Intel Threadlinqs MCP
Related Servers
Alternatives to Intel Threadlinqs MCP
- AlicenseNot gradedqualityDmaintenanceUnifies 7,283+ detection rules from Sigma, Splunk ESCU, Elastic, and KQL into a single queryable interface via MCP, with a web dashboard and autonomous agent pipeline for detection engineering.274 npm1Apache 2.0
Related Servers
- AlicenseNot gradedqualityBmaintenanceA defensive MCP server for Claude Desktop / any MCP client — the blue-team counterpart to offensive tooling. 123 tools + 4 resources across Wazuh SIEM, multi-provider threat intelligence, MITRE-driven 3-Sum APT correlation, attack graphing, LangGraph investigation workflows, and host forensics. Read-only by default.58BSD 3-Clause
- AlicenseBqualityFmaintenanceMCP server providing comprehensive threat intelligence access to OpenCTI for Claude Code and other MCP clients, with 32 tools for searching and managing threat data.28MIT
- FlicenseNot gradedqualityCmaintenanceThis MCP server connects Claude Desktop to OpenCTI for AI-augmented threat intelligence analysis, enabling natural language queries and instant, contextualized answers from your threat intelligence database.29-
- AlicenseNot gradedqualityAmaintenanceAn MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.1MIT
- AlicenseNot gradedqualityDmaintenanceThis MCP server connects Claude Desktop to a Velociraptor instance and local forensic tools. It enables remote endpoint investigation and local evidence analysis through natural language commands.1MIT
- AlicenseNot gradedqualityDmaintenanceA comprehensive MCP server that exposes multiple OSINT tools to AI assistants like Claude, enabling sophisticated reconnaissance and information gathering tasks using industry-standard OSINT tools.237MIT
TDQS
Scored across 81 tools
The descriptions are unusually thorough, but the set is dense with overlapping families: get_threat / get_threat_enrichment / get_threat_bundle / get_threat_hunting_bundle, get_cve / get_cve_intelligence, get_actor / get_actor_intelligence, get_ioc_intelligence / get_entity_profile, and the multiple campaign tools. An agent can easily pick a differently-scoped variant and get a different result shape than expected. The detailed caveats are the only thing keeping this from a 1.
The overwhelming majority of tool names follow a clear verb_noun snake_case pattern: get_threat, search_threats, list_debriefs, export_stix, generate_c2_blocklist, explain_correlation, and hunt_schema. Minor deviations like `health` and bare `hunt`, plus the alternation between get/search on very similar resources, keep it from a perfect 5.
81 tools is far beyond a workable MCP surface; the list itself becomes the main cognitive burden for an agent. The many get_*_intelligence and bundle tools show the platform knows fragmentation is a problem, but they add to rather than reduce the raw count.
The threat-intelligence domain is covered remarkably well: threats, actors, malware, tools, campaigns, CVEs, CWEs, IOCs, detections, C2, MITRE, ATT&CK Flows, and correlation evidence all have dedicated lookup and search paths. There are only minor workaroundable gaps such as some endpoints without full pagination and some stored-only enrichment layers.