io.github.lupingQAQ/ntobjmanager-mcp MCP Server
io.github.lupingQAQ/ntobjmanager-mcp
Stateful Windows RPC attack-surface research for AI agents—24 tools on NtObjectManager for CVE methodology and context-handle chaining.
What is the io.github.lupingQAQ/ntobjmanager-mcp MCP server?
The NtObjectManager-MCP server is a Model Context Protocol server that gives AI agents live, stateful access to Windows RPC attack-surface research built on James Forshaw's NtObjectManager. It provides 24 tools for parsing RPC servers, discovering endpoints, connecting clients, invoking methods, and executing 2024–2026 CVE methodologies like context-handle type confusion and EPM hijacking—all with persistent state across tool calls.
NtObjectManager-MCP enables security researchers and AI agents to conduct Windows RPC vulnerability research at scale. It maintains stateful RPC connections and session variables across multiple tool invocations, implements standard CVE hunting workflows as one-click tools, and bridges to lab VMs for safe, isolated testing. Use it to inventory RPC attack surfaces, probe for authorization bypasses, chain context handles across procedures, and validate exploit primitives without manual PowerShell engineering.
How to install io.github.lupingQAQ/ntobjmanager-mcp
Copy-paste configuration for popular MCP clients.
No machine-readable install method is published for this server in the registry. Check the repository or website for setup instructions.
Tools & capabilities
Tools this server exposes to the agent.
rpc_parse— Parse a PE file for RPC servers and cache the results for later reference.rpc_state— Return cached servers and live RPC sessions.rpc_get_interface— Retrieve procedures, NDR parameters, context handles, and strictness flags for an interface.rpc_query_endpoints— Query the Endpoint Mapper for RPC endpoints, optionally filtering by interface ID or binding, and discover ALPC ports.rpc_running_servers— Enumerate live RPC servers by process ID or service name.rpc_connect— Generate and establish a stateful RPC client connection, auto-discovering bindings via EPM.rpc_methods— List RPC method signatures with opnum mapping for a connected session.rpc_call— Invoke an RPC method via reflection with JSON arguments; supports passing stored objects via __var__ references.rpc_disconnect— Close and drop an RPC session.rpc_vm_exec— Execute PowerShell inside a lab VM with persistent state across calls.rpc_vm_start_listener— Deploy and start the persistent guest HTTP engine for stateful VM execution.rpc_scan_context_handles— Scan for context-handle type confusion vulnerabilities following CVE-2025-48815 patterns.rpc_inventory— Perform attack-surface inventory and cross-check with EPM, following MS-RPC-Fuzzer phase 1 methodology.rpc_fuzz— Run primitive-only default-value fuzzing with ok/denied/error classification; dry-run by default.rpc_find_hijackable— Identify unregistered interfaces of stopped services vulnerable to EPM poisoning or RPC-Racer attacks.rpc_etw_unreachable— Detect clients calling dead servers via ETW tracing (PhantomRPC pattern); requires admin.rpc_interface_security— Audit ALPC security descriptors and anonymous ACEs for authorization bypasses.rpc_decode_flags— Decode RpcServerRegisterIf3 flag bitmasks.rpc_format_client— Export generated C# RPC client source code for offline analysis.rpc_new_struct— Build NDR complex types and store them as session variables.
Use cases
- Discover and enumerate RPC servers across Windows system binaries, then probe for authorization bypasses and context-handle type confusion vulnerabilities.
- Chain RPC method calls across producer and consumer procedures by storing return objects and passing them as arguments to detect handle-confusion exploits.
- Inventory the RPC attack surface of a target system, cross-reference with the Endpoint Mapper, and identify unregistered interfaces of stopped services for EPM poisoning attacks.
- Fuzz RPC procedures with default-value payloads and classify responses as ok/denied/error to identify unexpected behavior and potential crashes.
- Execute PowerShell-based RPC research workflows inside an isolated lab VM while maintaining state across multiple tool calls, enabling safe testing without affecting the host.
io.github.lupingQAQ/ntobjmanager-mcp MCP server FAQ
It is a Model Context Protocol server that provides AI agents with 24 tools for stateful Windows RPC attack-surface research. It maintains persistent RPC connections and session state across tool calls, implements CVE hunting methodologies as fixed tools, and bridges to lab VMs for isolated testing.
Yes, NtObjectManager-MCP is released under the MIT license.
Run `claude mcp add ntobjectmanager-rpc -- python C:\path\to\ntobjmanager-mcp\server.py` for Claude, or add it to your MCP client config (e.g., opencode.json) with type 'local' and the server.py command.
Windows PowerShell 5.1, Python 3.10+, the NtObjectManager PowerShell module (Install-Module NtObjectManager), and dependencies from requirements.txt (mcp>=1.2.0).
No API keys are required. However, some tools like rpc_etw_unreachable and rpc_interface_security require administrator privileges on the Windows host.
No, NtObjectManager-MCP requires Windows PowerShell 5.1 and Windows RPC runtime. PowerShell 7 (pwsh) is not yet tested.
README (reference)
Source of truth, from the repository.
🛰️ NtObjectManager-MCP
Stateful Windows RPC Research MCP — 2024–2026 CVE methodologies as one-click tools
🌐 中文版
What is NtObjectManager-MCP?
A Model Context Protocol server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).
Three things a generic PowerShell MCP cannot do — and the reason this exists:
- Stateful RPC connections — a persistent PowerShell engine keeps parsed
RpcServerobjects and connected RPC clients alive across tool calls:rpc_connectonce,rpc_callmany times (auth handshakes, context-handle chains, session variables survive). - CVE methodology as fixed tools — the standard hunting workflows from 2024–2026 public research are one-click, not prompt-engineering.
- Stateful execution inside a lab VM — the same one-engine principle applied
in the guest:
rpc_vm_execkeeps variables and connected RPC clients alive across calls through a single persistent guest runspace, never a fresh shell per call (the vmrun fallback is reported asstateful: false).
┌────────────────────────────────────────────────────────────────────┐
│ AI Agent (Claude Code / OpenCode / any MCP client) │
│ │ MCP (stdio, 24 tools) │
│ ▼ │
│ server.py ── snippets.py (PS templates, @@TOKEN@@ + ps_str escape)│
│ │ │
│ ▼ │
│ ps_engine.py ── persistent powershell.exe (base64 + __MCP_DONE__) │
│ │ state: $RPCMCP = @{ Servers; Clients; vars } │
│ ▼ │
│ NtObjectManager / NtCoreLib ──► RPC runtime (ALPC / pipe / TCP) │
└────────────────────────────────────────────────────────────────────┘
Tool Matrix (24)
Core stateful pipeline
| Tool | Purpose |
|---|---|
rpc_parse(file, symbol_path?) | Parse a PE for RPC servers, cache (keys file_N) |
rpc_state() | Cached servers + live sessions |
rpc_get_interface(key) | Procedures, NDR params, context handles, strictness |
rpc_query_endpoints(ifid?, search_binding?, find_alpc_port?) | EPM query (local or remote) |
rpc_running_servers(pid?/service?) | Live process/service enumeration |
rpc_connect(session, key, binding?, auth?) | Generate + connect client (stateful) |
rpc_methods(session) | Signatures with opnum mapping |
rpc_call(session, method, args_json, store_as?) | Reflection invoke; {"__var__"} passes stored objects |
rpc_disconnect(session) | Drop session |
VM lab bridge (stateful guest execution)
| Tool | Purpose |
|---|---|
rpc_vm_exec(ps, timeout?, vm?) | Run PowerShell inside a lab VM; state survives across calls (persistent guest runspace) |
rpc_vm_start_listener(vm?) | Deploy/start the persistent guest HTTP engine (vm_listener.ps1) |
2024–2026 CVE methodology tools
| Tool | Methodology source |
|---|---|
rpc_scan_context_handles(paths) | Context-handle type confusion — CVE-2025-48815 pattern (whereisk0shl 2026) |
rpc_inventory(paths?, limit?) | Attack-surface inventory + EPM cross-check — MS-RPC-Fuzzer phase 1 (CVE-2025-26651) |
rpc_fuzz(session, dry_run=True) | Primitive-only default-value fuzzing with ok/denied/error classification — dry-run by default |
rpc_find_hijackable() | Unregistered interfaces of stopped services — EPM poisoning / RPC-Racer (CVE-2025-49760/59200/59230) |
rpc_etw_unreachable(duration, trigger_script?) | Clients calling dead servers — PhantomRPC (Kaspersky 2026), admin required |
rpc_interface_security(key) | ALPC SD / anonymous-ACE audit — MS-NRPC null session (SafeBreach/Securelist 2025) |
rpc_decode_flags(flags) | RpcServerRegisterIf3 flag bitmask decoding |
rpc_format_client(key) | Export generated C# client source (offline grep workflow) |
rpc_new_struct(session, type, store_as) | Build NDR complex types as session vars |
rpc_alpc_squat(name, duration) | ALPC port squat + connection capture (race validation primitive) |
rpc_accessible_tasks() | User-startable tasks (Dark-Elevator chain material, CVE-2026-66804 pattern) |
rpc_vars / rpc_clear_cache | Session-variable and cache management (eviction cap 150) |
Every tool call is appended to output/mcp_audit.log.
Field-Tested (real machine, full hunting round)
| Candidate | Result |
|---|---|
srvsvc.dll 98716d03… flagged HIGH | Identified as XactSrv (XsOpenPrinter/XsClosePrinter/XsAddJob/XsScheduleJob) — single printer-handle type; live probe: non-admin connect OK but XsOpenPrinter → ACCESS_DENIED (authorization gate works). Scanner false-positive mode documented |
ssdpsrv.dll (CVE-2025-48815 original) | All 20 context handles strict — patched state on current builds |
| 51-module sweep | 31 findings, 6 HIGH, all "one producer → many consumers"; NDR layer cannot prove multi-type handles (needs RE) |
| EPM hijack surface | 10 stopped services with unregistered interfaces (AppIDSvc, ClipSVC, dcsvc…) |
| Task chains | 44 user-startable SYSTEM tasks inventoried |
| Verdict | No confirmable exploitable vuln on the tested host — with per-step evidence |
🚀 Quick Start
# 1) Prerequisites (one-time)
Install-Module NtObjectManager -Scope CurrentUser -Force
pip install -r requirements.txt # mcp>=1.2.0 (1.x / 2.x compatible)
# 2) Verify — three suites, all green
python tests\smoke_test.py # 17 checks (live MCP stdio round-trip)
python tests\var_test.py # 10 checks (store_as / __var__ mechanics)
python tests\audit.py # 43 checks (edge cases, hostile paths, concurrency)
# 3) Run the server
python server.py # stdio MCP
Claude Code:
claude mcp add ntobjectmanager-rpc -- python C:\path\to\ntobjmanager-mcp\server.py
Any MCP client (e.g. OpenCode opencode.json):
{
"mcp": {
"ntobjectmanager-rpc": {
"type": "local",
"command": ["python", "C:\\path\\to\\ntobjmanager-mcp\\server.py"],
"enabled": true
}
}
}
Example: context-handle type confusion (CVE-2025-48815 pattern)
1. rpc_parse C:\Windows\System32\target.dll [symbol_path optional]
2. rpc_scan_context_handles ["C:\\Windows\\System32\\target.dll"]
3. rpc_get_interface target_0 → producer ([out] ctx) / consumer ([in] ctx) pairs
4. rpc_connect s1 target_0 → auto-discovers binding via EPM
5. rpc_methods s1 → opnum-mapped signatures
6. rpc_call s1 XsOpenPrinter-like args store_as="h" → keep the raw handle object
7. rpc_call s1 XsClosePrinter-like [{"__var__":"h"}] → feed it to the other type
store_as / {"__var__"} is the core chain primitive: RPC return objects flow
between calls without serialization round-trips, which is exactly what
producer→consumer handle-confusion testing needs.
📁 Project Structure
ntobjmanager-mcp/
├── server.py # 24 MCP tools + audit logging wrapper
├── snippets.py # PowerShell templates (@@TOKEN@@ render + ps_str escaping)
├── ps_engine.py # Persistent engine: base64 cmds + __MCP_DONE__ markers, timeouts
├── wrapper.ps1 # PS-side loop (state lives in $RPCMCP)
├── vm_listener.ps1 # Persistent guest HTTP bridge (stateful VM exec)
├── tests/
│ ├── smoke_test.py # 17 checks — live stdio end-to-end
│ ├── var_test.py # 10 checks — store_as/__var__ object passing
│ ├── audit.py # 43 checks — hostile inputs, concurrency, engine kill/restart
│ ├── hunt.py # Full dogfood hunting round (safe policy)
│ ├── hunt2_static.py # Deep-dive: symbols + producer/consumer map
│ ├── hunt2_wide.py # 51-module sweep
│ └── hunt2_probe.py # Safe runtime probes (exposure / task cross-ref)
├── ARCHITECTURE.md # Engine protocol + design decisions
├── CHANGELOG.md # Decision history (R1–R13)
├── SECURITY.md # Authorized-use policy + MSRC disclosure
├── CONTRIBUTING.md # Development invariants
└── LICENSE # MIT
🛡️ Honest Capability Boundaries
| Claim | Status |
|---|---|
| Stateful clients across tool calls | Yes — persistent engine + $RPCMCP |
| Stateful execution inside a lab VM | Yes — one persistent guest runspace (rpc_vm_exec); the vmrun fallback is stateless |
| Context-handle chaining (producer → consumer) | Yes — store_as / __var__ raw-object passing |
| Auto-confirm type confusion | No — NDR cannot prove distinct handle types; verify via RE (see XactSrv case) |
| Full rogue-RPC hosting | No — NtObjectManager 2.0.1 ships no server builder; rpc_alpc_squat covers race-capture only |
| ETW tracing / ALPC SDDL | Requires admin (logman / SeDebugPrivilege) |
| Symbol-resolved procedure names | Environment-dependent (symsrv chain); heuristic fallback names otherwise |
| Runs anywhere but Windows PS 5.1 | Not yet (pwsh 7 untested) |
📖 Documentation
- ARCHITECTURE.md — engine protocol, state model, design decisions
- CHANGELOG.md — R1–R13 decision history incl. two PS 5.1 marshaling bugs
- SECURITY.md — authorized use, VM isolation, MSRC disclosure
- CONTRIBUTING.md — development invariants and test requirements
⚠️ Disclaimer
For lawful security research, education, and authorized testing only.
rpc_call invokes real RPC methods and can crash services — run it against an
isolated VM, never a production or daily-driver host. Vulnerabilities found
through this tool must follow responsible disclosure (MSRC).
📄 License
MIT — Copyright (c) 2026 ntobjmanager-mcp Contributors
Related MCP servers

Code intelligence MCP: symbols, call graphs, change impact + affected tests, routes, search.

Keel
Control plane MCP that dedups scanner output, rate-limits hosts, and runs non-destructive proofs.

Sense
Symbol graph, blast radius, and semantic search for AI coding agents—structural codebase understanding on your machine.
MCP server for Skim code transformation. Compresses code 60-95% for LLM context optimization.

io.github.luziadev/luzia
Real-time crypto prices from Binance, Coinbase, Kraken, OKX, and Bybit
Empirical maritime distances from real AIS tracks: 4 route variants, port lookup, bulk matrix
View repository →