Threat.Zone

Integrates with the Threat.Zone API to provide malware analysis capabilities including static analysis, dynamic sandbox execution

threat-zone 12
Claude CodeClaude DesktopGeneric
View source ↗

This MCP server provides AI assistants with comprehensive malware analysis capabilities through integration with the Threat.Zone API, built by the Malwation Team using Python with FastMCP, httpx, and Pydantic. It offers multiple analysis methods including static analysis, dynamic sandbox execution with configurable environments (Windows, macOS, Android, Linux), URL scanning, and CDR (Content Disarm and Reconstruction) processing, alongside detailed result retrieval for indicators of compromise, YARA rules, network traffic, and configuration extraction. The implementation features extensive sandbox customization options (timeout settings, environment selection, evasion techniques), artifact management with download capabilities for sanitized files and HTML reports, and supports both public and private scan modes, making it valuable for security researchers, malware analysts, and AI assistants that need programmatic access to advanced threat analysis workflows.

Source

Repository: https://github.com/threat-zone/threatzonemcp

Maintain Threat.Zone?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[Threat.Zone on getagentictools](https://getagentictools.com/mcp/threat-zone-threatzonemcp?ref=badge)