MCP: PPEE for AI Assistants¶
The Model Context Protocol (MCP) is an open standard that lets AI assistants call external tools. With ppee-cli --mcp, PPEE becomes an MCP server. An assistant such as Claude can then look inside Windows binaries on your machine instead of guessing:
You: Triage
C:\Samples\invoice.exe: is it signed, is it packed, and does it do anything network-related?Assistant: (calls
triage_pe, thenget_iocs) It's unsigned, and the overall entropy is 7.6, which suggests packing. The only static imports areLoadLibraryAandGetProcAddressfrom kernel32, which fits a packer stub.get_iocsfound two URLs…
Quick start¶
- Check the server runs:
ppee-cli --mcpshould printMCP server ready on stdio(press Ctrl+C to stop it). - Add it to your AI tool: find your tool in Client setup and paste its snippet, using the full path to
ppee-cli. - Ask: "Triage C:\Samples\invoice.exe". The assistant starts with
triage_peand digs deeper from there. - Go inside: "What does the installer in its overlay drop?" The assistant lists it with
list_container, and analyses any embedded PE in place.
The server can read any file you can
Paths come from the assistant, so it can open any file your user account can read. For untrusted samples or a cautious setup, run it in Docker with a read-only samples folder. See Security.
How it works¶
sequenceDiagram
participant C as MCP client<br/>(Claude Desktop / Claude Code / VS Code)
participant P as ppee-cli --mcp
participant F as PE file on disk
C->>P: initialize (stdio, JSON-RPC 2.0)
P-->>C: serverInfo "ppee", tools capability
C->>P: tools/list
P-->>C: triage_pe, analyze_pe, get_hashes, …
C->>P: tools/call triage_pe {path}
P->>F: read & parse (read-only)
P-->>C: JSON document (same as ppee-cli --json) - Transport: stdio, with newline-delimited JSON-RPC 2.0. The client starts
ppee-cli --mcpas a child process. - Protocol versions:
2025-06-18,2025-03-26,2024-11-05. - No network, no daemon: the server lives only as long as the client session. It never runs the update check.
- Same data as the CLI: each tool returns the JSON document that
ppee-cli --jsonwould print. - Read-only by default. The write tool (
patch_pe) is only available with--mcp-allow-write.
Tools at a glance¶
| Tool | Returns | Read-only |
|---|---|---|
triage_pe | Start here: the facts that stand out, plus a compact summary (~1–2k tokens) | |
analyze_pe | Any selection of sections, including runtime analysis (defaults to all except strings, similarity and the deep pass) | |
get_hashes | CRC32, MD5, SHA-1, SHA-256, ImpHash, Authentihash, SSDEEP, TLSH, entropy | |
list_imports | Imports, delay-load and bound imports | |
list_exports | Exports and forwarders | |
check_signature | Authenticode details + hashes | |
get_strings | Filtered, paged strings | |
read_bytes | Hex dump by file offset or RVA | |
decode_bytes | The strings in a range, in file order; XOR, base64, RC4, zlib, LZNT1, … on a range or a text; key search | |
hash_range | Hashes of a range, or of every section | |
disassemble | x86/x64 instructions with import names and string comments | |
get_xrefs | Where an API, address or string is used in the code | |
list_functions | Function starts found by the code scan | |
get_callers / get_callees | Call tree around a function, with the imports it calls | |
get_resources | Dialogs, version info and string tables decoded; IDs linked to code | |
list_types | A .NET assembly's types and methods; disassemble, get_xrefs and the call trees then read its IL (mixed-mode C++/CLI too) | |
search_bytes | Find hex patterns (with ?? wildcards) or up to 16 texts, with the surroundings as text | |
extract_payload | Hashes, entropy and type of the overlay, a resource or a section | (writing needs write mode) |
list_container | What an archive or installer holds: ZIP, CAB, PyInstaller, MSI, RAR | |
get_iocs | URLs, domains, IPs, registry keys, paths, pipes, PDB paths | |
check_similarity | Matches in the local similarity DB (records the file) | writes DB |
patch_pe | Applies --set edits to a copy (opt-in) | writes file |
Analyse the payload where it is
Point any tool inside a file: drop.exe#overlay, drop.exe#resource:RT_RCDATA/101, drop.exe#resource:W/101#offset:4. The layer is read in memory, nothing is extracted to disk. Ask: "Triage the PE inside resource W/101 of launcher.dll". See Look inside a file.
Every result is kept within a size budget, and large lists can be paged: see response size and paging.
Next: Set up your client →: step-by-step instructions for Claude Desktop, Claude Code, VS Code and GitHub Copilot, Cursor, Windsurf, Cline, Zed, Continue, Gemini CLI, OpenAI Codex CLI, opencode, Kilo Code, OpenClaw, Hermes Agent and JetBrains AI Assistant.
References¶
- Model Context Protocol specification: the protocol PPEE's MCP server implements.