GTI MCP Server
Servidor MCP de Google Threat Intelligence (GTI)
Un servidor Model Context Protocol (MCP) listo para producción que proporciona una integración completa con Google Threat Intelligence (GTI) y VirusTotal API v3. Construido con Python asíncrono de alto rendimiento, FastAPI y el estándar de transporte MCP Streamable HTTP (/mcp), diseñado para su despliegue en Google Cloud Run y una interacción fluida con Gemini Enterprise y los Agentes de Seguridad de IA.
🌟 Características principales
Transporte HTTP Streamable (
/mcp): Soporte nativo para la especificación del protocolo MCP Streamable HTTP con enrutamiento sin redirecciones.Más de 22 herramientas de inteligencia de amenazas: Acceso directo a colecciones de Google Threat Intelligence, Actores de Amenazas, Campañas, Familias de Malware, Informes, Análisis de Sandbox de Archivos, telemetría de IP/Dominio/URL y búsquedas de IoC.
Seguridad empresarial: Integración nativa con Google Cloud Secret Manager (
VT_APIKEY/VT_SECRET_NAME) garantiza que no se almacenen secretos ni claves API en el código fuente.Preparado para Gemini Enterprise y Agentes: Endpoints protegidos por IAM (
roles/run.invoker) con autenticación de identidad de Google Cloud.Despliegue automatizado en la nube: Script de compilación y despliegue con un solo comando (
deploy.sh) con Google Cloud Build y Cloud Run.
Related MCP server: OSINT MCP Server
🛠️ Conjunto de herramientas MCP
Categoría | Herramientas disponibles |
Panorama de amenazas y colecciones |
|
Telemetría de archivos e IoC |
|
Infraestructura de red |
|
Diagnóstico y estado |
|
🚀 Inicio rápido
1. Requisitos previos
Python 3.10+
Google Cloud SDK (
gcloud) configurado con acceso al proyectoClave API de Google Threat Intelligence / VirusTotal válida
2. Configuración local
Clona el repositorio e instala las dependencias:
git clone https://github.com/yayefa/GTI-MCP-Server.git
cd GTI-MCP-Server
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt3. Configuración del entorno
Copia el archivo de entorno de muestra:
cp .env.example .envEdita .env para configurar tus ajustes:
PROJECT_ID=your-gcp-project-id
REGION=us-central1
SERVICE_NAME=mcp-gti-mcp-server
VT_SECRET_NAME=VT_APIKEY
SECRET_PROJECT_ID=your-gcp-project-id
LOG_LEVEL=INFO4. Ejecución local
uvicorn server:app --host 0.0.0.0 --port 8080 --reload☁️ Despliegue en Google Cloud Run
1. Almacena la clave API en Google Secret Manager
echo -n "YOUR_GTI_VT_API_KEY" | gcloud secrets create "VT_APIKEY" \
--data-file=- \
--project="YOUR_PROJECT_ID" \
--replication-policy="automatic"2. Despliega mediante script
Ejecuta el script de despliegue automatizado:
chmod +x deploy.sh
./deploy.shPara obtener detalles completos del despliegue y la configuración de IAM, consulta DEPLOYMENT.md.
🧪 Pruebas y verificación
Ejecuta el cliente de pruebas automatizado contra tu instancia en ejecución o el servicio desplegado en Cloud Run:
AUTH_TOKEN=$(gcloud auth print-identity-token) \
TARGET_URL="https://<YOUR-CLOUD-RUN-URL>" \
python3 test_client.pyO consulta el endpoint MCP directamente usando curl:
curl -X POST https://<YOUR-CLOUD-RUN-URL>/mcp \
-H "Authorization: Bearer $(gcloud auth print-identity-token)" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "get_ip_report",
"arguments": {
"ip_address": "8.8.8.8"
}
}
}'📄 Licencia
Este proyecto está licenciado bajo la licencia Apache 2.0; consulta el archivo LICENSE para obtener más detalles.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceAn MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.519MIT
- AlicenseDqualityDmaintenanceA comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.5620ISC
- Alicense-qualityAmaintenanceAn MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.1MIT
- FlicenseAqualityDmaintenanceMCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.81
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
MCP server exposing the Backtest360 engine API as tools for AI agents.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/yayefa/GTI-MCP-Server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server