OpenCTI MCP Server
Servidor MCP de OpenCTI
Un servidor del Protocolo de Contexto de Modelo (MCP) para OpenCTI, la plataforma abierta de inteligencia de ciberamenazas desarrollada por Filigran.
Conecta tu asistente de IA a tu instancia de OpenCTI para realizar búsquedas de inteligencia de amenazas, consultas de indicadores, análisis de informes y supervisión de conectores mediante una conversación natural.
Herramientas
Herramienta | Descripción |
| Buscar cualquier tipo de entidad STIX (informes, malware, actores de amenazas, etc.) |
| Obtener detalles completos del informe por ID de STIX |
| Buscar IOC por valor, tipo de patrón o palabra clave |
| Crear un nuevo indicador con patrón STIX/YARA/Sigma |
| Listar todos los conectores con su estado y profundidad de cola |
Related MCP server: Security Infrastructure MCP Server
Inicio rápido
Variables de entorno
Variable | Requerido | Predeterminado | Descripción |
| Sí | — | URL de tu instancia de OpenCTI |
| Sí | — | Token de API de OpenCTI |
| No |
| Verificar certificados SSL |
| No |
| Transporte: |
| No |
| Host al que vincular (modo http) |
| No |
| Puerto al que vincular (modo http) |
Docker
git clone https://github.com/DarkAngel-agents/opencti-mcp.git
cd opencti-mcp
export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token
docker compose up -dLocal
pip install -r requirements.txt
export OPENCTI_URL=https://your-opencti-instance.com
export OPENCTI_TOKEN=your-api-token
# stdio mode
python server.py
# http mode
MCP_TRANSPORT=http python server.pyClaude Desktop
{
"mcpServers": {
"opencti": {
"command": "python",
"args": ["/path/to/opencti-mcp/server.py"],
"env": {
"OPENCTI_URL": "https://your-opencti-instance.com",
"OPENCTI_TOKEN": "your-api-token"
}
}
}
}Ejemplos de prompts
"Busca en OpenCTI actores de amenazas relacionados con APT28"
"Muéstrame los últimos informes sobre ransomware"
"Busca indicadores que coincidan con esta IP: 192.168.1.100"
"Crea un indicador STIX para el dominio evil.example.com"
"¿Qué conectores están activos y cuál es el estado de su cola?"
Proyectos relacionados
misp-mcp — Servidor MCP para MISP
nixos-anssi-bp028 — Módulo de endurecimiento NixOS ANSSI
Licencia
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityCmaintenanceA Model Context Protocol server that facilitates integration with OpenCTI, allowing users to query and retrieve cyber threat intelligence data via a standardized interface.1640MIT
- AlicenseNot gradedqualityDmaintenanceA comprehensive implementation of Model Context Protocol servers enabling natural language interactions with security platforms including Splunk SIEM, CrowdStrike EDR, and Microsoft MISP for threat intelligence querying and analysis.4422MIT
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that integrates TAK Server with AI systems, providing geospatial-aware tools for querying, analyzing, and interacting with tactical data.10MIT
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that connects AI assistants to MISP threat intelligence platforms. It enables threat intelligence search, IOC lookup, and event analysis through natural conversation.
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
A Model Context Protocol server for Wix AI tools
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DarkAngel-agents/opencti-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server