Ross ROSS = Recommend OSS · open-source software intelligence for agents

BlackSnufkin/LitterBox

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end. observed · 2026-08-28

github.com/BlackSnufkin/LitterBox · YARA · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

62/100

  • Activity 80
  • Release rhythm 50
  • Longevity 44
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 616
  • days_rel: 121
  • days_push: 120
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1526 stars · 170 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces a Detection Score with triggering indicators. It includes an MCP server so LLM agents can drive the analysis pipeline end to end, and can dispatch payloads to an EDR-instrumented Windows VM.

Use cases

  • test if my payload gets detected by EDR before deployment
  • run static and dynamic malware analysis on a sample
  • check which YARA rules trigger on my binary
  • self-host a sandbox to score payload detection risk
  • let an LLM agent automate malware analysis via MCP
  • dispatch samples to an Elastic Defend or Fibratus VM and collect alerts
  • blue team malware triage with detection indicator breakdown

When to choose

  • you are a red team operator validating payloads against modern detection before field use
  • you want a self-hosted alternative to online sandboxes for sensitive samples
  • you want LLM-driven automated malware analysis via MCP
  • you need EDR telemetry (Elastic Defend, Fibratus) correlated with sandbox results

When to avoid

  • you need a general-purpose production malware detonation service at scale
  • you lack Windows environments or admin access for EDR integration
  • you only need simple antivirus scanning without detection scoring
  • your organization prohibits offensive-security tooling

Facets

application · maturity active

security penetration-testing vulnerability-scanning mcp self-hosted developer-tools security penetration-testing developer-tools self-hosted windows self-hosted python red-team malware-analysis sandbox edr-testing payload-analysis yara detection-scoring offensive-security linux docker

1 source

Member repositories

RepositoryRoleHealth v2
BlackSnufkin/LitterBoxmain62

For agents

markdown · JSON · MCP: product_card(name="BlackSnufkin/LitterBox")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem