Abuse.ch Threat Intelligence MCP Server
Provides a unified API layer for querying threat intelligence from multiple abuse.ch platforms including MalwareBazaar, URLhaus, and ThreatFox, enabling comprehensive reports on files, URLs, IPs, and domains for cybersecurity analysis.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Abuse.ch Threat Intelligence MCP Servercheck if 8.8.8.8 is malicious"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
abusech-mcp 🚦
abusech-mcp is an MCP server that fetches threat intelligence from multiple abuse.ch platforms, including MalwareBazaar, URLhaus, and ThreatFox.
Features
Unified VT-like API for querying file, URL, IP, and domain intelligence
Uses Pydantic schemas for robust data validation and serialization
Powered by fastmcp:
Unified API layer: Directly use functions from
abusech_intel.pyto obtain correlated intelligence from abuse.ch platforms—serving as a unified API layer since the platforms themselves do not provide one
Related MCP server: FastMCP ThreatIntel
Requirements
Python 3.10+
abuse.ch API key (set as
ABUSECH_API_KEYenvironment variable)
Usage
Start the MCP server:
python abusech_mcp.pyAvailable Tools
get_ip_report(ip: str): Get a comprehensive IP report from URLhaus and ThreatFoxget_domain_report(domain: str): Get a domain report from URLhaus and ThreatFoxget_url_report(url: str): Get a URL report from URLhaus and ThreatFoxget_file_report(hash_value: str): Get a file report (MD5/SHA-1/SHA-256) from MalwareBazaar, URLhaus, and ThreatFox
Configuration
Set your API key as an environment variable:
export ABUSECH_API_KEY=your_api_key_hereLicense
MIT License
This server cannot be deployed
Maintenance
Related MCP Connectors
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
Related MCP Servers
- AlicenseAqualityAmaintenanceAggregates real-time threat intelligence from multiple sources including Feodo Tracker, URLhaus, CISA KEV, and ThreatFox, with IP/hash reputation checking via VirusTotal, AbuseIPDB, and Shodan for comprehensive security monitoring.11636MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI-powered threat intelligence analysis of IPs, domains, URLs, and file hashes across multiple threat intelligence platforms (VirusTotal, AlienVault OTX, AbuseIPDB, IPinfo) with APT attribution and interactive reporting through natural language queries.10 PyPI39Apache 2.0
- AlicenseAqualityCmaintenanceProvides unified access to multiple threat intelligence sources like AlienVault OTX, AbuseIPDB, and GreyNoise for security research and analysis. It enables users to perform simultaneous lookups on IPs, domains, hashes, and URLs across several platforms within a single response.750 npm7MIT
- FlicenseNot gradedqualityDmaintenanceProvides threat intelligence and vulnerability research tools by integrating with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT\&CK. It enables users to perform CVE lookups, analyze IP reputation, and retrieve detailed MITRE ATT\&CK technique information.1-