MITRE ATT&CK Mapper MCP
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MITRE ATT&CK Mapper MCPWhat is technique T1055?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MITRE ATT&CK Mapper MCP
Buy Starter — £29/mo
Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.
Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.
MITRE ATT&CK matrix lookup, tactic/technique/sub-technique mapper, and incident-to-technique correlation for cyber defenders.
Install
pip install mitre-attack-mcpTools
Tool | Purpose |
| Query ATT&CK technique by ID (Txxxx) or name |
| All 14 enterprise tactics (TA0001-TA0040+) |
| Map incident IOCs/behaviors to ATT&CK techniques |
| Threat actor groups (G-codes) using a technique |
| Mitigations (M-codes) for a technique |
Pairs with
meok-attestation-api— POST results to https://meok-attestation-api.vercel.app/sign for cryptographically signed compliance certsmeok-attestation-verify— public verification of any MEOK-signed certOther MEOK governance MCPs via SOV3
mcp_bridge_call
Pricing
Free: 10 calls/day. No API key required.
Pro £79/mo: unlimited + signed attestations. Subscribe
Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai
Status
Scaffold v1.0.0 ships the MCP framework + 5 tool stubs. v1.1.0 will add real regulation data ingestion.
If your team needs this MCP fully-loaded faster, ping hello@meok.ai for sponsored development.
Wire it up — full stack
Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:
bft-progress-council-mcp — anti-loop guardrail
agent-token-budget-mcp — hard spend cap
agent-prompt-injection-firewall-mcp — OWASP LLM01 scan
agent-audit-logger-mcp — hash-chained evidence
a2a-governance-bridge-mcp — fold N attestations → 1 signed event
agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously
See meok.ai/mcp-stack for the architecture and meok.ai/mcp-stack/demo for the live in-browser demo.
License
MIT © MEOK AI Labs
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/mitre-attack-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server