Skip to main content
Glama
aplaceforallmystuff

MCP Threat Intel Server

Related Servers

Alternatives to MCP Threat Intel Server

No user-submitted related servers found.

    Related Servers

    • F
      license
      Not graded
      quality
      C
      maintenance
      Provides a unified interface for security analysts to gather threat intelligence from multiple sources including VirusTotal, Shodan, NVD, AnyRun, AlienVault OTX, and GitHub.
      2 npm
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      Enables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.
      3
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables AI-powered threat intelligence analysis of IPs, domains, URLs, and file hashes across multiple threat intelligence platforms (VirusTotal, AlienVault OTX, AbuseIPDB, IPinfo) with APT attribution and interactive reporting through natural language queries.
      17 PyPI
      39
      Apache 2.0
    • A
      license
      A
      quality
      A
      maintenance
      Aggregates real-time threat intelligence from multiple sources including Feodo Tracker, URLhaus, CISA KEV, and ThreatFox, with IP/hash reputation checking via VirusTotal, AbuseIPDB, and Shodan for comprehensive security monitoring.
      11
      645
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      Provides threat intelligence and vulnerability research tools by integrating with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT\&CK. It enables users to perform CVE lookups, analyze IP reputation, and retrieve detailed MITRE ATT\&CK technique information.
      1
      -

    TDQS

    A3.6/5.0

    Scored across 7 tools

    Disambiguation5/5

    Each tool targets a distinct IOC type or source: feodo_tracker for botnet C2s, greynoise_ip for noise classification, and threatintel_lookup_* for domain, hash, IP, and URL lookups. There is no confusion about which tool to use for a given input type.

    Naming Consistency3/5

    Most tools follow a 'threatintel_lookup_<type>' pattern, but 'feodo_tracker' and 'greynoise_ip' break this convention, creating a mix of styles. The naming is not fully predictable.

    Tool Count5/5

    With 7 tools, the server covers the core threat intelligence operations without being bloated. The count feels well-scoped for the domain.

    Completeness3/5

    The set covers common IOC types (IP, domain, hash, URL) but has redundancy: feodo_tracker and greynoise_ip overlap with the combined threatintel_lookup_ip. Missing IOC types like email or CVE, and no write/update operations, though acceptable for a lookup service.

    Maintenance

    ActivitySlowing
    ResponsivenessNo issues