- Conduid
- Marketplace
- #threat-intelligence
MCP servers tagged threat-intelligence
29 live MCP servers tagged "threat-intelligence", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with threat-intelligence.
Viper
🛡️ VIPER: Stay ahead of threats with AI-driven vulnerability intelligence. Prioritize CVEs effectively using NVD, EPSS, CISA KEV, and Google Gemini insights, all on an interactive…
Xtm MCP
eXtended Threat Management MCP Servers
Honeymcp
Open-source honeypot for MCP (Model Context Protocol) servers. Collects threat intel on attacks against the AI agent ecosystem.
Anthropic Cybersecurity Skills
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini…
Awesome Annual Security Reports
A curated list of annual cyber security reports
AiSOC
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Attackgen
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tail…
Gti MCP Standalone
MCP server: Gti MCP Standalone
Mallorymcp
Mallory - Cyber Threat Intelligence MCP Server
Cyberbro
Using MCP is fun with Cyberbro!
Lyrie AI
Lyrie.ai — The world's first autonomous AI cybersecurity agent. Built by OTT Cybersecurity LLC.
Opensquat
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
API
Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and strea…
Cve MCP Server
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
OnionClaw
OnionClaw™ — OpenClaw skill for full Tor dark web access: search .onion sites, fetch hidden services, rotate identity, run OSINT pipeline, craw.
ARL Next
🚀 自动化资产侦察与漏洞监控平台 (ARL-Next)。重构自经典 ARL,全面升级 Puppeteer + Nuclei 引擎,打通「天眼查/ICP ➔ 资产发现 ➔ 漏洞扫描 ➔ 威胁情报追踪」安全闭环。支持 Docker 极简部署,AI 二开友好。
Panguard MCP Proxy
MCP Proxy — runtime interception for AI agent tool calls using ATR rules
ZettelForge
Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code and LangChain agents
Darknet MCP Server
66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs
World Intel MCP
100+ tool MCP server for real-time global intelligence — markets, FX, bonds, earnings, SEC filings, conflict, military, cyber, climate, news, company enrichment, and 30+ domains.…
Ms Sentinel MCP Server
MCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed f…
Wazuh Autopilot
Autonomous AI SOC for Wazuh SIEM — 11 security-expert agents triage, correlate, investigate and plan responses 24/7, every action gated by two-tier human approval. Runs on OpenCla…
Services
Multi-tool MCP server + REST API for AI agents. 29 tools: web scraping, SEO toolkit, agent memory, screenshot, PDF, PDF-to-DOCX, WHOIS, DNS, SSL, OCR, HTML-to-Markdown, multi-chai…
Osint MCP Server
OSINT intelligence MCP server for AI agents — 37 tools, 12 sources. Shodan, VirusTotal, Censys, SecurityTrails, DNS reconnaissance, WHOIS, certificate transparency, BGP routing, W…
Vulnerability Intelligence MCP Server
Built for security professionals, developers, and DevSecOps teams who need reliable vulnerability intelligence integrated directly into their development workflow.
ppcvote/misp-mcp-server
intel tools (events, attributes, search, tags, feeds, galaxies). Scans every MISP response for adversarial seeding before returning to LLM. Tracks [MISP/MISP#10745](https://github…
Dns Security MCP
104-tool DNS Security Intelligence MCP Server — DNSSEC, hijacking, tunneling, typosquatting, email security, CT monitoring, blocklist, infrastructure audit. 100% local, zero API k…
Nikolife2016/pulsefeed-x402
mcp`
Vo Soc Harness
Harness de operaciones de ciberseguridad sobre Trend Micro Vision One: agentes de IA que hacen triage, investigan IOCs, ejecutan la contención y documentan la alerta. Incluye el s…