Server data from the Official MCP Registry
Stateful Windows RPC attack-surface research for AI agents: 22 tools on NtObjectManager.
About
Stateful Windows RPC attack-surface research for AI agents: 22 tools on NtObjectManager.
Security Report
This MCP server provides powerful Windows RPC research capabilities with stateful remote procedure call handling, but contains several security concerns that require careful management. Key issues include: (1) arbitrary PowerShell code execution via rpc_call with __ps__ expressions, (2) unsafe subprocess invocation with user-supplied VM paths and credentials, (3) credentials potentially stored in environment variables or local_config without encryption, and (4) extensive file system and network access that, while appropriate for the security research domain, could be abused if the server is compromised. The code quality is generally good, but input validation is inconsistent and there are dangerous patterns that could enable privilege escalation or data exfiltration in hostile scenarios. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity).
3 files analyzed Β· 18 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-lupingqaq-ntobjmanager-mcp": {
"args": [
"-y",
"github:lupingQAQ/ntobjmanager-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
π°οΈ NtObjectManager-MCP
Stateful Windows RPC Research MCP β 2024β2026 CVE methodologies as one-click tools
π δΈζη
What is NtObjectManager-MCP?
A Model Context Protocol server that gives an AI agent live, stateful access to Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).
Three things a generic PowerShell MCP cannot do β and the reason this exists:
- Stateful RPC connections β a persistent PowerShell engine keeps parsed
RpcServerobjects and connected RPC clients alive across tool calls:rpc_connectonce,rpc_callmany times (auth handshakes, context-handle chains, session variables survive). - CVE methodology as fixed tools β the standard hunting workflows from 2024β2026 public research are one-click, not prompt-engineering.
- Stateful execution inside a lab VM β the same one-engine principle applied
in the guest:
rpc_vm_execkeeps variables and connected RPC clients alive across calls through a single persistent guest runspace, never a fresh shell per call (the vmrun fallback is reported asstateful: false).
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β AI Agent (Claude Code / OpenCode / any MCP client) β
β β MCP (stdio, 24 tools) β
β βΌ β
β server.py ββ snippets.py (PS templates, @@TOKEN@@ + ps_str escape)β
β β β
β βΌ β
β ps_engine.py ββ persistent powershell.exe (base64 + __MCP_DONE__) β
β β state: $RPCMCP = @{ Servers; Clients; vars } β
β βΌ β
β NtObjectManager / NtCoreLib βββΊ RPC runtime (ALPC / pipe / TCP) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Tool Matrix (24)
Core stateful pipeline
| Tool | Purpose |
|---|---|
rpc_parse(file, symbol_path?) | Parse a PE for RPC servers, cache (keys file_N) |
rpc_state() | Cached servers + live sessions |
rpc_get_interface(key) | Procedures, NDR params, context handles, strictness |
rpc_query_endpoints(ifid?, search_binding?, find_alpc_port?) | EPM query (local or remote) |
rpc_running_servers(pid?/service?) | Live process/service enumeration |
rpc_connect(session, key, binding?, auth?) | Generate + connect client (stateful) |
rpc_methods(session) | Signatures with opnum mapping |
rpc_call(session, method, args_json, store_as?) | Reflection invoke; {"__var__"} passes stored objects |
rpc_disconnect(session) | Drop session |
VM lab bridge (stateful guest execution)
| Tool | Purpose |
|---|---|
rpc_vm_exec(ps, timeout?, vm?) | Run PowerShell inside a lab VM; state survives across calls (persistent guest runspace) |
rpc_vm_start_listener(vm?) | Deploy/start the persistent guest HTTP engine (vm_listener.ps1) |
2024β2026 CVE methodology tools
| Tool | Methodology source |
|---|---|
rpc_scan_context_handles(paths) | Context-handle type confusion β CVE-2025-48815 pattern (whereisk0shl 2026) |
rpc_inventory(paths?, limit?) | Attack-surface inventory + EPM cross-check β MS-RPC-Fuzzer phase 1 (CVE-2025-26651) |
rpc_fuzz(session, dry_run=True) | Primitive-only default-value fuzzing with ok/denied/error classification β dry-run by default |
rpc_find_hijackable() | Unregistered interfaces of stopped services β EPM poisoning / RPC-Racer (CVE-2025-49760/59200/59230) |
rpc_etw_unreachable(duration, trigger_script?) | Clients calling dead servers β PhantomRPC (Kaspersky 2026), admin required |
rpc_interface_security(key) | ALPC SD / anonymous-ACE audit β MS-NRPC null session (SafeBreach/Securelist 2025) |
rpc_decode_flags(flags) | RpcServerRegisterIf3 flag bitmask decoding |
rpc_format_client(key) | Export generated C# client source (offline grep workflow) |
rpc_new_struct(session, type, store_as) | Build NDR complex types as session vars |
rpc_alpc_squat(name, duration) | ALPC port squat + connection capture (race validation primitive) |
rpc_accessible_tasks() | User-startable tasks (Dark-Elevator chain material, CVE-2026-66804 pattern) |
rpc_vars / rpc_clear_cache | Session-variable and cache management (eviction cap 150) |
Every tool call is appended to output/mcp_audit.log.
Field-Tested (real machine, full hunting round)
| Candidate | Result |
|---|---|
srvsvc.dll 98716d03β¦ flagged HIGH | Identified as XactSrv (XsOpenPrinter/XsClosePrinter/XsAddJob/XsScheduleJob) β single printer-handle type; live probe: non-admin connect OK but XsOpenPrinter β ACCESS_DENIED (authorization gate works). Scanner false-positive mode documented |
ssdpsrv.dll (CVE-2025-48815 original) | All 20 context handles strict β patched state on current builds |
| 51-module sweep | 31 findings, 6 HIGH, all "one producer β many consumers"; NDR layer cannot prove multi-type handles (needs RE) |
| EPM hijack surface | 10 stopped services with unregistered interfaces (AppIDSvc, ClipSVC, dcsvcβ¦) |
| Task chains | 44 user-startable SYSTEM tasks inventoried |
| Verdict | No confirmable exploitable vuln on the tested host β with per-step evidence |
π Quick Start
# 1) Prerequisites (one-time)
Install-Module NtObjectManager -Scope CurrentUser -Force
pip install -r requirements.txt # mcp>=1.2.0 (1.x / 2.x compatible)
# 2) Verify β three suites, all green
python tests\smoke_test.py # 17 checks (live MCP stdio round-trip)
python tests\var_test.py # 10 checks (store_as / __var__ mechanics)
python tests\audit.py # 43 checks (edge cases, hostile paths, concurrency)
# 3) Run the server
python server.py # stdio MCP
Claude Code:
claude mcp add ntobjectmanager-rpc -- python C:\path\to\ntobjmanager-mcp\server.py
Any MCP client (e.g. OpenCode opencode.json):
{
"mcp": {
"ntobjectmanager-rpc": {
"type": "local",
"command": ["python", "C:\\path\\to\\ntobjmanager-mcp\\server.py"],
"enabled": true
}
}
}
Example: context-handle type confusion (CVE-2025-48815 pattern)
1. rpc_parse C:\Windows\System32\target.dll [symbol_path optional]
2. rpc_scan_context_handles ["C:\\Windows\\System32\\target.dll"]
3. rpc_get_interface target_0 β producer ([out] ctx) / consumer ([in] ctx) pairs
4. rpc_connect s1 target_0 β auto-discovers binding via EPM
5. rpc_methods s1 β opnum-mapped signatures
6. rpc_call s1 XsOpenPrinter-like args store_as="h" β keep the raw handle object
7. rpc_call s1 XsClosePrinter-like [{"__var__":"h"}] β feed it to the other type
store_as / {"__var__"} is the core chain primitive: RPC return objects flow
between calls without serialization round-trips, which is exactly what
producerβconsumer handle-confusion testing needs.
π Project Structure
ntobjmanager-mcp/
βββ server.py # 24 MCP tools + audit logging wrapper
βββ snippets.py # PowerShell templates (@@TOKEN@@ render + ps_str escaping)
βββ ps_engine.py # Persistent engine: base64 cmds + __MCP_DONE__ markers, timeouts
βββ wrapper.ps1 # PS-side loop (state lives in $RPCMCP)
βββ vm_listener.ps1 # Persistent guest HTTP bridge (stateful VM exec)
βββ tests/
β βββ smoke_test.py # 17 checks β live stdio end-to-end
β βββ var_test.py # 10 checks β store_as/__var__ object passing
β βββ audit.py # 43 checks β hostile inputs, concurrency, engine kill/restart
β βββ hunt.py # Full dogfood hunting round (safe policy)
β βββ hunt2_static.py # Deep-dive: symbols + producer/consumer map
β βββ hunt2_wide.py # 51-module sweep
β βββ hunt2_probe.py # Safe runtime probes (exposure / task cross-ref)
βββ ARCHITECTURE.md # Engine protocol + design decisions
βββ CHANGELOG.md # Decision history (R1βR13)
βββ SECURITY.md # Authorized-use policy + MSRC disclosure
βββ CONTRIBUTING.md # Development invariants
βββ LICENSE # MIT
π‘οΈ Honest Capability Boundaries
| Claim | Status |
|---|---|
| Stateful clients across tool calls | Yes β persistent engine + $RPCMCP |
| Stateful execution inside a lab VM | Yes β one persistent guest runspace (rpc_vm_exec); the vmrun fallback is stateless |
| Context-handle chaining (producer β consumer) | Yes β store_as / __var__ raw-object passing |
| Auto-confirm type confusion | No β NDR cannot prove distinct handle types; verify via RE (see XactSrv case) |
| Full rogue-RPC hosting | No β NtObjectManager 2.0.1 ships no server builder; rpc_alpc_squat covers race-capture only |
| ETW tracing / ALPC SDDL | Requires admin (logman / SeDebugPrivilege) |
| Symbol-resolved procedure names | Environment-dependent (symsrv chain); heuristic fallback names otherwise |
| Runs anywhere but Windows PS 5.1 | Not yet (pwsh 7 untested) |
π Documentation
- ARCHITECTURE.md β engine protocol, state model, design decisions
- CHANGELOG.md β R1βR13 decision history incl. two PS 5.1 marshaling bugs
- SECURITY.md β authorized use, VM isolation, MSRC disclosure
- CONTRIBUTING.md β development invariants and test requirements
β οΈ Disclaimer
For lawful security research, education, and authorized testing only.
rpc_call invokes real RPC methods and can crash services β run it against an
isolated VM, never a production or daily-driver host. Vulnerabilities found
through this tool must follow responsible disclosure (MSRC).
π License
MIT β Copyright (c) 2026 ntobjmanager-mcp Contributors
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol Β· Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol Β· Developer Tools
Read, search, and manipulate Git repositories programmatically
Paperclip
Freeby Paperclipai Β· Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno Β· Developer Tools
Toleno Network MCP Server β Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace Β· Developer Tools
Create, build, and publish Python MCP servers to PyPI β conversationally.
MCP Marketplace
Freeby mcp-marketplace Β· Developer Tools
Search and install MCP servers from inside your AI client.
