Best abuse.ch MCP Servers
Abuse.ch is a research project that tracks and monitors malware, botnets, and other cyber threats. It provides various tools and resources to help security professionals identify and combat online abuse, including databases of malicious URLs, compromised websites, and command-and-control servers.
Why this server?
Integrates AbuseIPDB and URLhaus threat intelligence for IP reputation checks and PCAP-wide threat scanning.
AlicenseBqualityCmaintenanceA professional-grade network analysis MCP server that integrates Wireshark/TShark, Nmap, and threat intelligence to enable packet capture, network scanning, threat detection, and credential extraction through natural language.Last updated412MITWhy this server?
Integrates with URLhaus (abuse.ch) to check URLs against active malware distribution lists.
AlicenseAqualityAmaintenanceEnables AI agents to check URL safety before fetching content, using Google Web Risk, URLhaus, PhishTank, and AI analysis to return SAFE/SUSPICIOUS/DANGEROUS verdicts.Last updated164MITWhy this server?
Provides unified access to abuse.ch projects including URLhaus for malware distribution URLs, MalwareBazaar for sample lookups by hash, ThreatFox for IOC sharing, and Feodo Tracker for identifying active botnet C2 infrastructure.
AlicenseAqualityBmaintenanceProvides unified access to multiple threat intelligence sources like AlienVault OTX, AbuseIPDB, and GreyNoise for security research and analysis. It enables users to perform simultaneous lookups on IPs, domains, hashes, and URLs across several platforms within a single response.Last updated7926MITWhy this server?
Enables AI agents to query abuse.ch services such as ThreatFox for malware IOCs, URLhaus for malicious URLs, and other threat intelligence feeds.
AlicenseAqualityAmaintenanceDark web & threat intelligence for AI agents. HIBP, ThreatFox, ransomware tracking, Tor .onion access, blockchain intel, exploit search, stealer logs, malware analysis — unified into a single MCP server.Last updated664MITWhy this server?
Integrates with MalwareBazaar to provide real-time threat intelligence, sample metadata, and file downloads for cybersecurity research.
Alicense-qualityCmaintenanceAn AI-driven MCP server that autonomously interfaces with Malware Bazaar, delivering real-time threat intel and sample metadata for authorized cybersecurity research workflows.Last updated30Apache 2.0Why this server?
Provides tools for searching and retrieving malware samples from the MalwareBazaar database, allowing queries by tag, family, signature, or recent samples.
Alicense-qualityCmaintenanceEnables querying the abuse.ch MalwareBazaar database for malware samples by tag, family, signature, or recent submissions.Last updated6MITWhy this server?
Integrates with URLhaus (abuse.ch) for threat intelligence, enabling batch IP threat scanning and stream correlation against known malware URLs.
Alicense-qualityDmaintenanceAn MCP server for offline network forensic analysis and threat intelligence, enabling LLMs to analyze PCAP files, extract streams, detect threats, and identify credentials using tshark.Last updated6MITWhy this server?
Provides a unified API layer for querying threat intelligence from multiple abuse.ch platforms including MalwareBazaar, URLhaus, and ThreatFox, enabling comprehensive reports on files, URLs, IPs, and domains for cybersecurity analysis.
Alicense-qualityDmaintenanceEnables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.Last updated2MITWhy this server?
Provides tools for querying the ThreatFox indicator-of-compromise feed from abuse.ch, allowing AI agents to search IOCs by file hash or malware family.
Alicense-qualityCmaintenanceEnables searching for indicators of compromise from ThreatFox by file hash (MD5/SHA1/SHA256) or malware family name.Last updated6MIT