Developer Tools · Security

YaraFlux logo

YaraFlux

ThreatFlux/YaraFlux

YaraFlux MCP Server enables AI assistants to perform YARA rule-based threat analysis through the standardized Model Context Protocol interface. The server integrates YARA scanning with modern AI assistants, supporting comprehensive rule management, secure scanning, and detailed result analysis through a modular architecture.

Install

docker run -i --rm --env JWT_SECRET_KEY=<value> --env ADMIN_PASSWORD=<value> --env DEBUG=<value> --env PYTHONUNBUFFERED=<value> threatflux/yaraflux-mcp-server:latest

Client configuration

{
  "mcpServers": {
    "yaraflux-mcp-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--env",
        "JWT_SECRET_KEY=your-secret-key",
        "--env",
        "ADMIN_PASSWORD=your-admin-password",
        "--env",
        "DEBUG=true",
        "--env",
        "PYTHONUNBUFFERED=1",
        "threatflux/yaraflux-mcp-server:latest"
      ]
    }
  }
}
GitHub stars
12
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

About YaraFlux

A Model Context Protocol (MCP) server for YARA scanning, providing LLMs with capabilities to analyze files with YARA rules.

Features

  • Modular Architecture

  • MCP Integration

  • YARA Scanning

  • Rule Management

  • File Analysis

  • Security Features

Tools (17)

  • get_yara_rule

    Get a specific YARA rule's content and metadata

  • validate_yara_rule

    Validate YARA rule syntax with detailed error reporting

  • add_yara_rule

    Create a new YARA rule

  • update_yara_rule

    Update an existing YARA rule

  • delete_yara_rule

    Delete a YARA rule

  • import_threatflux_rules

    Import rules from ThreatFlux GitHub repository

  • scan_url

    Scan content from a URL with specified YARA rules

  • scan_data

    Scan provided data (base64 encoded) with specified rules

  • get_scan_result

    Retrieve detailed results from a previous scan

  • upload_file

    Upload a file for analysis or scanning

  • get_file_info

    Get metadata about an uploaded file

  • delete_file

    Delete an uploaded file

  • extract_strings

    Extract ASCII/Unicode strings from a file

  • get_hex_view

    Get hexadecimal view of file content

  • download_file

    Download an uploaded file

  • get_storage_info

    Get storage usage statistics

  • clean_storage

    Remove old files to free up storage space

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools