PluginBench
MCP Server
Active
MIT

io.github.lupingQAQ/ntobjmanager-mcp MCP Server

io.github.lupingQAQ/ntobjmanager-mcp

Stateful Windows RPC attack-surface research for AI agents—24 tools on NtObjectManager for CVE methodology and context-handle chaining.

What is the io.github.lupingQAQ/ntobjmanager-mcp MCP server?

The NtObjectManager-MCP server is a Model Context Protocol server that gives AI agents live, stateful access to Windows RPC attack-surface research built on James Forshaw's NtObjectManager. It provides 24 tools for parsing RPC servers, discovering endpoints, connecting clients, invoking methods, and executing 2024–2026 CVE methodologies like context-handle type confusion and EPM hijacking—all with persistent state across tool calls.

NtObjectManager-MCP enables security researchers and AI agents to conduct Windows RPC vulnerability research at scale. It maintains stateful RPC connections and session variables across multiple tool invocations, implements standard CVE hunting workflows as one-click tools, and bridges to lab VMs for safe, isolated testing. Use it to inventory RPC attack surfaces, probe for authorization bypasses, chain context handles across procedures, and validate exploit primitives without manual PowerShell engineering.

How to install io.github.lupingQAQ/ntobjmanager-mcp

Copy-paste configuration for popular MCP clients.

No machine-readable install method is published for this server in the registry. Check the repository or website for setup instructions.

Tools & capabilities

Tools this server exposes to the agent.

  • rpc_parse — Parse a PE file for RPC servers and cache the results for later reference.
  • rpc_state — Return cached servers and live RPC sessions.
  • rpc_get_interface — Retrieve procedures, NDR parameters, context handles, and strictness flags for an interface.
  • rpc_query_endpoints — Query the Endpoint Mapper for RPC endpoints, optionally filtering by interface ID or binding, and discover ALPC ports.
  • rpc_running_servers — Enumerate live RPC servers by process ID or service name.
  • rpc_connect — Generate and establish a stateful RPC client connection, auto-discovering bindings via EPM.
  • rpc_methods — List RPC method signatures with opnum mapping for a connected session.
  • rpc_call — Invoke an RPC method via reflection with JSON arguments; supports passing stored objects via __var__ references.
  • rpc_disconnect — Close and drop an RPC session.
  • rpc_vm_exec — Execute PowerShell inside a lab VM with persistent state across calls.
  • rpc_vm_start_listener — Deploy and start the persistent guest HTTP engine for stateful VM execution.
  • rpc_scan_context_handles — Scan for context-handle type confusion vulnerabilities following CVE-2025-48815 patterns.
  • rpc_inventory — Perform attack-surface inventory and cross-check with EPM, following MS-RPC-Fuzzer phase 1 methodology.
  • rpc_fuzz — Run primitive-only default-value fuzzing with ok/denied/error classification; dry-run by default.
  • rpc_find_hijackable — Identify unregistered interfaces of stopped services vulnerable to EPM poisoning or RPC-Racer attacks.
  • rpc_etw_unreachable — Detect clients calling dead servers via ETW tracing (PhantomRPC pattern); requires admin.
  • rpc_interface_security — Audit ALPC security descriptors and anonymous ACEs for authorization bypasses.
  • rpc_decode_flags — Decode RpcServerRegisterIf3 flag bitmasks.
  • rpc_format_client — Export generated C# RPC client source code for offline analysis.
  • rpc_new_struct — Build NDR complex types and store them as session variables.

Use cases

  • Discover and enumerate RPC servers across Windows system binaries, then probe for authorization bypasses and context-handle type confusion vulnerabilities.
  • Chain RPC method calls across producer and consumer procedures by storing return objects and passing them as arguments to detect handle-confusion exploits.
  • Inventory the RPC attack surface of a target system, cross-reference with the Endpoint Mapper, and identify unregistered interfaces of stopped services for EPM poisoning attacks.
  • Fuzz RPC procedures with default-value payloads and classify responses as ok/denied/error to identify unexpected behavior and potential crashes.
  • Execute PowerShell-based RPC research workflows inside an isolated lab VM while maintaining state across multiple tool calls, enabling safe testing without affecting the host.

io.github.lupingQAQ/ntobjmanager-mcp MCP server FAQ

What is NtObjectManager-MCP?

It is a Model Context Protocol server that provides AI agents with 24 tools for stateful Windows RPC attack-surface research. It maintains persistent RPC connections and session state across tool calls, implements CVE hunting methodologies as fixed tools, and bridges to lab VMs for isolated testing.

Is it free?

Yes, NtObjectManager-MCP is released under the MIT license.

How do I install it in Claude or Cursor?

Run `claude mcp add ntobjectmanager-rpc -- python C:\path\to\ntobjmanager-mcp\server.py` for Claude, or add it to your MCP client config (e.g., opencode.json) with type 'local' and the server.py command.

What are the prerequisites?

Windows PowerShell 5.1, Python 3.10+, the NtObjectManager PowerShell module (Install-Module NtObjectManager), and dependencies from requirements.txt (mcp>=1.2.0).

Does it require authentication or API keys?

No API keys are required. However, some tools like rpc_etw_unreachable and rpc_interface_security require administrator privileges on the Windows host.

Can it run on non-Windows systems?

No, NtObjectManager-MCP requires Windows PowerShell 5.1 and Windows RPC runtime. PowerShell 7 (pwsh) is not yet tested.

README (reference)

Source of truth, from the repository.

🛰️ NtObjectManager-MCP

Stateful Windows RPC Research MCP — 2024–2026 CVE methodologies as one-click tools

Python License PowerShell MCP

🌐 中文版


What is NtObjectManager-MCP?

A Model Context Protocol server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).

Three things a generic PowerShell MCP cannot do — and the reason this exists:

  1. Stateful RPC connections — a persistent PowerShell engine keeps parsed RpcServer objects and connected RPC clients alive across tool calls: rpc_connect once, rpc_call many times (auth handshakes, context-handle chains, session variables survive).
  2. CVE methodology as fixed tools — the standard hunting workflows from 2024–2026 public research are one-click, not prompt-engineering.
  3. Stateful execution inside a lab VM — the same one-engine principle applied in the guest: rpc_vm_exec keeps variables and connected RPC clients alive across calls through a single persistent guest runspace, never a fresh shell per call (the vmrun fallback is reported as stateful: false).
┌────────────────────────────────────────────────────────────────────┐
│  AI Agent (Claude Code / OpenCode / any MCP client)                │
│      │  MCP (stdio, 24 tools)                                      │
│      ▼                                                             │
│  server.py ── snippets.py (PS templates, @@TOKEN@@ + ps_str escape)│
│      │                                                             │
│      ▼                                                             │
│  ps_engine.py ── persistent powershell.exe (base64 + __MCP_DONE__) │
│      │            state: $RPCMCP = @{ Servers; Clients; vars }     │
│      ▼                                                             │
│  NtObjectManager / NtCoreLib  ──►  RPC runtime (ALPC / pipe / TCP) │
└────────────────────────────────────────────────────────────────────┘

Tool Matrix (24)

Core stateful pipeline

ToolPurpose
rpc_parse(file, symbol_path?)Parse a PE for RPC servers, cache (keys file_N)
rpc_state()Cached servers + live sessions
rpc_get_interface(key)Procedures, NDR params, context handles, strictness
rpc_query_endpoints(ifid?, search_binding?, find_alpc_port?)EPM query (local or remote)
rpc_running_servers(pid?/service?)Live process/service enumeration
rpc_connect(session, key, binding?, auth?)Generate + connect client (stateful)
rpc_methods(session)Signatures with opnum mapping
rpc_call(session, method, args_json, store_as?)Reflection invoke; {"__var__"} passes stored objects
rpc_disconnect(session)Drop session

VM lab bridge (stateful guest execution)

ToolPurpose
rpc_vm_exec(ps, timeout?, vm?)Run PowerShell inside a lab VM; state survives across calls (persistent guest runspace)
rpc_vm_start_listener(vm?)Deploy/start the persistent guest HTTP engine (vm_listener.ps1)

2024–2026 CVE methodology tools

ToolMethodology source
rpc_scan_context_handles(paths)Context-handle type confusion — CVE-2025-48815 pattern (whereisk0shl 2026)
rpc_inventory(paths?, limit?)Attack-surface inventory + EPM cross-check — MS-RPC-Fuzzer phase 1 (CVE-2025-26651)
rpc_fuzz(session, dry_run=True)Primitive-only default-value fuzzing with ok/denied/error classification — dry-run by default
rpc_find_hijackable()Unregistered interfaces of stopped services — EPM poisoning / RPC-Racer (CVE-2025-49760/59200/59230)
rpc_etw_unreachable(duration, trigger_script?)Clients calling dead servers — PhantomRPC (Kaspersky 2026), admin required
rpc_interface_security(key)ALPC SD / anonymous-ACE audit — MS-NRPC null session (SafeBreach/Securelist 2025)
rpc_decode_flags(flags)RpcServerRegisterIf3 flag bitmask decoding
rpc_format_client(key)Export generated C# client source (offline grep workflow)
rpc_new_struct(session, type, store_as)Build NDR complex types as session vars
rpc_alpc_squat(name, duration)ALPC port squat + connection capture (race validation primitive)
rpc_accessible_tasks()User-startable tasks (Dark-Elevator chain material, CVE-2026-66804 pattern)
rpc_vars / rpc_clear_cacheSession-variable and cache management (eviction cap 150)

Every tool call is appended to output/mcp_audit.log.

Field-Tested (real machine, full hunting round)

CandidateResult
srvsvc.dll 98716d03… flagged HIGHIdentified as XactSrv (XsOpenPrinter/XsClosePrinter/XsAddJob/XsScheduleJob) — single printer-handle type; live probe: non-admin connect OK but XsOpenPrinter → ACCESS_DENIED (authorization gate works). Scanner false-positive mode documented
ssdpsrv.dll (CVE-2025-48815 original)All 20 context handles strict — patched state on current builds
51-module sweep31 findings, 6 HIGH, all "one producer → many consumers"; NDR layer cannot prove multi-type handles (needs RE)
EPM hijack surface10 stopped services with unregistered interfaces (AppIDSvc, ClipSVC, dcsvc…)
Task chains44 user-startable SYSTEM tasks inventoried
VerdictNo confirmable exploitable vuln on the tested host — with per-step evidence

🚀 Quick Start

# 1) Prerequisites (one-time)
Install-Module NtObjectManager -Scope CurrentUser -Force
pip install -r requirements.txt            # mcp>=1.2.0 (1.x / 2.x compatible)

# 2) Verify — three suites, all green
python tests\smoke_test.py                 # 17 checks (live MCP stdio round-trip)
python tests\var_test.py                   # 10 checks (store_as / __var__ mechanics)
python tests\audit.py                      # 43 checks (edge cases, hostile paths, concurrency)

# 3) Run the server
python server.py                           # stdio MCP

Claude Code:

claude mcp add ntobjectmanager-rpc -- python C:\path\to\ntobjmanager-mcp\server.py

Any MCP client (e.g. OpenCode opencode.json):

{
  "mcp": {
    "ntobjectmanager-rpc": {
      "type": "local",
      "command": ["python", "C:\\path\\to\\ntobjmanager-mcp\\server.py"],
      "enabled": true
    }
  }
}

Example: context-handle type confusion (CVE-2025-48815 pattern)

1. rpc_parse  C:\Windows\System32\target.dll  [symbol_path optional]
2. rpc_scan_context_handles ["C:\\Windows\\System32\\target.dll"]
3. rpc_get_interface target_0                 → producer ([out] ctx) / consumer ([in] ctx) pairs
4. rpc_connect s1 target_0                    → auto-discovers binding via EPM
5. rpc_methods s1                            → opnum-mapped signatures
6. rpc_call s1 XsOpenPrinter-like args store_as="h"   → keep the raw handle object
7. rpc_call s1 XsClosePrinter-like [{"__var__":"h"}] → feed it to the other type

store_as / {"__var__"} is the core chain primitive: RPC return objects flow between calls without serialization round-trips, which is exactly what producer→consumer handle-confusion testing needs.

📁 Project Structure

ntobjmanager-mcp/
├── server.py            # 24 MCP tools + audit logging wrapper
├── snippets.py          # PowerShell templates (@@TOKEN@@ render + ps_str escaping)
├── ps_engine.py         # Persistent engine: base64 cmds + __MCP_DONE__ markers, timeouts
├── wrapper.ps1          # PS-side loop (state lives in $RPCMCP)
├── vm_listener.ps1      # Persistent guest HTTP bridge (stateful VM exec)
├── tests/
│   ├── smoke_test.py    # 17 checks — live stdio end-to-end
│   ├── var_test.py      # 10 checks — store_as/__var__ object passing
│   ├── audit.py         # 43 checks — hostile inputs, concurrency, engine kill/restart
│   ├── hunt.py          # Full dogfood hunting round (safe policy)
│   ├── hunt2_static.py  # Deep-dive: symbols + producer/consumer map
│   ├── hunt2_wide.py    # 51-module sweep
│   └── hunt2_probe.py   # Safe runtime probes (exposure / task cross-ref)
├── ARCHITECTURE.md      # Engine protocol + design decisions
├── CHANGELOG.md         # Decision history (R1–R13)
├── SECURITY.md          # Authorized-use policy + MSRC disclosure
├── CONTRIBUTING.md      # Development invariants
└── LICENSE              # MIT

🛡️ Honest Capability Boundaries

ClaimStatus
Stateful clients across tool callsYes — persistent engine + $RPCMCP
Stateful execution inside a lab VMYes — one persistent guest runspace (rpc_vm_exec); the vmrun fallback is stateless
Context-handle chaining (producer → consumer)Yes — store_as / __var__ raw-object passing
Auto-confirm type confusionNo — NDR cannot prove distinct handle types; verify via RE (see XactSrv case)
Full rogue-RPC hostingNo — NtObjectManager 2.0.1 ships no server builder; rpc_alpc_squat covers race-capture only
ETW tracing / ALPC SDDLRequires admin (logman / SeDebugPrivilege)
Symbol-resolved procedure namesEnvironment-dependent (symsrv chain); heuristic fallback names otherwise
Runs anywhere but Windows PS 5.1Not yet (pwsh 7 untested)

📖 Documentation

  • ARCHITECTURE.md — engine protocol, state model, design decisions
  • CHANGELOG.md — R1–R13 decision history incl. two PS 5.1 marshaling bugs
  • SECURITY.md — authorized use, VM isolation, MSRC disclosure
  • CONTRIBUTING.md — development invariants and test requirements

⚠️ Disclaimer

For lawful security research, education, and authorized testing only. rpc_call invokes real RPC methods and can crash services — run it against an isolated VM, never a production or daily-driver host. Vulnerabilities found through this tool must follow responsible disclosure (MSRC).

📄 License

MIT — Copyright (c) 2026 ntobjmanager-mcp Contributors

Related MCP servers

Code intelligence MCP: symbols, call graphs, change impact + affected tests, routes, search.

0
TypeScript
MIT
View repository →
KEKeel logo

Keel

Maintained

Control plane MCP that dedups scanner output, rate-limits hosts, and runs non-destructive proofs.

1
Python
MIT
View repository →
SESense logo

Sense

Active

Symbol graph, blast radius, and semantic search for AI coding agents—structural codebase understanding on your machine.

31
Go
MIT
View repository →

MCP server for Skim code transformation. Compresses code 60-95% for LLM context optimization.

Real-time crypto prices from Binance, Coinbase, Kraken, OKX, and Bybit

0
TypeScript
MIT
View repository →

Empirical maritime distances from real AIS tracks: 4 route variants, port lookup, bulk matrix

View repository →