# list_drivers

Enumerate kernel drivers via Win32_SystemDriver.

Agent View of the PolicyLayer registry record for `list_drivers`. HTML page: https://policylayer.com/tools/0xhackerfren-procmon-mcp/list-drivers

## Facts

- Tool: `list_drivers`
- Server: Procmon (`0xhackerfren/procmon-mcp`) — https://policylayer.com/tools/0xhackerfren-procmon-mcp.md
- Homepage: https://github.com/0xhackerfren/ProcMon-MCP
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_drivers",
    "arguments": {}
  }
}
```

## Why list_drivers is rated Low

The tool retrieves a list of kernel drivers using the WMI Win32_SystemDriver class. This is a read-only operation that queries system information without creating, modifying, deleting, or executing any code. While kernel driver information could theoretically inform malicious actions, the tool itself performs no side effects and poses minimal direct risk as a standalone operation.

From the tool's own definition: "Tool 'list_drivers' uses 'Enumerate kernel drivers via Win32_SystemDriver' - a passive query operation that retrieves system state without modification or execution."

## Use case

AI agents call list_drivers to retrieve information from Procmon without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Procmon:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_drivers": {}
  }
}
```

## Other tools on Procmon (17)

- `request_elevation` — Execute — https://policylayer.com/tools/0xhackerfren-procmon-mcp/request-elevation.md
- `start_etw_trace` — Execute — https://policylayer.com/tools/0xhackerfren-procmon-mcp/start-etw-trace.md
- `stop_etw_trace` — Execute — https://policylayer.com/tools/0xhackerfren-procmon-mcp/stop-etw-trace.md
- `timed_capture` — Execute — https://policylayer.com/tools/0xhackerfren-procmon-mcp/timed-capture.md
- `analyze_pe` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/analyze-pe.md
- `capture_snapshot` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/capture-snapshot.md
- `check_elevation` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/check-elevation.md
- `find_pe_files` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/find-pe-files.md
- `get_minifilters` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/get-minifilters.md
- `get_network_connections` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/get-network-connections.md
- `get_process_details` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/get-process-details.md
- `get_security_events` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/get-security-events.md
- `get_system_info` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/get-system-info.md
- `list_etw_providers` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/list-etw-providers.md
- `list_processes` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/list-processes.md
- `list_services` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/list-services.md
- `query_event_log` — Read — https://policylayer.com/tools/0xhackerfren-procmon-mcp/query-event-log.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xhackerfren-procmon-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/0xhackerfren-procmon-mcp
