Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Tools/GitHubGitHub/sjkim1127/reversecore_mcp
Indicator of Compromise (IOC) ManagementStatic AnalysisDynamic Analysis (Sandboxing)Vulnerability AnalysisReverse EngineeringFuzzingMalware AnalysisDigital ForensicsBinary AnalysisIncident Response
GitHubsjkim1127/reversecore_mcp

Reversecore_MCP

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.

Repository anzeigen
1851835vor 14h 30mVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.
Reversecore MCP

Reversecore MCP

AI-Powered Reverse Engineering & Security Analysis via Model Context Protocol

An MCP server that gives AI assistants like Claude and Cursor the ability to perform reverse engineering, malware analysis, vulnerability research, digital forensics, and source code auditing through natural language.


CI/CD Python License: MIT Tests Coverage FastMCP PyPI Docker OpenSSF Scorecard HVTrust

Watch the Demo SafeSkill Verified


Table of Contents

  • What is Reversecore MCP?
  • Architecture
  • Tool Catalog (151 Tools)
  • Guided Analysis Prompts (22 Modes)
  • MCP Resources (11 URIs)
  • Quick Start
  • Connect to Your AI Client
  • Configuration
  • Security Model
  • Development
  • CI/CD Pipeline
  • Docker Build Architecture
  • System Requirements
  • Project Structure
  • Error Handling
  • Adding New Tools
  • Contributing
  • Documentation
  • License

What is Reversecore MCP?

Reversecore MCP is a Model Context Protocol server that wraps 151 analysis tools into a single interface that AI assistants can call through natural language.

Instead of learning the command-line syntax for a dozen different tools, you describe what you want:

"Decompile the main function of this malware sample, extract all network IOCs,
 map the behavior to MITRE ATT&CK, and generate a triage report."

The AI assistant breaks this into tool calls:

r2_decompile("sample.exe", "main")
  → extract_iocs("sample.exe")
    → add_mitre_technique(technique_id="T1071.001", ...)
      → create_analysis_report(template_type="quick_triage")

Each tool returns a structured ToolResult (either ToolSuccess or ToolError) with typed data that the AI can reason about, chain into follow-up queries, or render for the user.

What it covers

DomainWhat you can do
Static analysisDisassembly, decompilation (r2ghidra), binary parsing (LIEF), packer detection (DIE), capability detection (CAPA), string extraction, firmware scanning (binwalk)
Dynamic & symbolicESIL emulation, angr symbolic execution, taint analysis, fuzzing harness generation
Malware analysisIOC extraction, YARA scanning, dormant backdoor detection, adaptive vaccine generation, autonomous vulnerability hunting
Vulnerability researchDangerous API detection, ROP gadget discovery, heap exploit analysis, crash triage, PoC generation
Digital forensicsMemory forensics (Volatility3), PCAP analysis (Scapy), disk forensics (Sleuth Kit), artifact correlation
Source code auditPython AST scanning, C/C++ regex pattern scanning
ReportingSession-based reports with MITRE ATT&CK mapping, SIGMA rule generation, VEX reports, email delivery

Architecture

AI Client (Claude / Cursor / any MCP-compatible client)
        │  MCP Protocol (stdio or HTTP/SSE)
        ▼
┌──────────────────────────────────────────────────────┐
│                   FastMCP 3.4.4 Server               │
│          151 registered tools · Fully async          │
│                  Python 3.10–3.12                    │
├────────────────────┬─────────────────────────────────┤
│   Guided Prompts   │  Dynamic Resources              │
│  (22 analysis      │  (11 URI-based: per-binary      │
│   modes)           │   strings, IOCs, ASM, CFG, …)   │
├────────────────────┴─────────────────────────────────┤
│                  Core Infrastructure                 │
│  Config · Security · Validators · Exceptions (17)    │
│  R2 Pool · Metrics · Memory (SQLite) · Task Queue    │
│  MITRE Mapper · Evidence Engine · Resilience Layer   │
│  Arch Registry (x86/ARM/MIPS/RISC-V/PPC)            │
│  Result Cache (SHA256) · Analysis Cache (Redis+SQL)  │
│  SAST (Python AST + C/C++ Regex) · Plugin System     │
├──────────────────────────────────────────────────────┤
│                 Analysis Engines                     │
│  Radare2 6.0.4     │  YARA 4.3.1 · LIEF · Capstone  │
│  r2ghidra           │  CAPA · angr · Qiling          │
│  Volatility3 · Scapy│ DIE · Binwalk · Sleuth Kit    │
│  pwntools · ROPgadget│ Keystone (assembler)          │
└──────────────────────────────────────────────────────┘

The server supports Python 3.10–3.12. The optional angr symbolic execution engine is installed on Python 3.12 and newer, where a secure compatible release is available; Python 3.10 and 3.11 installs omit angr.

Core Infrastructure (37 modules)

The reversecore_mcp/core/ directory contains the shared infrastructure that all tools build on:

Tool herunterladen