Mitre Attck
Server Details
MITRE ATT&CK MCP — STIX bundles from github.com/mitre/cti.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Uptime
- 0.0% over 46 days
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- pipeworx-io/mcp-mitre-attck
- GitHub Stars
- 0
- Server Listing
- mcp-mitre-attck
TDQS
Scored across 21 tools
The tools split into two distinct groups: MITRE ATT&CK tools (group, mitigation, technique, etc.) and Pipeworx data tools (ask_pipeworx, bet_research, compare_entities, etc.). While within each group tools are fairly distinct, the overall mix can confuse an agent expecting only MITRE tools. Some tools like 'search' and 'discover_tools' have overlapping purposes for finding information.
Tool names are inconsistent: some use verb_noun patterns (e.g., ask_pipeworx, resolve_entity), while MITRE tools use single nouns (group, technique, tactic). CamelCase is not used, but underscore conventions vary. The mix of single-word and multi-word names with underscores creates no clear pattern.
With 21 tools, the server seems overloaded for its stated MITRE ATT&CK purpose. Only 7 tools are directly MITRE-related, while the remaining 14 are from a completely different domain (Pipeworx data and betting). This mismatch makes the tool count feel excessive and unfocused.
For MITRE ATT&CK, the coverage is minimal: basic lookups exist but no relationship queries, listing, or advanced analysis. For the Pipeworx side, it appears more complete but that domain is not expected from the server name. Overall, the surface has significant gaps for its primary stated purpose.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
21 tool updates
- First observed
ask_pipeworx - First observed
bet_research - First observed
compare_entities - First observed
discover_tools - First observed
domains - First observed
entity_profile - First observed
forget - First observed
group - First observed
mitigation - First observed
pipeworx_feedback - First observed
polymarket_arbitrage - First observed
polymarket_edges - First observed
recall - First observed
recent_changes - First observed
remember - First observed
resolve_entity - First observed
search - First observed
software - First observed
tactic - First observed
technique - First observed
validate_claim
Related MCP Connectors
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
Query and retrieve information about various adversarial tactics and techniques used in cyber atta…
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables cyber defenders to query ATT\&CK techniques, list tactics, map incidents to techniques, look up threat actor groups and mitigations, all via the MCP protocol.5MIT
- AlicenseAqualityBmaintenanceComprehensive MITRE ATT\&CK MCP server with SOC integration for technique lookup, alert mapping, and coverage analysis.2619 npm4MIT
- AlicenseNot gradedqualityDmaintenanceMCP server for a compliance knowledge graph covering 686 frameworks, 21,696+ controls and 310K+ cross-framework mappings, with tools to map controls between two standards and run coverage analysis. Node and Python implementations over stdio, plus a hosted streamable HTTP endpoint.MIT
- AlicenseAqualityAmaintenanceExposes 79 cybersecurity skills and 12 orchestrator agents over MCP, with a typed 11-field output contract, an enforced resolvable-evidence gate (no verdict without a resolvable source), and human-approval gating for every mutating action. Apache-2.0, stdlib-only.84Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.