Threat Intel MCP Server provides a set of tools for querying multiple threat intelligence platforms like VirusTotal, Shodan, GreyNoise, and urlscan.io. It includes enrichment tools that query all providers at once for IPs, URLs, or files.
MCP-native agentic threat investigation server that investigates IOCs across multiple threat intelligence sources, correlates findings to detect campaigns, and outputs STIX 2.1 bundles.
Enables AI-driven SOC investigations by providing automated Splunk querying, threat intelligence enrichment, and response actions through natural language. Includes tools for IP pivoting, lateral movement detection, and label harvesting.
An MCP server that enables LLMs to interact with MISP for threat intelligence sharing, IOC lookups, and event management. It provides tools for investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata.