Skip to main content
Glama
yayefa
by yayefa

Google Threat Intelligence (GTI) MCP Server

Model Context Protocol Google Cloud Run Лицензия

Производственный сервер Model Context Protocol (MCP), обеспечивающий полную интеграцию с Google Threat Intelligence (GTI) и VirusTotal API v3. Создан на высокопроизводительном асинхронном Python, FastAPI и стандарте транспорта MCP Streamable HTTP (/mcp), предназначен для развертывания на Google Cloud Run и бесшовного взаимодействия с Gemini Enterprise и AI Security Agents.


🌟 Ключевые возможности

  • Streamable HTTP Transport (/mcp): Нативная поддержка спецификации протокола MCP Streamable HTTP с маршрутизацией без перенаправлений.

  • 22+ инструментов разведки угроз: Прямой доступ к коллекциям Google Threat Intelligence, Threat Actors, Campaigns, Malware Families, Reports, File Sandbox Analyses, IP/Domain/URL телеметрии и поиску IoC.

  • Корпоративная безопасность: Нативная интеграция с Google Cloud Secret Manager (VT_APIKEY / VT_SECRET_NAME) гарантирует отсутствие секретов и ключей API в исходном коде.

  • Готовность к Gemini Enterprise и агентам: Защищенные IAM конечные точки (roles/run.invoker) с аутентификацией через Google Cloud identity.

  • Автоматизированное облачное развертывание: Скрипт сборки и развертывания одной командой (deploy.sh) с Google Cloud Build и Cloud Run.


Related MCP server: OSINT MCP Server

🛠️ Набор инструментов MCP

Категория

Доступные инструменты

Ландшафт угроз и коллекции

search_threat_actors, get_threat_actor, search_campaigns, get_campaign, search_malware_families, get_malware_family, search_reports, get_threat_report

Телеметрия файлов и IoC

get_file_report, get_file_behaviour, search_ioc, get_file_sigma_analysis, get_file_yara_rules

Сетевая инфраструктура

get_ip_report, get_domain_report, get_url_report, get_ip_communicating_files, get_domain_communicating_files, get_ip_historical_ssl, get_domain_subdomains

Диагностика и состояние

health_check, get_server_status


🚀 Быстрый старт

1. Предварительные требования

  • Python 3.10+

  • Google Cloud SDK (gcloud) с настроенным доступом к проекту

  • Действительный ключ API Google Threat Intelligence / VirusTotal

2. Локальная настройка

Клонируйте репозиторий и установите зависимости:

git clone https://github.com/yayefa/GTI-MCP-Server.git
cd GTI-MCP-Server

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

3. Конфигурация окружения

Скопируйте пример файла окружения:

cp .env.example .env

Отредактируйте .env для настройки параметров:

PROJECT_ID=your-gcp-project-id
REGION=us-central1
SERVICE_NAME=mcp-gti-mcp-server
VT_SECRET_NAME=VT_APIKEY
SECRET_PROJECT_ID=your-gcp-project-id
LOG_LEVEL=INFO

4. Локальный запуск

uvicorn server:app --host 0.0.0.0 --port 8080 --reload

☁️ Развертывание на Google Cloud Run

1. Сохранение ключа API в Google Secret Manager

echo -n "YOUR_GTI_VT_API_KEY" | gcloud secrets create "VT_APIKEY" \
    --data-file=- \
    --project="YOUR_PROJECT_ID" \
    --replication-policy="automatic"

2. Развертывание через скрипт

Выполните автоматизированный скрипт развертывания:

chmod +x deploy.sh
./deploy.sh

Полные сведения о развертывании и настройке IAM см. в DEPLOYMENT.md.


🧪 Тестирование и проверка

Запустите автоматизированный тестовый клиент для вашего запущенного экземпляра или развернутого сервиса Cloud Run:

AUTH_TOKEN=$(gcloud auth print-identity-token) \
TARGET_URL="https://<YOUR-CLOUD-RUN-URL>" \
python3 test_client.py

Или запросите конечную точку MCP напрямую с помощью curl:

curl -X POST https://<YOUR-CLOUD-RUN-URL>/mcp \
  -H "Authorization: Bearer $(gcloud auth print-identity-token)" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "get_ip_report",
      "arguments": {
        "ip_address": "8.8.8.8"
      }
    }
  }'

📄 Лицензия

Этот проект лицензирован под лицензией Apache 2.0 — подробности см. в файле LICENSE.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that extracts Indicators of Compromise (IoCs) from unstructured text and checks their reputation across multiple threat intelligence services. It enables real-time analysis of IPs, domains, hashes, and URLs, providing enriched context for security workflows within LLMs.
    5
    19
    MIT
  • A
    license
    D
    quality
    D
    maintenance
    A comprehensive MCP server providing tools for IP, domain, email, and image-based open-source intelligence. It integrates services like Shodan, VirusTotal, and HaveIBeenPwned to facilitate advanced security research and data gathering.
    56
    20
    ISC
  • A
    license
    -
    quality
    A
    maintenance
    An MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    MCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.
    8
    1

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • MCP server exposing the Backtest360 engine API as tools for AI agents.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yayefa/GTI-MCP-Server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server