This wraps a Dockerized Kali Linux environment into an MCP server so you can call security tools directly from Claude or other MCP clients. It exposes operations for nmap scans (basic, stealth, vulnerability), binary analysis with objdump and nm, string extraction, and tshark for packet capture and pcap analysis. The whole thing runs in an isolated container with configurable resource limits. You'd reach for this when you need to run security tooling or reverse engineering workflows without leaving your chat interface, whether that's scanning a network range, disassembling a binary, or pulling HTTP streams from a capture file. Built on FastMCP, still early but functional for common Kali use cases.
Welcome to awsome-kali-MCPServers! This repository is a collection of Model Context Protocol (MCP) servers designed specifically for Kali Linux environments. The goal is to enhance reverse engineering, security testing, and automation workflows by integrating powerful tools and flexible features. Whether you're a security researcher or a developer, this project aims to streamline your tasks with Kali Linux.
Follow these steps to quickly get started with kali-mcps:
docker build -t kali-mcps:latest .
{
"mcpServers": {
"kali-docker": {
"command": "docker",
"args": ["run", "-i", "kali-mcps:latest"]
}
}
}
"kali-docker" is the server name, which you can customize."command": "docker" specifies that Docker will be used to run the container."args" defines the Docker run parameters: -i enables interactive mode, and kali-mcps:latest is the image you just built.basic_scan for basic network scanning.disassemble to disassemble a target file.capture_live to capture real-time network traffic.
Network Analysis: Tools for sniffing and analyzing traffic. Binary Understanding: Support for reverse engineering and function analysis. Automation: Scripts and servers to simplify repetitive tasks.
Since the last update, we have added the following features, integrating a series of tools based on the FastMCP framework:
basic_scan: Basic network scanning.intense_scan: In-depth network scanning.stealth_scan: Stealth network scanning.quick_scan: Quick network scanning.vulnerability_scan: Vulnerability scanning.basic_symbols: Lists basic symbols.dynamic_symbols: Lists dynamic symbols.demangle_symbols: Decodes symbols.numeric_sort: Sorts symbols numerically.size_sort: Sorts symbols by size.undefined_symbols: Lists undefined symbols.file_headers: Lists file headers.disassemble: Disassembles the target file.symbol_table: Lists the symbol table.section_headers: Lists section headers.full_contents: Lists full contents.basic_strings: Basic string extraction.min_length_strings: Extracts strings with a specified minimum length.offset_strings: Extracts strings with offsets.encoding_strings: Extracts strings based on encoding.capture_live: Captures network traffic in real-time.analyze_pcap: Analyzes pcap files.extract_http: Extracts HTTP data.protocol_hierarchy: Lists protocol hierarchy.conversation_statistics: Provides conversation statistics.expert_info: Analyzes expert information.A new sandbox feature has been added, enabling secure command execution in an isolated container environment:
Runs commands using Docker containers, with the default image being ubuntu-systemd:22.04. Configurable memory limit (default: 2GB), CPU limit (default: 1 core), network mode, and timeout duration. Supports bidirectional file copying between the host and the container. Automatically cleans up container resources.
This project is still in its early stages. I’m working on preparing the content, including server configurations, tool integrations, and documentation. Nothing is fully ready yet, but stay tuned—exciting things are coming soon!
Feel free to star or watch this repository to get updates as I add more features and files. Contributions and suggestions are welcome once the groundwork is laid out.
makafeli/n8n-workflow-builder
danishashko/make-mcp
lukisch/n8n-manager-mcp
io.github.us-all/airflow
io.github.infoinlet-marketplace/mcp-workflow