MCP Server
AI-assisted operation via Claude Code, Cursor, and other MCP clients
Krait ships with an MCP (Model Context Protocol) server that exposes the operator API as AI-callable tools. This lets you run Krait operations from Claude Code, Cursor, or any MCP-compatible client.
Setup
1. Install dependencies
pip install -r mcp/requirements.txt
This installs mcp and httpx.
2. Configure credentials
Edit mcp/.mcp.json and fill in your operator credentials:
{
"mcpServers": {
"krait": {
"command": "python3",
"args": ["mcp_server.py"],
"cwd": "mcp",
"env": {
"KRAIT_SERVER": "http://127.0.0.1:50051",
"KRAIT_USER": "your-operator-username",
"KRAIT_PASSWORD": "your-operator-password"
}
}
}
}
Change KRAIT_SERVER if your operator is running on a different host or port.
3. Connect your MCP client
Claude Code:
Copy the MCP config into your project’s .mcp.json or your global ~/.claude/.mcp.json:
cp mcp/.mcp.json /path/to/your/project/.mcp.json
Then start Claude Code from that directory — Krait tools appear automatically.
Cursor / Other clients:
Add the krait server entry from mcp/.mcp.json to your client’s MCP configuration. The server communicates over stdio transport.
Available Tools
Read-Only (safe to call freely)
| Tool | Description |
|---|---|
krait_list_sessions | List all agent sessions with status, transport, and lock info |
krait_get_session | Detailed info for a specific agent (prefix match supported) |
krait_list_bofs | List available BOFs by category with MITRE ATT&CK tags |
krait_get_bof_info | Usage syntax and details for a specific BOF |
krait_get_results | Task output from a specific agent |
krait_get_events | Server event log (registrations, tasks, results) |
krait_get_topology | ASCII tree of agent parent-child relationships |
krait_get_mitre_report | MITRE ATT&CK coverage report for the engagement |
Destructive (dispatches tasks to live implants)
| Tool | Description |
|---|---|
krait_interact | Execute any Krait command on an agent |
krait_execute_assembly | Run a .NET assembly in-memory via CLR hosting |
krait_socks_start | Start a SOCKS5 proxy through an agent |
krait_socks_stop | Stop the SOCKS5 proxy |
Destructive tools are annotated with MCP’s destructiveHint — clients like Claude Code will ask for confirmation before executing them.
Usage Examples
Once connected, you can interact with Krait through natural language:
- “List all active sessions”
- “What BOFs are available in the credential category?”
- “Run whoami on agent 3a8f”
- “Show me the MITRE coverage for this engagement”
- “Start a SOCKS proxy on port 9050 through agent 3a8f”
- “Get the latest results from agent 3a8f”
Command-Line Usage
The MCP server can also be run directly for testing:
python3 mcp/mcp_server.py --server http://127.0.0.1:50051 --user admin --password yourpass
It communicates over stdio using the MCP protocol — this is primarily useful for debugging connectivity.
Security Notes
- The MCP server runs on the operator’s machine, not on the target. It’s a client to your Krait server, not a network service.
- Credentials are stored in the
.mcp.jsonenvironment variables. Treat this file like any other credential store. - The server authenticates to Krait’s API using the same operator accounts as the CLI and web UI — no elevated access.
- Destructive tools are annotated so MCP clients prompt for confirmation before dispatching commands to live implants.