# Velociraptor MCP

> Use this tool when you need to query Windows endpoints for forensic artifacts using natural language. It solves problems related to incident response and threat hunting by providing easy access to endpoint data, such as network connections and suspicious processes. The Velociraptor MCP bridge takes natural language inputs and outputs relevant forensic artifacts, making it ideal for use cases where speed and simplicity are crucial.

Canonical page: https://skillsregistry.net/skills/mgreen27-mcp-velociraptor  
JSON: https://api.skillsregistry.net/v1/skills/mgreen27-mcp-velociraptor

## Description

A proof-of-concept MCP bridge that exposes Velociraptor's forensic triage tools to LLMs, enabling natural language querying of Windows endpoints for artifacts like network connections and suspicious processes.

## Trust

- **Trust score (0–1):** 0.68
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-01

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/ac0g2ybvo6)
- **Repository:** <https://github.com/mgreen27/mcp-velociraptor>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "mgreen27-mcp-velociraptor"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/mgreen27-mcp-velociraptor` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/mgreen27-mcp-velociraptor/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
