misp-mcp
This server connects to a MISP (Malware Information Sharing Platform) instance, enabling you to query threat intelligence, investigate indicators, explore the knowledge base, and submit new indicators — all in plain language through any MCP-compatible client. It exposes 18 tools across the following areas:
Indicator Lookups
misp_lookup_ioc: Search MISP for sightings of a single IPv4/IPv6, domain, URL, or hash (defanged forms accepted). Returns a verdict with event hits, threat level, and detection-flag status.misp_lookup_iocs: Batch triage up to 20 indicators in one call with a compact per-IOC summary.misp_correlate_ioc: Pivot from an IOC to find other indicators appearing in the same MISP event(s) — useful for discovering related infrastructure.
Event Investigation
misp_get_event: Fetch full details of a MISP event by ID (metadata, tags, attributes).misp_search_events: Search events by title keyword, tag, and/or date range.
Attribute & Object Access
misp_get_attribute: Fetch a single attribute by ID along with its parent event.misp_get_object: Retrieve a MISP object (group of related attributes) by ID.misp_search_attributes: Search attributes by type, category, tag,to_idsstatus, or event ID.
Threat Intelligence Knowledge Base
misp_lookup_galaxy: Look up threat actors, malware families, tools, and ATT&CK techniques by name or synonym.misp_list_galaxies: List all galaxy types available on the instance.misp_list_taxonomies: View all taxonomies (TLP, kill-chain, PAP, etc.) and their enabled status.misp_get_taxonomy: Retrieve a specific taxonomy's tags and their meanings.misp_search_tags: Find tag definitions by name.
Feed & Instance Monitoring
misp_feed_stats: See feed counts and which are enabled.misp_instance_status: Verify connectivity, authentication, and retrieve MISP/server versions.
Audit & Review
misp_review_submissions: Audit recent IOC submissions — what was added, by whom, when, and which are detection-flagged.
Indicator Submission (requires write-capable API key)
misp_submit_ioc: Add a single, fully attributed indicator with required fields (reporter, justification, last-seen date, tags, detection flag). Guardrails block private/reserved IPs and first-party infrastructure.misp_submit_iocs: Bulk validate and add up to 50 indicators; defaults todry_run=trueso you can preview before committing.
All operations automatically clean defanged indicators (e.g., hxxp://evil[.]com, 1.2.3[.]4), and write operations enforce rate limiting and security guardrails.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@misp-mcplook up 102.130.113.9 in MISP"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
misp-mcp connects MISP to any MCP client (Claude Desktop, Claude Code, Cursor, and others). You ask in plain language, the client calls MISP, you get the answer. No MISP UI, no REST calls by hand.
It exposes 21 tools: 19 read (indicators, events, feeds, the galaxy /
taxonomy / tag knowledge base, warninglist checks, worker/job health) and 2
gated write (add indicators, single + bulk); a 22nd optional enrichment bridge
registers only when TI_LOOKUP_URL is set. Every
call runs under your own MISP key - the server holds no credential of its
own.
How it works
flowchart LR
C["MCP client<br/>Claude · Cursor · any"] -->|"X-MISP-Key: your key"| S["misp-mcp<br/>stdio or HTTP"]
S -->|"read (19 tools)"| M[("your MISP")]
S -->|"write (2 tools, gated)"| M
S -. "optional (TI_LOOKUP_URL)" .-> E["enrichment service"]
M -. "authorizes + attributes<br/>every call to you" .-> SYour key is the credential. It rides in a header; MISP validates it on the real call and attributes the query to you. No shared account.
Read by default, writes gated. A read-only key can look things up; adding indicators needs a write-capable key (held by the security team).
Enrichment is optional. Set
TI_LOOKUP_URLto bridge to a MISP-first enrichment service; unset, the tool stays hidden and this is a pure MISP client.
Related MCP server: MISP MCP Server
Get started
Two ways to use it. If you have your own MISP, run it locally (below). If your org already hosts misp-mcp, skip to Connect to a hosted server.
Run it locally
Your MCP client launches misp-mcp as a local process (stdio) that talks to your own MISP with your key. One user (you), nothing to host.
flowchart LR
A["Your MCP client<br/>Claude Desktop/Code · Cursor"] -->|"launches (stdio)"| B["misp-mcp<br/>your key in env"]
B -->|"HTTPS"| M[("your MISP")]Where's your MISP?
MISP_URLis your MISP's address, wherever it runs - a local Docker instance (https://localhost), one on your network (https://misp.lan), or a cloud-hosted one (https://misp.yourco.com). Only the URL changes. For a local or self-signed instance, also setMISP_VERIFY_TLS=false. misp-mcp just needs to be able to reach that URL - join your VPN first if the MISP is private.
Install it from source:
git clone https://github.com/indranilroy99/misp-mcp.git cd misp-mcp ./install.shinstall.shchecks your environment, installs themisp-mcpbinary, and can auto-write your client config. Manual steps are in ONBOARDING.md.Point your client at it. Add a stdio server with two env vars -
MISP_URLand yourMISP_API_KEY. Claude Code, one command:claude mcp add misp --scope user \ -e MISP_URL=https://misp.example.com \ -e MISP_API_KEY=YOUR_KEY_HERE \ -- misp-mcpOther clients: add an
mcpServersentry running themisp-mcpcommand with those two env vars, then fully restart the app.Try it. Ask your assistant "Is MISP healthy?" or "Look up 8.8.8.8 in MISP." If it answers from MISP, you're set.
Prefer Docker or a team deployment? See Host it for a team.
Connect to a hosted server
If your org runs misp-mcp behind a URL, there's nothing to install - point your client at it with your own key. You must be on the network / VPN that can reach it.
Get your MISP key (one time): open MISP → My Profile → Auth Keys → Add authentication key, comment it
misp-mcp <your-name>, copy it (shown once). A read-only key is enough for lookups. Keep it private - every query runs as you.Add the server - any MCP client that speaks streamable HTTP with custom headers works. It needs three things: transport
http, the URL, and two headers.{ "mcpServers": { "misp": { "type": "http", "url": "https://misp.example.com/mcp", "headers": { "X-MISP-Key": "YOUR_KEY_HERE", "X-MISP-User": "you@example.com" } } } }Check it works: this should print
401(endpoint reachable, auth required):curl -s -o /dev/null -w '%{http_code}\n' -X POST https://misp.example.com/mcp
Claude Code (one terminal command):
claude mcp add --transport http misp https://misp.example.com/mcp \
--scope user \
--header "X-MISP-Key: YOUR_KEY_HERE" \
--header "X-MISP-User: you@example.com"Claude Desktop / Cursor / Windsurf - add the mcpServers block above to the
client's MCP JSON config, then fully restart the app.
VS Code (Copilot MCP) - in .vscode/mcp.json or user settings, under
"servers", use the same type/url/headers shape.
Cline / Continue / Zed / Goose and others - same URL, http transport, and
the two X-MISP-* headers, in whatever config format the client uses. Any
client that cannot send custom HTTP headers is not supported (the key must ride
in X-MISP-Key).
MCP clients cache the tool list at connect time. If tools are wrong or the
server was updated, fully quit and reopen the app (an in-app reconnect or a
new chat is often not enough). Still stale: remove the misp server, save,
reopen, add it back, reopen again.
Claude Code:
claude mcp remove misp
# then re-add (see above) and fully restart Claude CodeWhat you can ask
"Look up 102.130.113.9 in MISP."
"Triage these 30 IOCs from the report."
"What else showed up in the same event as evil[.]com?"
"Review the last 30 days of IOC submissions - who added what."
"Is MISP healthy? How many feeds are on?"Paste indicators however you have them - defanged forms (1.2.3[.]4,
hxxp://evil[.]com) are cleaned up automatically; private/reserved IPs are
rejected. Behind the scenes a tool returns structured JSON, e.g. a lookup:
{
"ioc": "102.130.113.9", "ioc_type": "ipv4", "total_hits": 6,
"summary": { "seen_in_misp": true, "detection_flagged": true,
"max_threat_level": "Medium", "restricted_hits": 0 },
"hits": [ { "event_id": "16989", "event_info": "Tor exit nodes feed",
"value": "102.130.113.9", "to_ids": true, "restricted": false } ]
}Tools
Tool | What it does | |
| read | Sightings of one IPv4/IPv6, domain, URL, or hash, with a verdict |
| read | Triage many indicators in one call |
| read | Other indicators in the same event, for pivoting |
| read | One event: info, tags, attributes |
| read | Search events by title, tag, or date |
| read | How many feeds exist and which are on |
| read | Reachability + auth check; run first when a tool fails |
| read | Audit recent submissions: what was added, by whom |
| read | Threat actors, malware, tools, ATT&CK techniques by name or synonym |
| read | Galaxy types available on the instance |
| read | Taxonomies (TLP, kill-chain, PAP) and whether each is enabled |
| read | One taxonomy's tags and their meanings |
| read | Find tag definitions by name |
| read | One MISP object (grouped attributes, e.g. a file object) |
| read | One attribute by id, with its event |
| read | Search attributes by type, category, tag, to_ids, or event (paginated) |
| read | Flag IOCs that hit known-good / noise lists (false-positive control) |
| read | Background worker / queue health (admin key) |
| read | Recent background jobs + failures and why (admin key) |
| write | Add a new indicator (needs a write-capable key) |
| write | Bulk: validate + add many indicators (dry-run preview first) |
| enrich | Optional: combined verdict via a MISP-first enrichment service ( |
Security
Your key is the authorization. MISP checks it on every call and attributes the action to you. A read-only key cannot write; only write-capable keys can add indicators.
Guarded write path. Submissions are rate-limited, well-known / first-party infrastructure can never be submitted (anti-poisoning safelist), and the submitter is read from MISP itself, not a value the caller sets.
Fail-closed TLP. With server-side redaction on, an event whose tags can't be read is treated as restricted, never revealed.
Keys stay private. No shared key on the server; the key rides in a header over TLS. Logs never contain keys or IOC values.
Report a vulnerability privately: SECURITY.md.
Host it for a team
Run misp-mcp as an HTTP server so a whole team can use it, each with their own
MISP key. It holds no credential - every request carries the caller's
X-MISP-Key, which MISP validates and attributes.
flowchart LR
U1["Analyst A"] --> LB
U2["Analyst B"] --> LB
LB["TLS proxy / load balancer<br/>ingress: your VPN CIDRs only"] -->|"HTTP :8080 (private)"| S["misp-mcp (HTTP)<br/>no stored key"]
S -->|"HTTPS"| M[("your MISP")]Run it somewhere that can reach your MISP - the same VPC/network if your MISP is
cloud-hosted or private, or alongside it (set MISP_URL to its address, as
above). TLS terminates at the load balancer; misp-mcp serves plain HTTP on
:8080 behind it (or give the process its own cert). Keep ingress scoped to
your caller networks - the endpoint is not public. Pick a path:
Path | Use it for | Guide |
Docker | Fastest single host | see below |
Self-host (VM + systemd) | A team, your own box | |
Cloud (AWS / GCP / Azure) | Any provider, hand steps | |
AWS Terraform | One |
Docker (bind stays on localhost; front it with your own TLS proxy for remote use - the key is a bearer credential):
docker run -d -p 127.0.0.1:8080:8080 \
-e MCP_TRANSPORT=http -e MCP_HOST=0.0.0.0 \
-e MISP_URL=https://misp.example.com \
-e MISP_MCP_ALLOW_INSECURE_BIND=true \
ghcr.io/indranilroy99/misp-mcp:latest
# or: MISP_URL=https://misp.example.com docker compose up -dThe Terraform modules ship two flavors sharing one networking module: Fargate (serverless, no VM) or EC2 (managed VM, SSM access), each behind an internal ALB with TLS.
Setting | Mode | Default | Meaning |
| both | required | MISP base URL |
| local | required | your key (local/stdio mode) |
| both |
|
|
| hosted |
| bind address |
| hosted |
| port |
| both |
| set |
| both |
|
|
| both | required for writes | event that |
| both | empty | your own domains that can never be submitted |
| both |
| max submissions per key per minute |
| both | random | HMAC secret for the internal key-id (rate-limit/log). Set it to keep ids stable across restarts/replicas; unset uses a per-process random secret |
| hosted | none | serve HTTPS directly |
| hosted |
| allow a public plain-HTTP bind (TLS on a proxy) |
| both | unset | optional enrichment endpoint (enables |
| both |
| seconds to wait on the enrichment endpoint (floor 5) |
python3 -m venv .venv
.venv/bin/pip install -e '.[dev]'
.venv/bin/python -m pytest tests/ -q # full suite, fully offlinemisp_mcp/
server.py the tools and the MCP server
client.py talks to the MISP REST API (read + write)
config.py reads settings from the environment
http_app.py hosted mode: header auth + web server
context.py carries your identity through one request
validators.py cleans, checks, and safelists indicatorsDependencies are pinned in pyproject.toml: mcp, httpx, pydantic,
uvicorn, starlette. Licensed under Apache-2.0 (LICENSE).
Contributions welcome - see CONTRIBUTING.md.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceAn MCP server that enables LLMs to interact with MISP for threat intelligence sharing, IOC lookups, and event management. It provides tools for investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata.36312MIT
- Flicense-qualityDmaintenanceA Model Context Protocol server that connects AI assistants to MISP threat intelligence platforms. It enables threat intelligence search, IOC lookup, and event analysis through natural conversation.
- Flicense-qualityDmaintenanceA Model Context Protocol server that connects AI assistants to OpenCTI threat intelligence platforms. It enables natural language interaction for searching threat intelligence, analyzing reports, managing indicators, and monitoring connectors.
- Flicense-qualityCmaintenanceThis MCP server connects Claude Desktop to OpenCTI for AI-augmented threat intelligence analysis, enabling natural language queries and instant, contextualized answers from your threat intelligence database.29
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Self-hosted MCP gateway: turn any API, database or MCP server into AI connectors — no code.
Official Microsoft MCP Server to query Microsoft Entra data using natural language
Appeared in Searches
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/indranilroy99/misp-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server