mcp-greynoise
Related Servers
Alternatives to mcp-greynoise
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityBmaintenanceEnables classification of internet scanners using GreyNoise data, helping identify benign or malicious scans through the free community tier.1 npmMIT
- AlicenseAqualityAmaintenanceMCP server for GreyNoise threat intelligence, enabling IP analysis, GNQL queries, tag and vulnerability lookups, and session/pcap retrieval via natural language.48126 npm5MIT
- AlicenseNot gradedqualityBmaintenanceEnables IP address lookups and risk assessments for IPv4/IPv6, providing geolocation, ISP/ASN, and security flags such as VPN, proxy, Tor, datacenter, and mobile with a risk score.184 npmMIT
- AlicenseAqualityDmaintenanceProvides threat intelligence lookups against the AbuseIPDB database, enabling IP reputation checks, CIDR block analysis, and log enrichment. It features intelligent caching and rate limiting to efficiently manage API usage for security analysis and automated workflows.5MIT
- AlicenseNot gradedqualityBmaintenanceEnables file, URL, domain, and IP reputation checks via VirusTotal API using the Pipeworx gateway.202 npmMIT
- AlicenseNot gradedqualityDmaintenanceProvides comprehensive IP and domain security intelligence, enabling analysis of IP addresses and domains for threat and reputation information.MIT
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one checks a single IP address, the other checks multiple IPs in bulk. An agent can easily distinguish between them based on the singular/plural naming and the explicit descriptions.
Both tools follow the consistent pattern of 'check_' followed by a noun indicating the input type ('ip' vs 'ips'). The naming is predictable and uses consistent snake_case throughout.
With only two tools, the server feels minimal for its domain. While both tools are necessary and well-scoped, a more comprehensive IP intelligence server would typically benefit from additional tools (e.g., contextual enrichment, history). The count is borderline thin.
The tool set covers the basic use case of checking IPs against GreyNoise data, both individually and in bulk. However, it lacks other common operations like fetching detailed threat context, searching by tags or queries, or retrieving known-good RIOT entries specifically. Notable gaps exist for a more complete threat intelligence surface.