MISP MCP Server
Officialby MISP
README.md
# MISP MCP Server
An [MCP](https://modelcontextprotocol.io) server that provides read-only access to [MISP](https://www.misp-project.org/) threat intelligence data.
## Features
- **Event search** - Find threat intelligence events by IOC values, tags, dates, organisations
- **Attribute search** - Search individual indicators of compromise across all events
- **Object search** - Find grouped attributes (file objects, network connections, etc.)
- **Event index** - Lightweight event metadata browsing
- **Tags & Taxonomies** - Search tags and browse taxonomy vocabularies (TLP, kill chain, etc.)
- **Galaxies** - Search threat actors, malware, ATT&CK techniques, and other knowledge bases
- **Feeds** - Browse configured threat intelligence feeds
All access is **read-only** - no data modification is possible through this server.
## Installation
```bash
pip install misp-mcp
```
Or install from source:
```bash
cd misp-mcp
pip install -e .
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
| `MISP_URL` | Yes | URL of your MISP instance (e.g. `https://misp.example.com`) |
| `MISP_API_KEY` | Yes | Your MISP API authentication key |
| `MISP_VERIFYCERT` | No | Verify TLS certificates (default: `true`) |
## Usage
### Claude Desktop / Claude Code
Add to your MCP configuration:
```json
{
"mcpServers": {
"misp": {
"command": "misp-mcp",
"env": {
"MISP_URL": "https://misp.example.com",
"MISP_API_KEY": "your-api-key-here"
}
}
}
}
```
### Standalone (stdio)
```bash
export MISP_URL="https://misp.example.com"
export MISP_API_KEY="your-api-key"
misp-mcp
```
## Available Tools
### Events & Attributes
- `search_events` - Search events by IOC values, tags, dates, organisations
- `search_attributes` - Search individual attributes/indicators
- `search_objects` - Search MISP objects
- `search_event_index` - Lightweight event metadata search
- `get_event` - Get full event by ID
- `get_attribute` - Get attribute by ID
- `get_object` - Get object by ID
### Tags & Taxonomies
- `search_tags` - Search tags by name
- `list_taxonomies` - List all taxonomy vocabularies
- `get_taxonomy` - Get taxonomy details and entries
### Galaxies
- `search_galaxies` - Search galaxies (threat actors, malware, ATT&CK, etc.)
- `get_galaxy` - Get galaxy with clusters
- `search_galaxy_clusters` - Search within a specific galaxy
### Feeds
- `search_feeds` - Search/list configured threat intelligence feeds
## License
AGPL-3.0-or-later - same as MISP.
Copyright (C) 2026 Andras Iklody
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues