
Ntobjmanager Mcp
io.github.lupingQAQv1.0.0更新于 Sep 30, 2026
Stateful Windows RPC attack-surface research for AI agents: 22 tools on NtObjectManager.
安装
在 SourceWeft 中
- 打开 控制台中的 Ntobjmanager Mcp,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
🛰️ NtObjectManager-MCP
Stateful Windows RPC Research MCP — 2024–2026 CVE methodologies as one-click tools
[Python] [License] [PowerShell] [MCP]
🌐 中文版
What is NtObjectManager-MCP?
A Model Context Protocol server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).
Two things a generic PowerShell MCP cannot do — and the reason this exists:
- Stateful RPC connections — a persistent PowerShell engine keeps parsed
RpcServerobjects and connected RPC clients alive across tool calls:rpc_connectonce,rpc_callmany times (auth handshakes, context-handle chains, session variables survive). - CVE methodology as fixed tools — the standard hunting workflows from 2024–2026 public research are one-click, not prompt-engineering:
Tool Matrix (22)
Core stateful pipeline
2024–2026 CVE methodology tools
Every tool call is appended to output/mcp_audit.log.
Field-Tested (real machine, full hunting round)
🚀 Quick Start
Claude Code:
Any MCP client (e.g. OpenCode opencode.json):
Example: context-handle type confusion (CVE-2025-48815 pattern)
store_as / {"__var__"} is the core chain primitive: RPC return objects flow
between calls without serialization round-trips, which is exactly what
producer→consumer handle-confusion testing needs.
📁 Project Structure
🛡️ Honest Capability Boundaries
📖 Documentation
- ARCHITECTURE.md — engine protocol, state model, design decisions
- CHANGELOG.md — R1–R12 decision history incl. two PS 5.1 marshaling bugs
- SECURITY.md — authorized use, VM isolation, MSRC disclosure
- CONTRIBUTING.md — development invariants and test requirements
⚠️ Disclaimer
For lawful security research, education, and authorized testing only.
rpc_call invokes real RPC methods and can crash services — run it against an
isolated VM, never a production or daily-driver host. Vulnerabilities found
through this tool must follow responsible disclosure (MSRC).
📄 License
MIT — Copyright (c) 2026 ntobjmanager-mcp Contributors
来源:README.md,提交 0539fd1
工具
0版本历史
1- v1.0.0最新Sep 30, 2026


