Skip to main content
Glama
abdulbrown

ransomware-live-mcp

by abdulbrown

Related Servers

Alternatives to ransomware-live-mcp

No user-submitted related servers found.

    Related Servers

    • F
      license
      Not graded
      quality
      D
      maintenance
      Enables comprehensive ransomware threat analysis through 25+ tools that interact with ransomware.live API. Provides real-time data on ransomware groups, victims, negotiations, IOCs, and attack trends for cybersecurity investigation and monitoring.
      -
    • F
      license
      A
      quality
      B
      maintenance
      Exposes eSentire Atlas API (Findings, Ticketing, MVS) and Threat Intelligence feeds (IP Watch, Advanced/STIX) as MCP tools, enabling security operations and threat intelligence queries through natural language.
      29
      -
    • A
      license
      B
      quality
      D
      maintenance
      Unified dark web and threat intelligence MCP server providing 66 tools across 16 data sources, including breach databases, ransomware tracking, Tor .onion access, blockchain intel, and malware analysis for AI agents.
      66
      186 npm
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      Provides threat intelligence tools like IoC lookups, event backtracking, and IP enrichment via MCP, enabling automated triage and evidence queries.
      1
      -
    • A
      license
      A
      quality
      B
      maintenance
      MCP server for Threadlinqs Intelligence — 49 tools across threat intelligence, detections, IOCs, threat actors, MITRE attack-chains, C2 infrastructure, and Purple-tier composite intelligence. Drop-in for Claude Code, Claude Desktop, Cursor, and any MCP-compatible client.
      81
      86 npm
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      A collection of MCP tools for cybersecurity threat intelligence and local network hacking, integrating APIs like GreyNoise, Malpedia, OpenCTI, and more.
      9
      BSD 2-Clause "Simplified"

    TDQS

    A4.1/5.0

    Scored across 25 tools

    Disambiguation4/5

    Each tool targets a distinct resource and action, with clear list/get navigation pairs for victims, IOCs, YARA rules, ransom notes, and negotiations. A couple of names are near-permutations (list_ransomnote_groups vs list_group_ransomnotes; list_negotiation_groups vs list_group_negotiations), so an agent could misselect without reading the descriptions.

    Naming Consistency4/5

    All tool names are verb-first snake_case (validate, get, list, search, filter, build, decode), giving a predictable overall style. Minor deviations include 'id' vs 'identifier' between build_victim_id and decode_victim_identifier, and the swapped noun order in the list_<type>_groups / list_group_<type> pairs.

    Tool Count4/5

    25 tools is at the heavy end, but the server spans many distinct intelligence domains (victims, groups, IOCs, YARA, ransom notes, negotiations, press, SEC filings, CSIRT contacts), so the count is justified. It feels slightly over-packed rather than redundant.

    Completeness5/5

    The tool surface gives complete read-only coverage of the exposed domain: every artifact type has listing plus retrieval, with navigation helpers (build/decode victim ID, sector/group enumerations) that avoid dead ends. Since this is an intelligence/retrieval API, write operations are not an expected part of the lifecycle.

    Maintenance

    ActivityMaintained
    ResponsivenessNo issues