Manage security cases, indicators, and artifacts through ThreatConnect v3.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "ThreatConnect v3 MCP Server" yet — see the docs or source repo.
Use ThreatConnect v3 to create a high-priority case titled "Suspected Phishing Email Incident" with discovery time, affected employee, and initial containment recommendations.
Returns the new case details such as case ID, title, priority, and creation status.
In ThreatConnect v3, update indicator 198.51.100.24 by adding the tags "C2" and "High Risk", plus source notes and the last observed time.
Returns the indicator update result, including added tags, updated fields, and success status.
Add these artifacts to the case "Malicious Login Investigation": suspicious email address, login IP, and related URL, each with its type and a short description.
Returns a list of added artifacts with type, value, linked case, and write status.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
Investigate threat indicators via urlscan and VirusTotal with compact structured results.
Query threat intelligence and trace incidents for faster security triage automation.
Connect AI assistants to ThreatLocker Portal API for security management tasks.
Securely search internal documents and company data through an authenticated MCP connector.
Connect AI assistants to Vectra on-prem for threat detection and response automation.