TriageMCP (PE File Analysis)
FreeNot checkedIntegrates with multiple security tools to perform static analysis of PE files, extracting critical information like import tables, metadata, strings, and malwa
About
Integrates with multiple security tools to perform static analysis of PE files, extracting critical information like import tables, metadata, strings, and malware capabilities for rapid triage of suspicious Windows executables.
README
MCP server to enable an LLM to do basic static triage of a PE.
A minimal prompt idea could be:
You are a malware analyst tasked to analyse the sample at <PATH> with your MCP tools. Create a markdown report that summarizes your findings.
Of course supplying more info will usually yield a better result.
Installation
Install dependencies:
pip install pefile yara-python die-python mcp[cli]
Then adjust triage.py and change <TOOL>_EXE_PATH and YARA_RULE_PATH accordingly.
Claude Desktop Integration
You can install this server in Claude Desktop and interact with it right away by running:
mcp install .\triage.py
Different transport protocol
By default, without using arguments, the server will use stdio transport:
.\triage.py
To use SSE transport:
.\triage.py --transport http://127.0.0.1:8744
TODO
- VT/AnyRun/Sandbox integration
- Hash lookup
- Streamable HTTP transport
Installing TriageMCP (PE File Analysis)
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/eversinc33/triagemcpFAQ
Is TriageMCP (PE File Analysis) MCP free?
Yes, TriageMCP (PE File Analysis) MCP is free — one-click install via Unyly at no cost.
Does TriageMCP (PE File Analysis) need an API key?
No, TriageMCP (PE File Analysis) runs without API keys or environment variables.
Is TriageMCP (PE File Analysis) hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install TriageMCP (PE File Analysis) in Claude Desktop, Claude Code or Cursor?
Open TriageMCP (PE File Analysis) on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare TriageMCP (PE File Analysis) with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
