Skip to content

MCP: PPEE for AI Assistants

The Model Context Protocol (MCP) is an open standard that lets AI assistants call external tools. With ppee-cli --mcp, PPEE becomes an MCP server. An assistant such as Claude can then look inside Windows binaries on your machine instead of guessing:

You: Triage C:\Samples\invoice.exe: is it signed, is it packed, and does it do anything network-related?

Assistant: (calls triage_pe, then get_iocs) It's unsigned, and the overall entropy is 7.6, which suggests packing. The only static imports are LoadLibraryA and GetProcAddress from kernel32, which fits a packer stub. get_iocs found two URLs…

Quick start

  1. Check the server runs: ppee-cli --mcp should print MCP server ready on stdio (press Ctrl+C to stop it).
  2. Add it to your AI tool: find your tool in Client setup and paste its snippet, using the full path to ppee-cli.
  3. Ask: "Triage C:\Samples\invoice.exe". The assistant starts with triage_pe and digs deeper from there.
  4. Go inside: "What does the installer in its overlay drop?" The assistant lists it with list_container, and analyses any embedded PE in place.

The server can read any file you can

Paths come from the assistant, so it can open any file your user account can read. For untrusted samples or a cautious setup, run it in Docker with a read-only samples folder. See Security.

How it works

sequenceDiagram
    participant C as MCP client<br/>(Claude Desktop / Claude Code / VS Code)
    participant P as ppee-cli --mcp
    participant F as PE file on disk
    C->>P: initialize (stdio, JSON-RPC 2.0)
    P-->>C: serverInfo "ppee", tools capability
    C->>P: tools/list
    P-->>C: triage_pe, analyze_pe, get_hashes, …
    C->>P: tools/call triage_pe {path}
    P->>F: read & parse (read-only)
    P-->>C: JSON document (same as ppee-cli --json)
  • Transport: stdio, with newline-delimited JSON-RPC 2.0. The client starts ppee-cli --mcp as a child process.
  • Protocol versions: 2025-06-18, 2025-03-26, 2024-11-05.
  • No network, no daemon: the server lives only as long as the client session. It never runs the update check.
  • Same data as the CLI: each tool returns the JSON document that ppee-cli --json would print.
  • Read-only by default. The write tool (patch_pe) is only available with --mcp-allow-write.

Tools at a glance

Tool Returns Read-only
triage_pe Start here: the facts that stand out, plus a compact summary (~1–2k tokens)
analyze_pe Any selection of sections, including runtime analysis (defaults to all except strings, similarity and the deep pass)
get_hashes CRC32, MD5, SHA-1, SHA-256, ImpHash, Authentihash, SSDEEP, TLSH, entropy
list_imports Imports, delay-load and bound imports
list_exports Exports and forwarders
check_signature Authenticode details + hashes
get_strings Filtered, paged strings
read_bytes Hex dump by file offset or RVA
decode_bytes The strings in a range, in file order; XOR, base64, RC4, zlib, LZNT1, … on a range or a text; key search
hash_range Hashes of a range, or of every section
disassemble x86/x64 instructions with import names and string comments
get_xrefs Where an API, address or string is used in the code
list_functions Function starts found by the code scan
get_callers / get_callees Call tree around a function, with the imports it calls
get_resources Dialogs, version info and string tables decoded; IDs linked to code
list_types A .NET assembly's types and methods; disassemble, get_xrefs and the call trees then read its IL (mixed-mode C++/CLI too)
search_bytes Find hex patterns (with ?? wildcards) or up to 16 texts, with the surroundings as text
extract_payload Hashes, entropy and type of the overlay, a resource or a section (writing needs write mode)
list_container What an archive or installer holds: ZIP, CAB, PyInstaller, MSI, RAR
get_iocs URLs, domains, IPs, registry keys, paths, pipes, PDB paths
check_similarity Matches in the local similarity DB (records the file) writes DB
patch_pe Applies --set edits to a copy (opt-in) writes file

Analyse the payload where it is

Point any tool inside a file: drop.exe#overlay, drop.exe#resource:RT_RCDATA/101, drop.exe#resource:W/101#offset:4. The layer is read in memory, nothing is extracted to disk. Ask: "Triage the PE inside resource W/101 of launcher.dll". See Look inside a file.

Every result is kept within a size budget, and large lists can be paged: see response size and paging.

Next: Set up your client →: step-by-step instructions for Claude Desktop, Claude Code, VS Code and GitHub Copilot, Cursor, Windsurf, Cline, Zed, Continue, Gemini CLI, OpenAI Codex CLI, opencode, Kilo Code, OpenClaw, Hermes Agent and JetBrains AI Assistant.

References