Skip to main content
Glama
DarkAngel-agents

OpenCTI MCP Server

OpenCTI MCP-Server

Ein Model Context Protocol (MCP)-Server für OpenCTI — die Open Cyber Threat Intelligence Platform, entwickelt von Filigran.

Verbinden Sie Ihren KI-Assistenten mit Ihrer OpenCTI-Instanz, um Bedrohungsinformationen zu suchen, Indikatoren nachzuschlagen, Berichte zu analysieren und Connectoren durch natürliche Konversation zu überwachen.

Tools

Tool

Beschreibung

search_entities

Suche nach jedem STIX-Entitätstyp (Berichte, Malware, Bedrohungsakteure usw.)

get_report

Abrufen vollständiger Berichtsdetails per STIX-ID

search_indicators

Suche nach IOCs nach Wert, Mustertyp oder Schlüsselwort

create_indicator

Erstellen eines neuen Indikators mit STIX/YARA/Sigma-Muster

list_connectors

Auflisten aller Connectoren mit Status und Warteschlangentiefe

Related MCP server: Security Infrastructure MCP Server

Schnellstart

Umgebungsvariablen

Variable

Erforderlich

Standard

Beschreibung

OPENCTI_URL

Ja

URL Ihrer OpenCTI-Instanz

OPENCTI_TOKEN

Ja

OpenCTI-API-Token

OPENCTI_SSL_VERIFY

Nein

false

SSL-Zertifikate verifizieren

MCP_TRANSPORT

Nein

stdio

Transport: stdio oder http

MCP_HOST

Nein

0.0.0.0

Host zum Binden (HTTP-Modus)

MCP_PORT

Nein

8000

Port zum Binden (HTTP-Modus)

Docker

git clone https://github.com/DarkAngel-agents/opencti-mcp.git
cd opencti-mcp

export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token

docker compose up -d

Lokal

pip install -r requirements.txt

export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token

# stdio mode
python server.py

# http mode
MCP_TRANSPORT=http python server.py

Claude Desktop

{
  "mcpServers": {
    "opencti": {
      "command": "python",
      "args": ["/path/to/opencti-mcp/server.py"],
      "env": {
        "OPENCTI_URL": "https://your-opencti-instance.com",
        "OPENCTI_TOKEN": "your-api-token"
      }
    }
  }
}

Beispiel-Prompts

  • "Suche in OpenCTI nach Bedrohungsakteuren, die mit APT28 in Verbindung stehen"

  • "Zeige mir die neuesten Berichte über Ransomware"

  • "Suche nach Indikatoren, die mit dieser IP übereinstimmen: 192.168.1.100"

  • "Erstelle einen STIX-Indikator für die Domain evil.example.com"

  • "Welche Connectoren sind aktiv und wie ist ihr Warteschlangenstatus?"

Verwandte Projekte

Lizenz

MIT

F
license - not found
Not graded
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    A Model Context Protocol server that facilitates integration with OpenCTI, allowing users to query and retrieve cyber threat intelligence data via a standardized interface.
    16
    40
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A comprehensive implementation of Model Context Protocol servers enabling natural language interactions with security platforms including Splunk SIEM, CrowdStrike EDR, and Microsoft MISP for threat intelligence querying and analysis.
    44
    22
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that connects AI assistants to MISP threat intelligence platforms. It enables threat intelligence search, IOC lookup, and event analysis through natural conversation.

View all related MCP servers

Related MCP Connectors

  • A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…

  • MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

  • A Model Context Protocol server for Wix AI tools

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/DarkAngel-agents/opencti-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server