Malware Analysis MCP Server
Related Servers
Alternatives to Malware Analysis MCP Server
No user-submitted related servers found.
Related Servers
- FlicenseBqualityCmaintenanceEnables AI assistants to access Google's Threat Intelligence suite for file analysis, indicator of compromise searches, and reputation checking. It supports both local and cloud-based deployments for investigating campaigns, threat actors, and malware families.364-
- AlicenseAqualityBmaintenanceEnables AI assistants to perform cybersecurity tasks including hash analysis, CVE lookup, HTTP header auditing, WHOIS/OSINT, payload decoding, password strength evaluation, and threat report generation.7MIT

REMnux MCP Serverofficial
AlicenseAqualityBmaintenanceEnables AI assistants to execute malware analysis tools on a REMnux system via Docker, SSH, or local connections. It provides automated file-type analysis, structured tool discovery, and security guardrails for streamlined malware investigation.121,346 npm123GPL 3.0- AlicenseAqualityCmaintenanceEnables assistants to analyze files and URLs for malware by integrating with security services like VirusTotal and ANY.RUN, returning threat reports.20MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to perform digital forensics analysis including memory analysis, file metadata inspection, and threat-intelligence lookups.5 npmISC
- FlicenseNot gradedqualityDmaintenanceProvides real-time threat intelligence for AI agents, enabling checks on IPs, domains, URLs, hashes, CVEs, prompt-injection payloads, and malicious AI-skill/MCP-tool definitions against a free database of 890K+ IOCs.-
TDQS
Scored across 29 tools
Several tools have vague or overlapping purposes, especially get_recent, get_info, get_taginfo, virustotal_lookup, and vt_lookup. The lack of descriptions makes it hard to distinguish similar-sounding intel lookup and generic retrieval tools from one another.
Most names use snake_case, which is readable, but the set mixes verb_noun patterns with noun-only names like entropy and hexdump_text. Abbreviation inconsistency between virustotal_lookup and vt_lookup weakens predictability.
At 29 tools, the server is heavy for a malware analysis utility surface and includes apparent duplication. The encoding, compression, hashing, and crypto operations could likely be grouped or reduced.
The tool set broadly covers threat intel lookup, local file checks, encoding, hashing, entropy, IOC handling, YARA templating, and alerting. It lacks obvious dynamic analysis or sandbox detonation capabilities, but the core analysis utility surface is fairly comprehensive.