Labsco
MCP SERVER · OFFICIAL PROJECT

Binalyze AIR MCP Server

by binalyze

Run a Binalyze AIR investigation from the assistant: acquire evidence from endpoints, isolate them, sweep with triage rules, and keep every artefact attached to a case.

Threat Intelligence & Digital ForensicsVerified
Summary
The full arc of an endpoint investigation — acquire, triage, isolate, record — runs against a single case.

Cases are the spine here: endpoints, tasks, notes, users and activities all hang off one, and each of those can be exported separately when the investigation has to leave the platform. The destructive tools are scoped rather than broad — uninstall and purge both require an included-endpoint-ID filter instead of accepting a wide match. Two things can be checked before they exist: a triage rule's syntax, and an FTPS, Azure Storage or Amazon S3 repository's configuration.

What it is

A client for a Binalyze AIR deployment spanning assets, evidence acquisition, triage, cases, policies, evidence repositories, organizations and audit logs.

What you get
  • Assets listed and inspected with the tasks attached to them, tagged by hand or by auto-tag rules written for Linux, Windows and macOS, and uninstalled with or without purging their data.
  • Evidence acquisition: profiles created and listed, acquisition and disk image tasks assigned to endpoints and volumes, baseline acquisition and comparison with a report, and the artifact and e-discovery pattern catalogues.
  • Endpoint actions assigned by filter — isolation, reboot, shutdown, log retrieval and version update.
  • Triage rules validated for syntax before creation, then created, updated, deleted and assigned as tasks, with triage tags beside them.
  • Cases opened, closed, archived and reassigned, carrying notes, endpoints, tasks, users and activity history, each exportable on its own, with a name-collision check before creation.
  • Evidence repositories on SMB, SFTP, FTPS, Azure Storage and Amazon S3, with FTPS, Azure and S3 configurations validated before they are saved.
  • Policies with storage, compression and filter settings, priority ordering and match statistics; organizations with users, tags, deployment tokens and shareable deployment settings; audit logs listed and exported; task assignments cancelled or deleted; and task reports and PPC files downloaded.
Requirements

A Binalyze AIR deployment you can reach, with its host in AIR_HOST and an API token in AIR_API_TOKEN, held by an account entitled to the actions you intend — isolation, uninstall and purge among them.

Setup effort

One command plus a key — npx -y @binalyze/air-mcp, then supply credentials