← Documentation / Operator Guide

MCP Server

AI-assisted operation via Claude Code, Cursor, and other MCP clients

Krait ships with an MCP (Model Context Protocol) server that exposes the operator API as AI-callable tools. This lets you run Krait operations from Claude Code, Cursor, or any MCP-compatible client.

Setup

1. Install dependencies

pip install -r mcp/requirements.txt

This installs mcp and httpx.

2. Configure credentials

Edit mcp/.mcp.json and fill in your operator credentials:

{
  "mcpServers": {
    "krait": {
      "command": "python3",
      "args": ["mcp_server.py"],
      "cwd": "mcp",
      "env": {
        "KRAIT_SERVER": "http://127.0.0.1:50051",
        "KRAIT_USER": "your-operator-username",
        "KRAIT_PASSWORD": "your-operator-password"
      }
    }
  }
}

Change KRAIT_SERVER if your operator is running on a different host or port.

3. Connect your MCP client

Claude Code:

Copy the MCP config into your project’s .mcp.json or your global ~/.claude/.mcp.json:

cp mcp/.mcp.json /path/to/your/project/.mcp.json

Then start Claude Code from that directory — Krait tools appear automatically.

Cursor / Other clients:

Add the krait server entry from mcp/.mcp.json to your client’s MCP configuration. The server communicates over stdio transport.

Available Tools

Read-Only (safe to call freely)

ToolDescription
krait_list_sessionsList all agent sessions with status, transport, and lock info
krait_get_sessionDetailed info for a specific agent (prefix match supported)
krait_list_bofsList available BOFs by category with MITRE ATT&CK tags
krait_get_bof_infoUsage syntax and details for a specific BOF
krait_get_resultsTask output from a specific agent
krait_get_eventsServer event log (registrations, tasks, results)
krait_get_topologyASCII tree of agent parent-child relationships
krait_get_mitre_reportMITRE ATT&CK coverage report for the engagement

Destructive (dispatches tasks to live implants)

ToolDescription
krait_interactExecute any Krait command on an agent
krait_execute_assemblyRun a .NET assembly in-memory via CLR hosting
krait_socks_startStart a SOCKS5 proxy through an agent
krait_socks_stopStop the SOCKS5 proxy

Destructive tools are annotated with MCP’s destructiveHint — clients like Claude Code will ask for confirmation before executing them.

Usage Examples

Once connected, you can interact with Krait through natural language:

  • “List all active sessions”
  • “What BOFs are available in the credential category?”
  • “Run whoami on agent 3a8f”
  • “Show me the MITRE coverage for this engagement”
  • “Start a SOCKS proxy on port 9050 through agent 3a8f”
  • “Get the latest results from agent 3a8f”

Command-Line Usage

The MCP server can also be run directly for testing:

python3 mcp/mcp_server.py --server http://127.0.0.1:50051 --user admin --password yourpass

It communicates over stdio using the MCP protocol — this is primarily useful for debugging connectivity.

Security Notes

  • The MCP server runs on the operator’s machine, not on the target. It’s a client to your Krait server, not a network service.
  • Credentials are stored in the .mcp.json environment variables. Treat this file like any other credential store.
  • The server authenticates to Krait’s API using the same operator accounts as the CLI and web UI — no elevated access.
  • Destructive tools are annotated so MCP clients prompt for confirmation before dispatching commands to live implants.