{"repo":"JameZUK/Arkana","free":true,"listed":false,"github":"https://github.com/JameZUK/Arkana","clone":"git clone https://github.com/JameZUK/Arkana.git","description":"Arkana - Your entire malware analysis lab, behind one AI prompt. 250+ MCP tools for binary analysis with Claude Code or other MCP","language":"Python","stars":94,"topics":["binary","cybersecurity-tools","malware-analysis","malware-analyzer","malware-research","mcp-server","reverse-engineering"],"license":"MIT","category":"security-tools","readme_excerpt":"Arkana - Your Entire Malware Analysis Lab, Behind One AI Prompt \"Analyse asyncrat.exe and tell me what it does\" From a single prompt, Arkana opens the binary, triages it (CRITICAL -- 43/72 VT detections), extracts the C2 server ( cveutb.sa.com ), identifies AES-256 encrypted communications via MessagePack, maps 12 MITRE ATT&CK techniques, detects anti-VM checks for VMware/VirtualBox/ Sandboxie, finds the persistence mechanism (Registry Run key), and recovers the operator's PDB path revealing a Vietnamese-speaking threat actor. See the full report. \"Step through the unpacking stub and show me what it decrypts\" Arkana starts an interactive debug session, sets breakpoints on VirtualAlloc and VirtualProtect , steps through the decryption loop, snapshots state before and after, diffs the memory regions, and dumps the unpacked payload -- all driven by natural language. Arkana is a Model Context Protocol (MCP) server that gives Claude Code (or any MCP client) 294 analysis tools -- decompilation, symbolic execution, interactive step-through debugging, data-flow analysis, YARA/capa/FLOSS signatures, Binary Refinery data transforms, Qiling/Speakeasy emulation, .NET deobfuscation, function similarity matching, and a real-time web dashboard -- so you can investigate PE, ELF, Mach-O, .NET, Go, Rust, and shellcode samples by describing what you want to know. No Ghidra scripts, no CLI flags, no context-switching between a dozen tools. Just results. --- Why Arkana The problem: Malware analys","default_branch":null,"files":null,"tree":[],"storefront":"/r/JameZUK","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JameZUK/Arkana/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}