Skip to main content
Glama
yayefa
by yayefa

Servidor MCP de Google Threat Intelligence (GTI)

Model Context Protocol Google Cloud Run License

Un servidor Model Context Protocol (MCP) listo para producción que proporciona una integración completa con Google Threat Intelligence (GTI) y VirusTotal API v3. Construido con Python asíncrono de alto rendimiento, FastAPI y el estándar de transporte MCP Streamable HTTP (/mcp), diseñado para su despliegue en Google Cloud Run y una interacción fluida con Gemini Enterprise y los Agentes de Seguridad de IA.


🌟 Características principales

  • Transporte HTTP Streamable (/mcp): Soporte nativo para la especificación del protocolo MCP Streamable HTTP con enrutamiento sin redirecciones.

  • Más de 22 herramientas de inteligencia de amenazas: Acceso directo a colecciones de Google Threat Intelligence, Actores de Amenazas, Campañas, Familias de Malware, Informes, Análisis de Sandbox de Archivos, telemetría de IP/Dominio/URL y búsquedas de IoC.

  • Seguridad empresarial: Integración nativa con Google Cloud Secret Manager (VT_APIKEY / VT_SECRET_NAME) garantiza que no se almacenen secretos ni claves API en el código fuente.

  • Preparado para Gemini Enterprise y Agentes: Endpoints protegidos por IAM (roles/run.invoker) con autenticación de identidad de Google Cloud.

  • Despliegue automatizado en la nube: Script de compilación y despliegue con un solo comando (deploy.sh) con Google Cloud Build y Cloud Run.


Related MCP server: OSINT MCP Server

🛠️ Conjunto de herramientas MCP

Categoría

Herramientas disponibles

Panorama de amenazas y colecciones

search_threat_actors, get_threat_actor, search_campaigns, get_campaign, search_malware_families, get_malware_family, search_reports, get_threat_report

Telemetría de archivos e IoC

get_file_report, get_file_behaviour, search_ioc, get_file_sigma_analysis, get_file_yara_rules

Infraestructura de red

get_ip_report, get_domain_report, get_url_report, get_ip_communicating_files, get_domain_communicating_files, get_ip_historical_ssl, get_domain_subdomains

Diagnóstico y estado

health_check, get_server_status


🚀 Inicio rápido

1. Requisitos previos

  • Python 3.10+

  • Google Cloud SDK (gcloud) configurado con acceso al proyecto

  • Clave API de Google Threat Intelligence / VirusTotal válida

2. Configuración local

Clona el repositorio e instala las dependencias:

git clone https://github.com/yayefa/GTI-MCP-Server.git
cd GTI-MCP-Server

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

3. Configuración del entorno

Copia el archivo de entorno de muestra:

cp .env.example .env

Edita .env para configurar tus ajustes:

PROJECT_ID=your-gcp-project-id
REGION=us-central1
SERVICE_NAME=mcp-gti-mcp-server
VT_SECRET_NAME=VT_APIKEY
SECRET_PROJECT_ID=your-gcp-project-id
LOG_LEVEL=INFO

4. Ejecución local

uvicorn server:app --host 0.0.0.0 --port 8080 --reload

☁️ Despliegue en Google Cloud Run

1. Almacena la clave API en Google Secret Manager

echo -n "YOUR_GTI_VT_API_KEY" | gcloud secrets create "VT_APIKEY" \
    --data-file=- \
    --project="YOUR_PROJECT_ID" \
    --replication-policy="automatic"

2. Despliega mediante script

Ejecuta el script de despliegue automatizado:

chmod +x deploy.sh
./deploy.sh

Para obtener detalles completos del despliegue y la configuración de IAM, consulta DEPLOYMENT.md.


🧪 Pruebas y verificación

Ejecuta el cliente de pruebas automatizado contra tu instancia en ejecución o el servicio desplegado en Cloud Run:

AUTH_TOKEN=$(gcloud auth print-identity-token) \
TARGET_URL="https://<YOUR-CLOUD-RUN-URL>" \
python3 test_client.py

O consulta el endpoint MCP directamente usando curl:

curl -X POST https://<YOUR-CLOUD-RUN-URL>/mcp \
  -H "Authorization: Bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "get_ip_report",
      "arguments": {
        "ip_address": "8.8.8.8"
      }
    }
  }'

📄 Licencia

Este proyecto está licenciado bajo la licencia Apache 2.0; consulta el archivo LICENSE para obtener más detalles.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.
    5
    19
    MIT
  • A
    license
    D
    quality
    D
    maintenance
    A comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.
    56
    20
    ISC
  • A
    license
    -
    quality
    A
    maintenance
    An MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    MCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.
    8
    1

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • MCP server exposing the Backtest360 engine API as tools for AI agents.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yayefa/GTI-MCP-Server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server