TriageMCP (PE File Analysis) MCP server

Integrates with multiple security tools to perform static analysis of PE files, extracting critical information like import tables, metadata, strings, and malware capabilities for rapid triage of suspicious Windows executables.
Back to servers
Setup instructions
Provider
eversinc33
Release date
May 18, 2025
Language
Python
Stats
63 stars

This MCP server enables large language models (LLMs) to perform basic static triage of PE (Portable Executable) files. By providing tools to analyze potentially malicious files, it allows an LLM to generate analysis reports with minimal prompting.

Installation

To set up the TriageMCP server, follow these steps:

Install Dependencies

First, install all required Python packages:

pip install pefile yara-python die-python fastmcp

Configure the Server

Open the triage.py file and modify the following configuration variables to match your environment:

  • <TOOL>_EXE_PATH: Update with the correct path to your analysis tools
  • YARA_RULE_PATH: Set to the directory containing your YARA rules

Complete Installation

After configuring the paths, install the MCP server:

fastmcp install .\triage.py

Usage

The TriageMCP server is designed to be used with an LLM to analyze PE files. Here's a basic example of how to use it:

Basic Prompt Template

You can use the following simple prompt to initiate a PE file analysis:

You are a malware analyst tasked to analyse the sample at <PATH> with your MCP tools. Create a markdown report that summarizes your findings.

Advanced Usage

For more comprehensive analysis, consider enhancing your prompts with:

  • Specific aspects of the file to analyze
  • Particular threats or behaviors to look for
  • Additional context about the file's origin
  • Desired format or sections for the analysis report

The more specific information you provide in your prompt, the more detailed and relevant the analysis will be.

Features

Currently, the TriageMCP server offers basic static PE file analysis. Future versions are planned to include:

  • Integration with VirusTotal, AnyRun, and other sandbox environments
  • Hash lookup capabilities for known malware samples

How to install this MCP server

For Claude Code

To add this MCP server to Claude Code, run this command in your terminal:

claude mcp add-json "triagemcp" '{"command":"python","args":["-m","triage"]}'

See the official Claude Code MCP documentation for more details.

For Cursor

There are two ways to add an MCP server to Cursor. The most common way is to add the server globally in the ~/.cursor/mcp.json file so that it is available in all of your projects.

If you only need the server in a single project, you can add it to the project instead by creating or adding it to the .cursor/mcp.json file.

Adding an MCP server to Cursor globally

To add a global MCP server go to Cursor Settings > Tools & Integrations and click "New MCP Server".

When you click that button the ~/.cursor/mcp.json file will be opened and you can add your server like this:

{
    "mcpServers": {
        "triagemcp": {
            "command": "python",
            "args": [
                "-m",
                "triage"
            ]
        }
    }
}

Adding an MCP server to a project

To add an MCP server to a project you can create a new .cursor/mcp.json file or add it to the existing one. This will look exactly the same as the global MCP server example above.

How to use the MCP server

Once the server is installed, you might need to head back to Settings > MCP and click the refresh button.

The Cursor agent will then be able to see the available tools the added MCP server has available and will call them when it needs to.

You can also explicitly ask the agent to use the tool by mentioning the tool name and describing what the function does.

For Claude Desktop

To add this MCP server to Claude Desktop:

1. Find your configuration file:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
  • Linux: ~/.config/Claude/claude_desktop_config.json

2. Add this to your configuration file:

{
    "mcpServers": {
        "triagemcp": {
            "command": "python",
            "args": [
                "-m",
                "triage"
            ]
        }
    }
}

3. Restart Claude Desktop for the changes to take effect

Want to 10x your AI skills?

Get a free account and learn to code + market your apps using AI (with or without vibes!).

Nah, maybe later