BigHugger
GH Repository · BlackSnufkin

LitterBox

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

stars
1,543
30-day movement
+41/day
Related entries
60
Connections
1
docker-composemcp-servermalware-analysismcpaioffensive-securitysandboxYARAredteampythonmalware-development

LitterBox is a self-hosted sandbox that lets red teams test payloads against modern detection mechanisms before deploying them. It ships as an MCP server, so an LLM agent can drive the analysis workflow end to end, and it is deployed via docker-compose.

Choose it when you want a private sandbox to check how your payloads trip detection, with the option of LLM-agent-driven analysis through MCP.

Use it to

  • Test payloads against detection before deployment
  • Integrate sandbox analysis into an LLM agent via MCP
  • Run the sandbox locally with docker-compose
  • Perform malware-style analysis using built-in YARA support

For Red teamers and offensive security practitioners

Role
mcp-server
Language
YARA
Licence
GPL-3.0
Forks
169
Open issues
1
Last push
2026-05-05
Latest release
v5.0.0 · 2026-05-04
topicsredteamsandboxmcp-servermalware-analysisoffensive-securityself-hosted