mukul975/Malware-Sandbox-mcp

View on GitHub ↗

Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across MalwareBazaar, ThreatFox, URLhaus, Feodo, URLScan & VirusTotal — straight from Claude. BYOK, async, MITRE ATT&CK.

20 ★7 forksPythonUpdated 1mo ago

What you need to know

MCP server that integrates with malware sandbox services, allowing AI agents to submit files for analysis and retrieve detonation results.

Install

Configure sandbox service credentials
Add server to MCP client

Usage

  • Submit a sample for analysis
  • Check detonation results

Key features

  • Submit files to sandbox
  • Retrieve analysis and detonation results
  • Query malware indicators

Caveats

  • Requires access to a malware sandbox service
Platforms: Local

Reviewed 2026-08-11

Topics

anyrunclaudecybersecuritydfirfastmcphybrid-analysisiocmalware-analysismalwarebazaarmcpmitre-attackmodel-context-protocolpythonsandboxsecurity-toolsthreat-intelligence
Stars
20★
Forks
7
Language
Python
License
MIT
Created
2026-06-11
Last push
2026-08-05