winrm_exec
2 registry entries were observed exposing a tool named winrm_exec — 2 of them as a privileged capability (a name matching exec / write / delete keywords).
Every row is point-in-time scan output, dated below. Forge has an observed tool surface for 8,635 of 26,808 scannable entries (32%) — an entry that has not been scanned cannot appear here, so absence from this list is not evidence that an entry does not expose this tool.
- MCP serverobserved · static extractionA Model Context Protocol (MCP) server for Windows PowerShell - runs commands in a hidden process (no popup windows), with structured output,
- io.github.IMRRD/powershell-mcpprivilegedMCP serverobserved · static extractionHeadless Windows ops over MCP: hidden PowerShell + in-process SSH, WinRM & SFTP.