Threat Intel MCP Server
Check IPs, domains, URLs, or file hashes for reputation and threat intelligence.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Threat Intel MCP Servercheck the reputation and open ports for IP address 193.163.125.12"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Threat Intel MCP Server
A FastMCP server providing threat intelligence and vulnerability research tools for Claude. Integrates with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT&CK.
Tools
Tool | Source | Description |
| NVD | CVE details, CVSS scores, affected products |
| NVD | Search CVEs by product and version |
| VirusTotal | Check IPs, domains, URLs, or file hashes |
| AbuseIPDB | Abuse confidence score and report history |
| Shodan | Open ports, services, and correlated CVEs |
| MITRE ATT&CK | Technique details, tactics, and mitigations |
Related MCP server: Security Intelligence MCP Server
Setup
1. Create and activate a virtual environment:
python -m venv venv
.\venv\Scripts\Activate.ps12. Install dependencies:
pip install -r requirements.txt3. Configure API keys — copy .env.example to .env and fill in your keys:
VIRUSTOTAL_API_KEY=your_key_here
ABUSEIPDB_API_KEY=your_key_here
SHODAN_API_KEY=your_key_hereFree API keys: VirusTotal · AbuseIPDB · Shodan
Claude Desktop
Since the server now runs over HTTP, start it first, then configure Claude Desktop to connect via URL.
1. Start the server (keep this running):
python server.py2. Add to %APPDATA%\Claude\claude_desktop_config.json:
{
"mcpServers": {
"threat-intel": {
"url": "http://127.0.0.1:8000/mcp"
}
}
}API keys are read from .env automatically.
Important: Claude Desktop only reads
claude_desktop_config.jsonon launch. After saving the config, fully quit and restart Claude Desktop — changes do not take effect while it is running.
MCP Inspector
The server runs over HTTP (Streamable HTTP) on port 8000. Start it first, then connect the inspector.
1. Start the server:
python server.py2. Launch the inspector:
npx @modelcontextprotocol/inspectorOpen http://localhost:5173, set transport to Streamable HTTP, and enter the URL http://127.0.0.1:8000/mcp.
Adding New Tools
Create
tools/newtool.pywith your async functionRegister it in
server.py:
from tools.newtool import my_function as _my_function
@mcp.tool()
async def my_tool(param: str) -> str:
"""Tool description shown in Inspector and to the LLM.
Args:
param: Parameter description
"""
return str(await _my_function(param))FastMCP generates the JSON schema automatically from the signature and docstring.
API Rate Limits
Service | Free Tier |
VirusTotal | 4 req/min, 500 req/day |
AbuseIPDB | 1,000 req/day |
Shodan | 100 results/month |
NVD | No key required |
MITRE ATT&CK | No key required |
Troubleshooting
JSON-RPC / EOF errors — This server uses HTTP transport. Run python server.py directly to start it; mcp dev is not required and is only needed for stdio-based servers.
API key not found — Ensure .env exists in the project root (copy from .env.example). At startup, the server prints a warning listing any unset keys and which tools they affect.
Rate limit errors — Wait before retrying, or upgrade to a paid API tier.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceEnables AI-powered threat intelligence analysis of IPs, domains, URLs, and file hashes across multiple threat intelligence platforms (VirusTotal, AlienVault OTX, AbuseIPDB, IPinfo) with APT attribution and interactive reporting through natural language queries.Last updated40Apache 2.0
- Flicense-qualityBmaintenanceProvides a unified interface for security analysts to gather threat intelligence from multiple sources including VirusTotal, Shodan, NVD, AnyRun, AlienVault OTX, and GitHub.Last updated33
- AlicenseAqualityBmaintenanceEnables AI assistants to search and analyze vulnerabilities and exploits from multiple intelligence sources, including NVD, CISA KEV, ExploitDB, Metasploit, and more, with tools for CVE research, exploit analysis, and report generation.Last updated17MIT
- Alicense-qualityAmaintenanceProvides CVE search enriched with EPSS exploit likelihood and CISA KEV status, plus live IP/domain reputation and a real-time threat feed for AI agents.Last updatedMIT
Related MCP Connectors
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Appeared in Searches
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/iceage2114/Security-Sandbox'
If you have feedback or need assistance with the MCP directory API, please join our Discord server