatility3 it's auto-detected. Otherwise: export VOLATILITY3_PATH="/path/to/volatility3"

Verify

uv run python -m mem_forensics_mcp.server
# Should show: Rust engine: available, Volatility3: available

Add to an MCP client

Register mem-forensics-mcp as a local stdio server in your MCP client's settings. Configuration format and location depend on the client. For clients that accept mcpServers JSON, use:

{
  "mcpServers": {
    "mem-forensics-mcp": {
      "command": "/absolute/path/to/.venv/bin/python3",
      "args": ["-m", "mem_forensics_mcp.server"]
    }
  }
}

Replace the command with the absolute path to the virtual environment's Python interpreter. For a source checkout, this is /path/to/mem_forensics-mcp/.venv/bin/python3 after uv sync. For a PyPI install, use the .venv created during installation. If your client uses a different configuration format, enter the same command and arguments through its MCP server settings.

If Volatility3 is installed in a custom location, set VOLATILITY3_PATH to its absolute path in the server's environment settings (for example, "env": {"VOLATILITY3_PATH": "/path/to/volatility3"} in the JSON example). Use the client's MCP server list to confirm it connects.


Quick Start

# 1. Initialize
memory_analyze_image(image_path="/evidence/memory.raw")

# 2. Full triage
memory_full_triage(image_path="/evidence/memory.raw")

# 3. Drill down
memory_run_plugin(image_path="/evidence/memory.raw", plugin="malfind", pid=1234)

memory_analyze_image reports readiness at two levels:

  • ready and session_ready: an engine opened the image and the session can be reused.
  • raw_ready: OS-agnostic Rust operations such as search and readraw are available.
  • structured_ready: symbols/profile data is sufficient for structure-aware plugins.

ready remains a compatibility alias for session_ready; it does not imply that Volatility process, network, or command plugins can run. Check os_type, structured_ready, capabilities, and warnings before choosing those tools.

For Linux structure-aware analysis, provide either a symbol directory or an explicit ISF file. Linux ISFs are never downloaded or generated automatically:

memory_analyze_image(
    image_path="/evidence/memory.lime",
    symbols_root="/evidence/symbols",
    # or: isf_path="/evidence/symbols/5.10.0-35-amd64.json.xz",
)

Without a matching ISF, LiME images still expose raw search and readraw. The analysis response includes the exact kernel banner and a suggested ISF filename. With symbols loaded, process tree routes to linux.pslist.PsList, command history routes to linux.bash.Bash, and generic Linux Volatility plugins are available through memory_run_plugin.


Tool Reference

Core

ToolTierDescription
memory_analyze_image1->2Initialize image, auto-detect profile
memory_run_plugin1->3Run any plugin (Rust or Vol3)
memory_list_plugins-List available plugins
memory_list_sessions-List active sessions
memory_get_status-Show engine status

Analysis

ToolTierDescription
memory_full_triage1+2Complete automated investigation
memory_hunt_process_anomalies2DKOM detection, parent-child validation
memory_get_process_tree2Process tree with suspicious highlighting
memory_find_injected_code1->2Code injection + YARA scanning
memory_find_c2_connections1+2Network C2 detection
memory_get_command_history1+2Command recovery + classification
memory_extract_credentials2Hash/secret extraction via Vol3

Extraction

ToolTierDescription
memory_dump_process2Process info and loaded DLLs
memory_dump_vad2Examine memory region details
memory_list_dumpable_files3List cached files

Threat Intelligence

ToolDescription
vt_lookup_hashVirusTotal hash lookup
vt_lookup_ipVirusTotal IP reputation
vt_lookup_domainVirusTotal domain reputation
vt_lookup_fileHash file + VT lookup

Example: Full Triage Output

Running memory_full_triage on a Windows 10 memory dump (Win10 19041, x64, VMware):

{
  "threat_level": "critical",
  "risk_score": 100,
  "summary": "Processes: 115 found. Process Anomalies: 4 info-level. Network: 4 flagged of 79 connections. Commands: 56 memory fragments. Injected Code: 12 RWX regions. Correlations: 2 critical.",
  "engine": "rust+python"
}

Key findings:

CategoryDetail
Suspicious processmmc.exe launched from explorer.exe, loading a .msc file from browser downloads
Injected code4 RWX private memory regions in mmc.exe, 2 in EXCEL.EXE
Child processdllhost.exe spawned by mmc.exe with executable RWX region
Networksvchost.exe connections to external IPs on ports 443/80
Correlationsactive_implant + active_c2_session flagged as critical
IOCsSuspicious external IPs extracted automatically

Drill-down with filtered filescan:

memory_run_plugin(image_path="memory.raw", plugin="filescan", filter="notepad")
# Returns: 2 of 7612 results matched (server-side grep before truncation)

Related Projects

  • winforensics-mcp — Windows disk forensics (EVTX, Registry, MFT, Prefetch, YARA, PCAP)
  • mac_forensics-mcp — macOS DFIR (Unified Logs, FSEvents, Spotlight, Plists)

MIT License | xtk | Built for the DFIR community. No Windows required >)

Search skills and MCP servers

Search across 31,816 skills and MCPs