ssh-forensics-mcp is an Apache-2.0 MCP server for remote SSH forensic investigations. It provides SSH channel primitives, local active probing, and JSONL evidence-chain output for security engineers and incident responders.
In the Penetration testing & red teaming space, ssh-forensics-mcp takes a focused approach. It focuses on collecting and preserving evidence during remote SSH incident investigations. ssh-forensics-mcp is an open-source project aimed at security engineers and incident responders. ssh-forensics-mcp is open source under the Apache-2.0 license. It runs on the command line and API, and it can be self-hosted.
It is developed by xihan123, and it first shipped in 2026. The project is developed in the open on GitHub with 1 commit in the last 90 days. Key capabilities include SSH channels, remote forensics, and active probing. It exposes integrations via an MCP server.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do