
Ntobjmanager Mcp
io.github.lupingQAQv1.0.0Updated Sep 30, 2026
Stateful Windows RPC attack-surface research for AI agents: 22 tools on NtObjectManager.
Installation
In SourceWeft
- Open Ntobjmanager Mcp in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
π°οΈ NtObjectManager-MCP
Stateful Windows RPC Research MCP β 2024β2026 CVE methodologies as one-click tools
[Python] [License] [PowerShell] [MCP]
π δΈζη
What is NtObjectManager-MCP?
A Model Context Protocol server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).
Two things a generic PowerShell MCP cannot do β and the reason this exists:
- Stateful RPC connections β a persistent PowerShell engine keeps parsed
RpcServerobjects and connected RPC clients alive across tool calls:rpc_connectonce,rpc_callmany times (auth handshakes, context-handle chains, session variables survive). - CVE methodology as fixed tools β the standard hunting workflows from 2024β2026 public research are one-click, not prompt-engineering:
Tool Matrix (22)
Core stateful pipeline
2024β2026 CVE methodology tools
Every tool call is appended to output/mcp_audit.log.
Field-Tested (real machine, full hunting round)
π Quick Start
Claude Code:
Any MCP client (e.g. OpenCode opencode.json):
Example: context-handle type confusion (CVE-2025-48815 pattern)
store_as / {"__var__"} is the core chain primitive: RPC return objects flow
between calls without serialization round-trips, which is exactly what
producerβconsumer handle-confusion testing needs.
π Project Structure
π‘οΈ Honest Capability Boundaries
π Documentation
- ARCHITECTURE.md β engine protocol, state model, design decisions
- CHANGELOG.md β R1βR12 decision history incl. two PS 5.1 marshaling bugs
- SECURITY.md β authorized use, VM isolation, MSRC disclosure
- CONTRIBUTING.md β development invariants and test requirements
β οΈ Disclaimer
For lawful security research, education, and authorized testing only.
rpc_call invokes real RPC methods and can crash services β run it against an
isolated VM, never a production or daily-driver host. Vulnerabilities found
through this tool must follow responsible disclosure (MSRC).
π License
MIT β Copyright (c) 2026 ntobjmanager-mcp Contributors
Source: README.md at commit 0539fd1
Tools
0Version history
1- v1.0.0LatestSep 30, 2026


