Threat Intel MCP Server
Check IPs, domains, URLs, or file hashes for reputation and threat intelligence.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Threat Intel MCP Servercheck the reputation and open ports for IP address 193.163.125.12"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Threat Intel MCP Server
A FastMCP server providing threat intelligence and vulnerability research tools for Claude. Integrates with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT&CK.
Tools
Tool | Source | Description |
| NVD | CVE details, CVSS scores, affected products |
| NVD | Search CVEs by product and version |
| VirusTotal | Check IPs, domains, URLs, or file hashes |
| AbuseIPDB | Abuse confidence score and report history |
| Shodan | Open ports, services, and correlated CVEs |
| MITRE ATT&CK | Technique details, tactics, and mitigations |
Related MCP server: Exploit Intel Platform MCP Server
Setup
1. Create and activate a virtual environment:
python -m venv venv
.\venv\Scripts\Activate.ps12. Install dependencies:
pip install -r requirements.txt3. Configure API keys — copy .env.example to .env and fill in your keys:
VIRUSTOTAL_API_KEY=your_key_here
ABUSEIPDB_API_KEY=your_key_here
SHODAN_API_KEY=your_key_hereFree API keys: VirusTotal · AbuseIPDB · Shodan
Claude Desktop
Since the server now runs over HTTP, start it first, then configure Claude Desktop to connect via URL.
1. Start the server (keep this running):
python server.py2. Add to %APPDATA%\Claude\claude_desktop_config.json:
{
"mcpServers": {
"threat-intel": {
"url": "http://127.0.0.1:8000/mcp"
}
}
}API keys are read from .env automatically.
Important: Claude Desktop only reads
claude_desktop_config.jsonon launch. After saving the config, fully quit and restart Claude Desktop — changes do not take effect while it is running.
MCP Inspector
The server runs over HTTP (Streamable HTTP) on port 8000. Start it first, then connect the inspector.
1. Start the server:
python server.py2. Launch the inspector:
npx @modelcontextprotocol/inspectorOpen http://localhost:5173, set transport to Streamable HTTP, and enter the URL http://127.0.0.1:8000/mcp.
Adding New Tools
Create
tools/newtool.pywith your async functionRegister it in
server.py:
from tools.newtool import my_function as _my_function
@mcp.tool()
async def my_tool(param: str) -> str:
"""Tool description shown in Inspector and to the LLM.
Args:
param: Parameter description
"""
return str(await _my_function(param))FastMCP generates the JSON schema automatically from the signature and docstring.
API Rate Limits
Service | Free Tier |
VirusTotal | 4 req/min, 500 req/day |
AbuseIPDB | 1,000 req/day |
Shodan | 100 results/month |
NVD | No key required |
MITRE ATT&CK | No key required |
Troubleshooting
JSON-RPC / EOF errors — This server uses HTTP transport. Run python server.py directly to start it; mcp dev is not required and is only needed for stdio-based servers.
API key not found — Ensure .env exists in the project root (copy from .env.example). At startup, the server prints a warning listing any unset keys and which tools they affect.
Rate limit errors — Wait before retrying, or upgrade to a paid API tier.
This server cannot be deployed
Maintenance
Related MCP Connectors
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI-powered threat intelligence analysis of IPs, domains, URLs, and file hashes across multiple threat intelligence platforms (VirusTotal, AlienVault OTX, AbuseIPDB, IPinfo) with APT attribution and interactive reporting through natural language queries.17 PyPI39Apache 2.0
- AlicenseAqualityDmaintenanceEnables AI assistants to search and analyze vulnerabilities and exploits from multiple intelligence sources, including NVD, CISA KEV, ExploitDB, Metasploit, and more, with tools for CVE research, exploit analysis, and report generation.17MIT
- AlicenseNot gradedqualityFmaintenanceProvides CVE search enriched with EPSS exploit likelihood and CISA KEV status, plus live IP/domain reputation and a real-time threat feed for AI agents.MIT
- FlicenseNot gradedqualityDmaintenanceEnables cybersecurity research through Claude by providing tools for CVE lookup, IP geolocation, and file hash checking against VirusTotal.-