Browse
→ Code & Dev
→ mal-mcp
mal-mcp
Native Windows Flare-VM MCP server for malware analysis and reverse engineering. It exposes thirty-eight tools spanning host diagnostics, hashes, binary hex reads, PE metadata, Detect It Easy, FLOSS, CAPA, YARA, entropy checks, ProcMon, Regshot, FakeNet-NG, Wireshark/tshark, PE-sieve, Hollows Hunter, UPX unpacking, dnSpy, x64dbg, and composite playbooks. Public GitHub repository created September 12, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | none |
| Endpoint | mal-mcp |
| Install | git clone https://github.com/8uggy-sec/mal-mcp.git && cd mal-mcp && python -m pip install -e . |
Use Cases
| 01 | Let an analyst drive Flare-VM static and dynamic malware-analysis tools through MCP |
| 02 | Collect hashes, strings, PE metadata, YARA matches, process-monitor evidence, and network captures from one assistant workflow |
| 03 | Run unpacking and memory-injection checks while keeping analysis local to a Windows reverse-engineering VM |
Tags
malware-analysis reverse-engineering flare-vm windows yara capa fakenet python
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>