# CYB3RMX/Qu1cksc0pe

All-in-One malware analysis tool.

Repository: https://github.com/CYB3RMX/Qu1cksc0pe
Canonical: https://ross.abutalabs.com/products/qu1cksc0pe
Language: YARA
License: GPL-3.0
License Family: copyleft
Topics: linux, malware-analysis, python3, static-analysis, security-tools, termux, elf, exe, windows, packer, suspicious-files, malware, threat-analysis, apk, osx, strings, ransomware, all-in-one, mcp, mcp-server
Last push: 2026-08-25T14:15:30+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 2511, "days_push": 8, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2049, forks 260 (observed 2026-08-28T04:06:09.076617+00:00)

## What it is
Qu1cksc0pe is an all-in-one malware analysis tool that statically and dynamically analyzes many file types, including Windows/Linux/macOS executables, Android APKs, documents, scripts, archives, PCAPs, and email files. It extracts indicators like DLLs, APIs, URLs, permissions, and MITRE ATT&CK mappings, and ships an MCP server exposing its analysis as tools for AI clients.

## Use cases
- analyze a suspicious exe for malware behavior
- extract URLs and IPs from a malware sample
- inspect android apk permissions and capabilities
- map malware samples to MITRE ATT&CK techniques
- detect packers and embedded executables in binaries
- analyze malicious vba macros in documents
- run malware static analysis from an mcp client like claude

## When to choose
- you need a single tool covering many file formats for triage
- you want quick static analysis of suspicious files on linux or termux
- you want to expose malware analysis to AI agents via MCP

## When to avoid
- you need deep reverse engineering with a full disassembler/decompiler
- you require enterprise sandbox detonation with detailed behavioral reports
- you need managed threat intelligence feeds and correlation

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, reverse-engineering, linter, cli, mcp
- domain: security, reverse-engineering, developer-tools
- platform: windows, python, cli
- tags: malware-analysis, yara, apk-analysis, threat-intelligence, mitre-attack, packer-detection, termux, command-line, linux, macos, android

## Member repositories
- CYB3RMX/Qu1cksc0pe (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:09.076617+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:57:36.500897+00:00, confidence not recorded.
  - readme: https://github.com/CYB3RMX/Qu1cksc0pe (fetched 2026-08-28T04:06:09.076617+00:00, sha 3f3b01dcf385)
- Data as of 2026-08-30T08:39:29.467469+00:00.
