Enables checking IP addresses against the GreyNoise API to determine if they are internet background noise, known benign services, or potentially targeted threats.
MCP server for GreyNoise threat intelligence, enabling IP analysis, GNQL queries, tag and vulnerability lookups, and session/pcap retrieval via natural language.
Enables real-time scanning of URLs for malicious content, spam/gray classification, and additional security flags like domain age through the Malicious Scanner API.
Enables threat intelligence for SOC and DFIR workflows, including IOC enrichment, CVE and threat actor lookup, domain scanning, and account-based scan management.
Enables IP address lookups and risk assessments for IPv4/IPv6, providing geolocation, ISP/ASN, and security flags such as VPN, proxy, Tor, datacenter, and mobile with a risk score.
Provides real-time threat intelligence including IP risk scores, CVE lookups, and malware hash analysis without requiring an API key. It enables users to monitor active threats, predict CISA KEV additions, and detect pre-attack infrastructure staging through natural language.