Skip to main content
Glama

Mythic MCP

Creation of MCP demo for Mythic C2, to made Offensive activities

Requirements

  1. uv

  2. python3

  3. Claude Desktop

  4. Mythic C2

  5. A Windows victim machine in VMware

Related MCP server: BloodyAD MCP

Usage with Claude Desktop

To deploy this MCP Server with Claude Desktop, you'll need to edit your claude_desktop_config.json to add the following:

{
    "mcpServers": {
        "mythic_mcp": {
            "command": "/Users/xpn/.local/bin/uv",
            "args": [
                "--directory",
                "/full/path/to/mythic_mcp/",
                "run",
                "main.py",
                "mythic_admin",
                "mythic_admin_password",
                "localhost",
                "7443"
            ]
        }
    }
}

Once done, kick off Claude Desktop. There are sample prompts to show how to task the LLM, but really anything will work along the lines of:

You are an automated pentester, tasked with emulating a specific threat actor. The threat actor is APT31. Your objective is: Add a flag to C:\win.txt on DC01. Perform any required steps to meet the objective, using only techniques documented by the threat actor.

## AD Recon & Tools 🔧

This MCP includes helpers useful in Active Directory environments. Use them only on systems you are authorized to test.

- `execute_powershell(agent_id, script)` — Run an arbitrary PowerShell script on an agent. The script is encoded and executed with `-EncodedCommand`.
- `ad_recon(agent_id)` — Run common AD reconnaissance commands and return collated output (`whoami /all`, `net user /domain`, `net group /domain`, `nltest`, `net share`).
- `enum_domain_users(agent_id)` — Attempts to enumerate domain users using the `ActiveDirectory` module (falls back to `net user /domain`).
- `run_kerberoast(agent_id, rubeus_base64, args="kerberoast")` — Upload and execute Rubeus for Kerberoasting. Upload the `Rubeus.exe` binary base64-encoded and provide any additional arguments as needed.

**Caveat:** These tools perform potentially intrusive AD actions. Ensure you have written authorization before using them in any environment.
Install Server
F
license - not found
B
quality
C
maintenance

Maintenance

–Maintainers
–Response time
–Release cycle
–Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables Active Directory enumeration and abuse operations through the bloodyAD tool. Supports LDAP queries, user/group management, DNS operations, and security testing directly from AI assistants.
    16
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    Enables LLMs to perform Active Directory penetration testing using tools like NetExec, Bloodhound, Nmap, Certipy, and John the Ripper. Automates vulnerability discovery, attack path analysis, and documentation generation for security assessments.
    26
    6
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to autonomously execute over 200 open-source penetration testing tools via MCP, including reconnaissance, web exploitation, and brute-forcing, through a unified server architecture with Docker sandboxing for safe execution.
    51
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

  • MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10

  • Offline methodology engine for authorized penetration testing, CTF, and security research.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/johanrobbenites/MCP-IA-for-Offensive-Security'

If you have feedback or need assistance with the MCP directory API, please join our Discord server