ThreatWeaver
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ThreatWeaverinvestigate IP 185.220.101.29 across multiple sources"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ThreatWeaver
MCP-native agentic threat investigation server. Investigate IOCs across multiple threat intelligence sources, correlate findings to detect campaigns, and output STIX 2.1 bundles - all from within Claude.
Problem
Security analysts investigating indicators of compromise manually toggle between VirusTotal, AbuseIPDB, URLhaus, Shodan, and other tools. Each query is separate, context switches are frequent, and coordinated threat patterns - where multiple indicators share infrastructure or registrants - remain invisible because single-source analysis cannot detect campaigns spanning multiple IOCs.
Related MCP server: Cyberbro MCP Server
Solution
ThreatWeaver is an MCP server that enables Claude to investigate indicators of compromise as a coherent workflow. It queries multiple threat intelligence sources in parallel, maintains investigation context across tool calls, correlates findings to detect threat campaigns, and outputs STIX 2.1 threat intelligence bundles for SOC tools.
The key insight: MCP's resource and prompt capabilities enable persistent, agentic investigation workflows that REST APIs cannot support.
Why MCP?
ThreatWeaver's value depends on three capabilities that REST APIs lack:
Persistent investigation context - MCP Resources expose investigation state that Claude reads directly, enabling natural follow up questions ("Which of these IPs are in the same ASN?") without re-prompting
Agentic reasoning - Claude reasons about multi source findings and decides what to investigate next without explicit prompting
Correlated state - Correlation across investigation history requires persistent state that only MCP provides
A traditional REST API would require separate endpoints for each step and manual context management. MCP enables the investigation itself to be the interface.
Why NitroStack?
NitroStack provides the decorator based MCP primitives and dependency injection that make this architecture possible:
@Tooldecorators for the five investigation tools@Resourcedecorators for investigation context and threat feeds@Promptfor guiding Claude's reasoning@Injectableand module system for clean service separationValidation via Zod schemas
Error handling infrastructure
Single command deployment to NitroCloud
Architecture
Claude Desktop ThreatWeaver MCP Server
| |
+---> investigate_indicator -------> ThreatIntelClient
| (VT, AbuseIPDB, |
| URLhaus, Shodan) CacheManager
| |
+---> suggest_next_steps --------> InvestigationService
| |
+---> correlate_investigations ---> CorrelationEngine
| |
+---> generate_report -----------> ReportGenerator
| |
+---> Resources -----------------> InvestigationStore (SQLite)
|
Fallback Data (offline)Core Features
Multi-source enrichment - Queries VirusTotal, AbuseIPDB, URLhaus, Shodan in parallel with automatic fallback on failure
Threat correlation - Detects campaigns by identifying shared ASNs, registrants, malware families, and geographic proximity across investigation history
STIX 2.1 output - Generates threat intelligence bundles consumable by Splunk, Elastic, Sentinel, and other SIEMs
Investigation graph - Interactive visualization of IOC relationships and verdict status
Batch investigation - Enrich multiple IOCs with progress streaming
Offline mode - Works without API keys using pre-loaded fallback datasets
Two-layer cache - In-memory LRU with configurable TTL backed by SQLite for persistence
Investigation persistence - SQLite stores all findings, correlation edges, and investigation context
Threat Correlation
This is ThreatWeaver's core differentiator. When you investigate multiple IOCs, the correlation engine compares every pair and detects shared attributes:
Relation | Confidence | Detection Method |
IP hosts domain | 1.0 | Shodan hostname resolution |
Shared ASN | 0.90 | Autonomous System Number match |
Shared malware family | 0.85 | VirusTotal tag overlap |
Same registrant/ISP | 0.75 | AbuseIPDB usage type match |
Geographic proximity | 0.60 | Haversine distance < 100km |
The engine uses BFS to find connected components. Groups of 3+ IOCs sharing multiple attributes are reported as coordination patterns - indicating likely coordinated threat campaigns that would be invisible in single-IOC analysis.
Repository Structure
threatweaver/
├── src/
│ ├── index.ts # Entry point
│ ├── app.module.ts # Root NitroStack module
│ ├── modules/
│ │ ├── investigation/ # MCP Tools, Resources, Prompts
│ │ ├── correlation/ # Pattern detection engine
│ │ ├── threat-intel/ # API adapters (VT, AbuseIPDB, etc.)
│ │ ├── output/ # STIX and report generation
│ │ ├── storage/ # SQLite and caching
│ │ ├── validation/ # IOC validation (Zod)
│ │ ├── widget/ # Graph visualization
│ │ └── config/ # Configuration
│ ├── common/
│ │ ├── types/ # Shared TypeScript interfaces
│ │ └── errors/ # Custom error classes
│ └── widgets/ # Next.js widget app
│ └── app/investigation-graph/ # vis-network graph component
├── data/
│ ├── fallback-feeds.json # Cached threat intelligence (offline)
│ └── fallback-iocs.json # Sample IOCs for offline mode
├── scripts/
│ ├── seed-db.ts # Database seeder
│ ├── generate-demo-data.ts # Demo data generator
│ └── deploy.sh # NitroCloud deployment script
├── docs/
│ ├── API.md # MCP API reference
│ ├── ARCHITECTURE.md # Architecture deep-dive
│ ├── DEMO.md # Demo script
│ ├── EXTENSION_GUIDE.md # Adding new threat feeds
│ ├── SECURITY.md # Security considerations
│ └── STIX_OUTPUT.md # STIX 2.1 format reference
├── package.json
├── tsconfig.json
├── vitest.config.ts
└── .env.exampleInstallation
git clone https://github.com/yourusername/threatweaver.git
cd threatweaver
npm install
npm run buildConfiguration
Create a .env file from the example:
cp .env.example .envAPI keys are optional. Without keys, ThreatWeaver operates using fallback datasets exposed through the threat://feeds resource.
# API Keys (optional - without keys, use fallback data)
VIRUSTOTAL_API_KEY=
ABUSEIPDB_API_KEY=
SHODAN_API_KEY=
# Cache
CACHE_TTL=3600
CACHE_MAX_SIZE=1000
# Rate Limits
VT_RATE_LIMIT_PER_MIN=600
ABUSEIPDB_RATE_LIMIT_PER_DAY=1000
# Database
DATABASE_PATH=./data/threatweaver.db
# Mode
OFFLINE_MODE=false
LOG_LEVEL=infoRunning
# Development
npm run dev
# Production
npm run build
npm run start:prodClaude Desktop Setup
Add to ~/.config/Claude/claude_desktop_config.json:
{
"mcpServers": {
"threatweaver": {
"command": "node",
"args": ["/absolute/path/to/threatweaver/dist/index.js"]
}
}
}Restart Claude. ThreatWeaver tools appear automatically.
Example Investigation
You: "Investigate the IP 1.2.3.4"
Claude: [calls investigate_indicator]
1.2.3.4 - Threat score 92/100
- VirusTotal: 45 detections (emotet, banking-trojan, c2)
- AbuseIPDB: 95% abuse confidence, 150 reports
- Shodan: Ports 80, 443, 8443 | ASN AS48031 | Moscow, RU
- Verdict: Malicious
Claude: [calls suggest_next_steps]
Found 2 related IOCs:
- evil.com (same ASN AS48031)
- paypa1-secure.login.com (same ASN, shared phishing tags)
You: "Investigate those too"
Claude: [investigates both, then calls correlate_investigations]
Pattern detected: 3 IOCs share ASN AS48031 + malware tags
Confidence: 87%
Evidence: Coordinated phishing infrastructure
Claude: [calls generate_report with format: "stix"]
[Produces STIX 2.1 bundle with IOC objects, malware objects, and relationships]MCP Primitives
Tools (5)
Tool | Purpose |
| Query VT, AbuseIPDB, URLhaus, Shodan for an IOC |
| Analyze context and recommend related IOCs |
| Detect threat patterns across investigation history |
| Produce Markdown or STIX 2.1 output |
| Enrich multiple IOCs with progress streaming |
Resources (2)
Resource | URI | Purpose |
Investigation Context |
| Current investigation state, findings, correlation graph |
Threat Feeds |
| Pre-loaded fallback data for offline mode |
Prompt (1)
Prompt | Purpose |
| Guides Claude through structured investigation workflow |
Widget (1)
Widget | Purpose |
| Interactive vis-network graph of IOC relationships, color-coded by verdict |
Tech Stack
Framework - NitroStack (MCP server framework)
Language - TypeScript 5.3+ (strict mode)
Runtime - Node.js 18+
Database - SQLite 3 (WAL mode, foreign keys)
Validation - Zod
HTTP - Axios
Widget - Next.js 14 + vis-network + React 18
Build - NitroStack CLI
Third-Party APIs
API | Purpose | Free Tier |
Hash/URL/IP reputation | 600 req/min | |
IP reputation + abuse reports | 1,000 req/day | |
Malicious URL database | Unlimited | |
Port/service enumeration | 1 req/month (lite) |
Deployment
NitroCloud
npm run deployThe deployment script runs pre-flight checks, tests, type checking, and builds before deploying.
Local Production
npm run build
npm run start:prodEnvironment Variables for Deployment
Set on NitroCloud Dashboard:
VIRUSTOTAL_API_KEY- for live VirusTotal queriesABUSEIPDB_API_KEY- for live AbuseIPDB queriesDATABASE_PATH- use persistent volume pathOFFLINE_MODE- set tofalsefor production
Future Improvements
Automated test suite (unit, integration, e2e)
Proactive rate limiting with request queuing
Offline mode with full fallback enrichment
MITRE ATT&CK automatic technique mapping from VT tags
File-based JSON logging
Sigma detection rule generation
Additional adapters (Censys, SecurityTrails)
CSV and PDF export formats
Redis caching for distributed deployments
Acknowledgements
Built for Amrita University MCP Hackathon 2026.
NitroStack - MCP server framework
Model Context Protocol - The standard
MITRE ATT&CK - Threat tactics reference
Threat intelligence providers - VirusTotal, AbuseIPDB, URLhaus, Shodan
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that performs third-party threat intelligence enrichment for various observables (IP addresses, domains, URLs, emails) using services like VirusTotal, Shodan, and AbuseIPDB.
- AlicenseAqualityAmaintenanceAn MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.519MIT
- AlicenseAqualityAmaintenanceAn MCP server for the Cortex observable analysis and active response engine. It enables LLMs to automate security investigations by running analyzers on observables like IPs and URLs and executing automated response actions.31101MIT
- AlicenseAqualityAmaintenanceAn MCP server that enables LLMs to interact with MISP for threat intelligence sharing, IOC lookups, and event management. It provides tools for investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata.36312MIT
Related MCP Connectors
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
Query Truss threat intelligence via hosted MCP (OAuth). Growth+ plans.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Hadobot/threatweaver'
If you have feedback or need assistance with the MCP directory API, please join our Discord server