Skip to main content
Glama
GreyNoise-Intelligence

greynoise-mcp-server

Official

Related Servers

Alternatives to greynoise-mcp-server

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      A
      maintenance
      An MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.
      1
      MIT
    • A
      license
      D
      quality
      D
      maintenance
      A comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.
      56
      52 npm
      ISC
    • A
      license
      Not graded
      quality
      C
      maintenance
      An MCP server for Tenable Vulnerability Management and the Tenable One platform, enabling LLMs to query assets, vulnerabilities, scans, exposure metrics, attack paths, and more via natural language.
      MIT
    • A
      license
      A
      quality
      A
      maintenance
      An MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.
      5
      21 PyPI
      19
      MIT
    • A
      license
      B
      quality
      C
      maintenance
      A professional-grade network analysis MCP server that integrates Wireshark/TShark, Nmap, and threat intelligence to enable packet capture, network scanning, threat detection, and credential extraction through natural language.
      41
      2
      MIT
    • A
      license
      A
      quality
      B
      maintenance
      MCP server for offensive-security tooling, enabling AI agents to run reconnaissance, CVE intelligence, JavaScript analysis, HTTP probing, and port scanning against authorized targets.
      10
      MIT

    TDQS

    A3.5/5.0

    Scored across 46 tools

    Disambiguation3/5

    Most tools map to clear resource/action pairs, but several close clusters create misselection risk: gnql-query vs gnql-metadata-query, export-session-data vs get-session-pcap, and session-unique-values vs session-counts all overlap in purpose. The descriptions help, but with 46 tools an agent has a real chance of picking the wrong one in these ambiguous areas.

    Naming Consistency3/5

    The majority of tools use readable snake_case verb_noun names like list-blocklists and create-alert, but the pattern is not consistent. Several tools are noun-first or use different action styles, such as callback-overview, bsi-lookup, session-unique-values, quick-check-ip, and gnql-stats, making the naming scheme predictable only in parts.

    Tool Count2/5

    46 tools is a very large surface, well beyond the 25+ threshold where agent selection burden becomes significant. While the server covers many GreyNoise API domains, the sheer number of near-sibling tools makes this feel over-scoped for a single MCP server.

    Completeness5/5

    The tool surface is remarkably comprehensive: full CRUD/lifecycle for alerts and blocklists, session search/aggregation/export, GNQL query/stats/timeseries, single and bulk IP lookups, callback and BSI analytics, plus tag and CVE intelligence. There are no obvious dead ends or critical missing operations for the apparent domain.

    Maintenance

    ActivityStale
    ResponsivenessNo issues