[rbinghidra mcp]
A Model Context Protocol server for Ghidra-based binary analysis. Employs analyzeHeadless for sub-second cached queries of callsites, CFGs, decompiler output, and type definitions.
[agent_runtime] Decoupled binary analysis and decompiler MCP servers for AI agents. Focused, token-efficient malware triage returning bounded tool output instead of raw decompiler dumps.
$ agent: open persistent rbinr2 session and query functions
> r2_open {"binary_path":"/samples/app.exe"}
> r2_metadata {"binary_path":"/samples/app.exe", "mode":"functions"}
$ agent: request targeted function decompilation from rbinghidra
> ghidra_decompile {"binary_name":"app.exe", "function_address":"0x1400018d0"}
A Model Context Protocol server for Ghidra-based binary analysis. Employs analyzeHeadless for sub-second cached queries of callsites, CFGs, decompiler output, and type definitions.
A Model Context Protocol server for radare2-based binary analysis. Exposes 39 specialized tools managing persistent r2pipe sessions for focused disassembly and symbol tracing.
A Model Context Protocol server for ILSpyCmd-based .NET decompilation. Outlines types, searches managed metadata, and returns focused C# or IL member bodies without dumping assemblies.
Get hashes, file shape, imports, sections, strings, hardening posture, call structure, and likely behavior families before an agent spends context on a backend.
May 26, 2026
Daily threat intelligence for May 26, 2026: 400 C2 observations, 21 ransomware claims, 59 OSV MAL advisories, and 5 news items.
May 25, 2026
Daily threat intelligence for May 25, 2026: 3,154 C2 observations, 19 ransomware claims, 15 OSV MAL advisories, and 5 news items.
May 24, 2026
Daily threat intelligence for May 24, 2026: 2,738 C2 observations, 15 ransomware claims, 8 OSV MAL advisories, and 5 news items.
[submit_query] Rogue Binary tool feedback, binary-analysis tooling, malware triage, and private consulting.
I have your message. If the work fits, I will reply with the next step.