Provides file and URL reputation analysis across 70+ antivirus engines, enabling comprehensive malware detection and threat assessment through natural language queries.
π‘οΈ FastMCP ThreatIntel - AI-Powered Threat Intelligence
π MCP AI Powered Threat Intelligence - Revolutionizing Cybersecurity Built by
A comprehensive Model Context Protocol (MCP) server that provides enterprise-grade threat intelligence capabilities through natural language AI prompts. Analyze IPs, domains, URLs, and file hashes across multiple threat intelligence platforms with advanced APT attribution and interactive reporting.

β¨ Why FastMCP ThreatIntel?
π― Purpose-Built for Modern Security Teams
π€ AI-First Design: Natural language queries with intelligent IOC detection
π MCP Integration: Seamless integration with Claude Desktop, VSCode (Roo-Cline), and other AI assistants
β‘ Lightning Fast: UV-powered development with optimized async processing
π’ Enterprise Ready: Production-grade Docker containers and Kubernetes support
π Multi-Source Intelligence
VirusTotal: File and URL reputation analysis with 70+ antivirus engines
AlienVault OTX: Community-driven threat intelligence and IOC feeds
AbuseIPDB: IP reputation and geolocation with abuse confidence scoring
IPinfo: Enhanced geolocation, ASN, and infrastructure data
π€ AI-Powered Analysis
Natural Language Interface: Query threats using plain English
Advanced APT Attribution: Confidence-scored attribution with MITRE ATT&CK mapping
Intelligent IOC Detection: Auto-detects IP addresses, domains, URLs, and file hashes
Context-Aware Reporting: Generates comprehensive threat intelligence reports
π Rich Reporting & Visualization
Interactive HTML Reports: Modern, responsive design with dark/light modes
D3.js Network Graphs: Visual IOC relationship mapping
Multiple Output Formats: Markdown, JSON, HTML, and STIX-compliant outputs
Export Capabilities: PDF, CSV, and JSON export for integration
π Flexible Deployment Options
π MCP Server: Direct integration with AI assistants
π» Standalone CLI: Interactive and batch processing modes
π³ Docker Container: Production-ready containerization
π¦ Python Package: Embed in your applications and workflows
ποΈ Architecture
π Quick Start
Choose your preferred installation method and get started in minutes:
π pip (Fastest)
π³ Docker (Production Ready)
π₯ UV (Developer Recommended)
π¦ Poetry (Traditional)
βοΈ Configuration
π API Keys Setup
Get your free API keys and unlock the full potential:
Service | Status | Free Tier Limit | Get Your Key |
VirusTotal | Required | 1,000 requests/day | |
OTX | Required | Unlimited | |
AbuseIPDB | Optional | 1,000 requests/day | |
IPinfo | Optional | 50,000 requests/month |
π οΈ Environment Configuration
Create a .env file in your project directory:
π» Usage Examples
CLI Analysis
π MCP Integration
Integrate with AI assistants for natural language threat intelligence:
VSCode with Roo-Cline
Claude Desktop
π
π― AI Prompt Examples
π Documentation
π User Guides
MCP Integration - Connect with AI assistants
Python API - Programmatic integration
Performance Guide - Optimization and scaling
π οΈ Developer Resources
Development Setup - Contributing and building
API Reference - Complete API documentation
Examples Repository - Sample implementations
π What Makes It Special
**π₯ MCP Functionality **
MCP AI Powered: Cutting-edge threat intelligence automation
Revolutionizing Cybersecurity: Enterprise-grade AI-powered platform
Community-Focused: Open source with professional quality
π Production-Ready Features
Multi-Architecture Docker: ARM64 and AMD64 support
Kubernetes Ready: Helm charts and deployment manifests
Comprehensive Testing: 80%+ code coverage with CI/CD pipeline
Security First: Secure by design with best practices
β‘ Performance Optimized
Async Everything: Non-blocking I/O for maximum throughput
Intelligent Caching: Redis-compatible caching layer
Rate Limiting: Built-in API rate limit management
Batch Processing: Efficient bulk IOC analysis
π€ Contributing
We welcome contributions from the cybersecurity community!
Quick Start
π Complete Contributing Guide β
π License
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.
π Acknowledgments
Special thanks to the cybersecurity community and these amazing projects:
FastMCP - Excellent MCP framework foundation
VirusTotal - Comprehensive malware analysis platform
AlienVault OTX - Open threat intelligence sharing
AbuseIPDB - IP reputation and abuse reporting
MITRE ATT&CK - Threat intelligence framework
π Links & Resources
π Star this repo if you find it useful! π
π
π¦
Built with β€οΈ by