Skip to main content
Glama
yayefa
by yayefa

Google Threat Intelligence (GTI) MCP Server

Model Context Protocol Google Cloud Run License

A production-ready Model Context Protocol (MCP) server providing comprehensive integration with Google Threat Intelligence (GTI) and VirusTotal API v3. Built with high-performance async Python, FastAPI, and MCP Streamable HTTP transport standard (/mcp), designed for deployment on Google Cloud Run and seamless interaction with Gemini Enterprise and AI Security Agents.


๐ŸŒŸ Key Features

  • Streamable HTTP Transport (/mcp): Native support for the MCP Streamable HTTP protocol specification with zero-redirect routing.

  • 22+ Threat Intelligence Tools: Direct access to Google Threat Intelligence collections, Threat Actors, Campaigns, Malware Families, Reports, File Sandbox Analyses, IP/Domain/URL telemetry, and IoC lookups.

  • Enterprise Security: Native integration with Google Cloud Secret Manager (VT_APIKEY / VT_SECRET_NAME) ensures no secrets or API keys are stored in source code.

  • Gemini Enterprise & Agent Ready: IAM-protected endpoints (roles/run.invoker) with Google Cloud identity authentication.

  • Automated Cloud Deployment: One-command build and deployment script (deploy.sh) with Google Cloud Build and Cloud Run.


Related MCP server: OSINT MCP Server

๐Ÿ› ๏ธ MCP Tool Suite

Category

Available Tools

Threat Landscape & Collections

search_threat_actors, get_threat_actor, search_campaigns, get_campaign, search_malware_families, get_malware_family, search_reports, get_threat_report

File & IoC Telemetry

get_file_report, get_file_behaviour, search_ioc, get_file_sigma_analysis, get_file_yara_rules

Network Infrastructure

get_ip_report, get_domain_report, get_url_report, get_ip_communicating_files, get_domain_communicating_files, get_ip_historical_ssl, get_domain_subdomains

Diagnostics & Health

health_check, get_server_status


๐Ÿš€ Quick Start

1. Prerequisites

  • Python 3.10+

  • Google Cloud SDK (gcloud) configured with project access

  • Valid Google Threat Intelligence / VirusTotal API Key

2. Local Setup

Clone the repository and install dependencies:

git clone https://github.com/yayefa/GTI-MCP-Server.git
cd GTI-MCP-Server

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

3. Environment Configuration

Copy the sample environment file:

cp .env.example .env

Edit .env to configure your settings:

PROJECT_ID=your-gcp-project-id
REGION=us-central1
SERVICE_NAME=mcp-gti-mcp-server
VT_SECRET_NAME=VT_APIKEY
SECRET_PROJECT_ID=your-gcp-project-id
LOG_LEVEL=INFO

4. Running Locally

uvicorn server:app --host 0.0.0.0 --port 8080 --reload

โ˜๏ธ Deployment to Google Cloud Run

1. Store API Key in Google Secret Manager

echo -n "YOUR_GTI_VT_API_KEY" | gcloud secrets create "VT_APIKEY" \
    --data-file=- \
    --project="YOUR_PROJECT_ID" \
    --replication-policy="automatic"

2. Deploy via Script

Execute the automated deployment script:

chmod +x deploy.sh
./deploy.sh

For complete deployment details and IAM configuration, see DEPLOYMENT.md.


๐Ÿงช Testing and Verification

Run the automated test client against your running instance or deployed Cloud Run service:

AUTH_TOKEN=$(gcloud auth print-identity-token) \
TARGET_URL="https://<YOUR-CLOUD-RUN-URL>" \
python3 test_client.py

Or query the MCP endpoint directly using curl:

curl -X POST https://<YOUR-CLOUD-RUN-URL>/mcp \
  -H "Authorization: Bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "get_ip_report",
      "arguments": {
        "ip_address": "8.8.8.8"
      }
    }
  }'

๐Ÿ“„ License

This project is licensed under the Apache 2.0 License - see the LICENSE file for details.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

โ€“Maintainers
โ€“Response time
โ€“Release cycle
โ€“Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.
    5
    19
    MIT
  • A
    license
    D
    quality
    D
    maintenance
    A comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.
    56
    20
    ISC
  • A
    license
    -
    quality
    A
    maintenance
    An MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    MCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.
    8
    1

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • MCP server exposing the Backtest360 engine API as tools for AI agents.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yayefa/GTI-MCP-Server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server