CyberMCP
Allows checking file hashes (MD5, SHA-1, SHA-256) against VirusTotal, returning verdict, detection ratio, file type, and threat names.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@CyberMCPcheck hash 44d88612fea8a8f36de82e1278abb02f"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CyberMCP
An MCP (Model Context Protocol) server that gives Claude cybersecurity research tools.
Tools
Tool | Source | Auth |
| NVD API | None required |
| ip-api.com | None required |
| VirusTotal API | Free API key |
cve_lookup
Look up any CVE by ID. Returns description, CVSS score, severity, vector string, and references.
Example: CVE-2021-44228 (Log4Shell)
ip_lookup
Geolocate an IPv4 or IPv6 address. Returns country, city, ISP, ASN, timezone, and proxy/VPN detection.
Example: 8.8.8.8
hash_check
Check a file hash (MD5, SHA-1, or SHA-256) against VirusTotal. Returns verdict, detection ratio, file type, and threat names.
Example: 44d88612fea8a8f36de82e1278abb02f (EICAR test file MD5)
Related MCP server: Threat Intel MCP Server
Installation
cd cybermcp
pip install -r requirements.txtSet up your VirusTotal API key:
cp .env.example .env
# Edit .env and add your VIRUSTOTAL_API_KEYGet a free VirusTotal API key at https://www.virustotal.com/gui/join-us
Running the server
python main.pyConnecting to Claude Desktop
Add the following to your claude_desktop_config.json:
{
"mcpServers": {
"cybermcp": {
"command": "python",
"args": ["/absolute/path/to/cybermcp/main.py"]
}
}
}Config file locations:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.json
Connecting to Claude Code (CLI)
claude mcp add cybermcp python /absolute/path/to/cybermcp/main.pyProject Structure
cybermcp/
├── main.py # MCP server entry point
├── tools/
│ ├── __init__.py # Exports all tools
│ ├── cve.py # NVD CVE lookup
│ ├── ip_lookup.py # ip-api.com geolocation
│ └── hash_check.py # VirusTotal hash analysis
├── .env.example # API key template
├── requirements.txt
└── README.mdThis server cannot be deployed
Maintenance
Related MCP Connectors
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
Related MCP Servers
- AlicenseBqualityNot gradedmaintenanceA unified Open Source Intelligence toolkit that integrates data sources like Censys, Shodan, and LinkedIn for comprehensive infrastructure and identity research. It enables users to perform automated email verification, vulnerability scanning, and person or company enrichment directly through Claude.22MIT
- FlicenseNot gradedqualityDmaintenanceProvides threat intelligence and vulnerability research tools by integrating with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT\&CK. It enables users to perform CVE lookups, analyze IP reputation, and retrieve detailed MITRE ATT\&CK technique information.1-
- FlicenseNot gradedqualityCmaintenanceProvides Claude with live access to multiple vulnerability databases (NVD, OSV, GitHub Advisories, Snyk) for querying CVEs, package vulnerabilities, and remediation guidance.-
- AlicenseAqualityCmaintenanceConverts Claude into a cybersecurity assistant by exposing 17 tools for network reconnaissance, cryptography, and security analysis, enabling users to perform tasks like SSL certificate checking, port scanning, and JWT analysis directly within conversations.17MIT