OpenCTI MCP Server
OpenCTI MCP-Server
Ein Model Context Protocol (MCP)-Server für OpenCTI — die Open Cyber Threat Intelligence Platform, entwickelt von Filigran.
Verbinden Sie Ihren KI-Assistenten mit Ihrer OpenCTI-Instanz, um Bedrohungsinformationen zu suchen, Indikatoren nachzuschlagen, Berichte zu analysieren und Connectoren durch natürliche Konversation zu überwachen.
Tools
Tool | Beschreibung |
| Suche nach jedem STIX-Entitätstyp (Berichte, Malware, Bedrohungsakteure usw.) |
| Abrufen vollständiger Berichtsdetails per STIX-ID |
| Suche nach IOCs nach Wert, Mustertyp oder Schlüsselwort |
| Erstellen eines neuen Indikators mit STIX/YARA/Sigma-Muster |
| Auflisten aller Connectoren mit Status und Warteschlangentiefe |
Related MCP server: Security Infrastructure MCP Server
Schnellstart
Umgebungsvariablen
Variable | Erforderlich | Standard | Beschreibung |
| Ja | — | URL Ihrer OpenCTI-Instanz |
| Ja | — | OpenCTI-API-Token |
| Nein |
| SSL-Zertifikate verifizieren |
| Nein |
| Transport: |
| Nein |
| Host zum Binden (HTTP-Modus) |
| Nein |
| Port zum Binden (HTTP-Modus) |
Docker
git clone https://github.com/DarkAngel-agents/opencti-mcp.git
cd opencti-mcp
export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token
docker compose up -dLokal
pip install -r requirements.txt
export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token
# stdio mode
python server.py
# http mode
MCP_TRANSPORT=http python server.pyClaude Desktop
{
"mcpServers": {
"opencti": {
"command": "python",
"args": ["/path/to/opencti-mcp/server.py"],
"env": {
"OPENCTI_URL": "https://your-opencti-instance.com",
"OPENCTI_TOKEN": "your-api-token"
}
}
}
}Beispiel-Prompts
"Suche in OpenCTI nach Bedrohungsakteuren, die mit APT28 in Verbindung stehen"
"Zeige mir die neuesten Berichte über Ransomware"
"Suche nach Indikatoren, die mit dieser IP übereinstimmen: 192.168.1.100"
"Erstelle einen STIX-Indikator für die Domain evil.example.com"
"Welche Connectoren sind aktiv und wie ist ihr Warteschlangenstatus?"
Verwandte Projekte
misp-mcp — MCP-Server für MISP
nixos-anssi-bp028 — NixOS ANSSI-Härtungsmodul
Lizenz
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityCmaintenanceA Model Context Protocol server that facilitates integration with OpenCTI, allowing users to query and retrieve cyber threat intelligence data via a standardized interface.1640MIT
- AlicenseNot gradedqualityDmaintenanceA comprehensive implementation of Model Context Protocol servers enabling natural language interactions with security platforms including Splunk SIEM, CrowdStrike EDR, and Microsoft MISP for threat intelligence querying and analysis.4422MIT
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that integrates TAK Server with AI systems, providing geospatial-aware tools for querying, analyzing, and interacting with tactical data.10MIT
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that connects AI assistants to MISP threat intelligence platforms. It enables threat intelligence search, IOC lookup, and event analysis through natural conversation.
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
A Model Context Protocol server for Wix AI tools
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DarkAngel-agents/opencti-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server