# TriageMCP (PE File Analysis)

> Use this tool when you need to analyze Portable Executable (PE) files for security threats, as it provides automated static analysis and integrates with multiple security tools to extract critical information. It solves problems such as identifying malware capabilities, extracting metadata, and scanning for suspicious activity, and accepts PE files as input, producing detailed analysis reports as output. Ideal for security analysts, it streamlines the triage process for suspicious Windows executables, reducing manual tool interaction and enhancing threat detection efficiency.

Canonical page: https://skillsregistry.net/skills/eversinc33-triage-pe-file-analysis  
JSON: https://api.skillsregistry.net/v1/skills/eversinc33-triage-pe-file-analysis

## Description

TriageMCP is a server that enables LLMs to perform basic static analysis of PE (Portable Executable) files. It integrates with multiple security tools including detect-it-easy, YARA, capa, floss, and UPX to extract critical information such as import/export tables, section details, metadata, strings, and capabilities. The implementation provides tools for calculating file hashes, analyzing PE structures, scanning with YARA rules, unpacking UPX-compressed executables, and identifying malware capabilities - making it particularly valuable for security analysts who need to quickly triage suspicious Windows executables without manual tool interaction.

## Trust

- **Trust score (0–1):** 0.95
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/eversinc33-triage-pe-file-analysis)
- **Repository:** <https://github.com/eversinc33/triagemcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "eversinc33-triage-pe-file-analysis"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/eversinc33-triage-pe-file-analysis` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/eversinc33-triage-pe-file-analysis/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
