Skip to main content
Glama
yayefa
by yayefa

Google Threat Intelligence (GTI) MCP Server

Model Context Protocol Google Cloud Run License

Ein produktionsreifer Model Context Protocol (MCP)-Server, der eine umfassende Integration mit Google Threat Intelligence (GTI) und VirusTotal API v3 bietet. Entwickelt mit hochleistungsfähigem asynchronem Python, FastAPI und dem MCP-Streamable-HTTP-Transportstandard (/mcp), konzipiert für die Bereitstellung auf Google Cloud Run und die nahtlose Interaktion mit Gemini Enterprise und KI-Sicherheitsagenten.


🌟 Hauptfunktionen

  • Streamable-HTTP-Transport (/mcp): Native Unterstützung für die MCP-Streamable-HTTP-Protokollspezifikation mit weiterleitungsfreiem Routing.

  • 22+ Threat-Intelligence-Tools: Direkter Zugriff auf Google-Threat-Intelligence-Sammlungen, Bedrohungsakteure, Kampagnen, Malware-Familien, Berichte, Datei-Sandbox-Analysen, IP-/Domain-/URL-Telemetrie und IoC-Abfragen.

  • Enterprise-Sicherheit: Native Integration mit Google Cloud Secret Manager (VT_APIKEY / VT_SECRET_NAME) stellt sicher, dass keine Geheimnisse oder API-Schlüssel im Quellcode gespeichert werden.

  • Gemini Enterprise & Agent Ready: IAM-geschützte Endpunkte (roles/run.invoker) mit Google-Cloud-Identitätsauthentifizierung.

  • Automatisierte Cloud-Bereitstellung: Ein Build- und Bereitstellungsskript mit einem einzigen Befehl (deploy.sh) für Google Cloud Build und Cloud Run.


Related MCP server: OSINT MCP Server

🛠️ MCP-Tool-Suite

Kategorie

Verfügbare Tools

Bedrohungslandschaft & Sammlungen

search_threat_actors, get_threat_actor, search_campaigns, get_campaign, search_malware_families, get_malware_family, search_reports, get_threat_report

Datei- & IoC-Telemetrie

get_file_report, get_file_behaviour, search_ioc, get_file_sigma_analysis, get_file_yara_rules

Netzwerkinfrastruktur

get_ip_report, get_domain_report, get_url_report, get_ip_communicating_files, get_domain_communicating_files, get_ip_historical_ssl, get_domain_subdomains

Diagnose & Status

health_check, get_server_status


🚀 Schnellstart

1. Voraussetzungen

  • Python 3.10+

  • Google Cloud SDK (gcloud) mit Projektzugriff konfiguriert

  • Gültiger Google Threat Intelligence / VirusTotal API-Schlüssel

2. Lokale Einrichtung

Klonen Sie das Repository und installieren Sie die Abhängigkeiten:

git clone https://github.com/yayefa/GTI-MCP-Server.git
cd GTI-MCP-Server

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

3. Umgebungskonfiguration

Kopieren Sie die Beispiel-Umgebungsdatei:

cp .env.example .env

Bearbeiten Sie .env, um Ihre Einstellungen zu konfigurieren:

PROJECT_ID=your-gcp-project-id
REGION=us-central1
SERVICE_NAME=mcp-gti-mcp-server
VT_SECRET_NAME=VT_APIKEY
SECRET_PROJECT_ID=your-gcp-project-id
LOG_LEVEL=INFO

4. Lokal ausführen

uvicorn server:app --host 0.0.0.0 --port 8080 --reload

☁️ Bereitstellung auf Google Cloud Run

1. API-Schlüssel in Google Secret Manager speichern

echo -n "YOUR_GTI_VT_API_KEY" | gcloud secrets create "VT_APIKEY" \
    --data-file=- \
    --project="YOUR_PROJECT_ID" \
    --replication-policy="automatic"

2. Per Skript bereitstellen

Führen Sie das automatisierte Bereitstellungsskript aus:

chmod +x deploy.sh
./deploy.sh

Vollständige Bereitstellungsdetails und IAM-Konfiguration finden Sie in DEPLOYMENT.md.


🧪 Testen und Verifizieren

Führen Sie den automatisierten Testclient gegen Ihre laufende Instanz oder den bereitgestellten Cloud-Run-Dienst aus:

AUTH_TOKEN=$(gcloud auth print-identity-token) \
TARGET_URL="https://<YOUR-CLOUD-RUN-URL>" \
python3 test_client.py

Oder fragen Sie den MCP-Endpunkt direkt mit curl ab:

curl -X POST https://<YOUR-CLOUD-RUN-URL>/mcp \
  -H "Authorization: Bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "get_ip_report",
      "arguments": {
        "ip_address": "8.8.8.8"
      }
    }
  }'

📄 Lizenz

Dieses Projekt ist unter der Apache-2.0-Lizenz lizenziert – siehe die Datei LICENSE für Details.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.
    5
    19
    MIT
  • A
    license
    D
    quality
    D
    maintenance
    A comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.
    56
    20
    ISC
  • A
    license
    -
    quality
    A
    maintenance
    An MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    MCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.
    8
    1

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • MCP server exposing the Backtest360 engine API as tools for AI agents.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yayefa/GTI-MCP-Server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server