Skip to main content
Glama
jmaciasc-google

Google Threat Intelligence MCP Server

Related Servers

Alternatives to Google Threat Intelligence MCP Server

No user-submitted related servers found.

    Related Servers

    • F
      license
      B
      quality
      C
      maintenance
      Enables AI assistants to access Google's Threat Intelligence suite for file analysis, indicator of compromise searches, and reputation checking. It supports both local and cloud-based deployments for investigating campaigns, threat actors, and malware families.
      36
      4
      -
    • F
      license
      Not graded
      quality
      D
      maintenance
      Provides real-time threat intelligence for AI agents, enabling checks on IPs, domains, URLs, hashes, CVEs, prompt-injection payloads, and malicious AI-skill/MCP-tool definitions against a free database of 890K+ IOCs.
      -
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables AI assistants to query and manage OpenCTI threat intelligence data, including indicators, observables, reports, malware, and more, with read-only and optional write operations.
      MIT
    • A
      license
      A
      quality
      D
      maintenance
      Enables AI-native access to the MITRE ATT\&CK framework, allowing LLMs and agents to query techniques, threat groups, software, and generate ATT\&CK Navigator layers for threat intelligence and security workflows.
      65
      42 npm
      5
      Apache 2.0
    • A
      license
      Not graded
      quality
      B
      maintenance
      Connects AI agents with the CrowdStrike Falcon platform to programmatically access detections, threat intelligence, host management, and other security capabilities for intelligent security analysis and automation.
      1
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables AI assistants to query the DugganUSA threat-intel corpus (1.5M+ IOCs) via three read-only tools: search, enrich-ioc, and stix-feed-summary.
      52 npm
      2
      MIT

    TDQS

    B3.4/5.0

    Scored across 36 tools

    Disambiguation4/5

    Most tools have distinct purposes, e.g., searching different entity types (search_campaigns, search_malware_families) and retrieving reports (get_file_report, get_domain_report). However, search_threats can filter by collection_type, causing slight overlap with the specific search tools. Overall clear differentiation.

    Naming Consistency4/5

    Predominantly follows verb_noun pattern (e.g., create_collection, get_collection_report). Inconsistencies include 'analyse_file' (British spelling) versus American spelling used elsewhere, and verbose names like get_entities_related_to_a_collection. Still largely predictable.

    Tool Count3/5

    With 36 tools, the count is on the high side. The server covers a broad threat intelligence domain, but multiple similar tools (e.g., seven search tools, five get_entities_related_to_* tools) add redundancy. Could be streamlined without losing functionality.

    Completeness4/5

    The tool set covers CRUD operations for collections, detailed reports for various IOC types, and specialized searches. Notable gap: no tool to delete a collection entirely (only update). Digital threat monitoring and hunting rulesets are well-integrated. Minor missing features prevent a perfect score.

    Maintenance

    ActivityStale
    ResponsivenessNo issues