Provides MISP threat-intelligence workflows for search, pivots, summaries, and reports.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "agentic-misp-mcp" yet — see the docs or source repo.
Use this tool to search this IOC in MISP and pivot into related events: 8.8.8.8
Returns matching events, related leads, and pivot points for further investigation.
Summarize this MISP event for an analyst, highlighting the timeline, IOCs, and key findings.
Produces a structured event summary for quick threat understanding.
Draft a report from the current investigation and provide controlled write proposals, including safety and audit-log notes.
Produces a reviewable report draft and controlled write proposals.
When an analyst has an IP, domain, or hash IOC, this tool can search MISP and pivot into related events. It helps expand the investigation quickly.
When you need to brief teammates, it can turn event data into concise summaries and report drafts, reducing manual整理 work.
If updates to intelligence data are needed, the tool provides controlled write proposals with safety and audit logging. It fits approval-based workflows.
It provides analyst-oriented workflows for MISP threat intelligence, including IOC search, pivoting, event summaries, and report generation. It also supports controlled write proposals with safety and audit logging.
From the description, it provides controlled write proposals rather than unrestricted direct writes. The exact write behavior and workflow details are not provided; see the source repository.
It is suited for people doing threat intelligence, IOC analysis, and incident assessment, as well as users who need to turn findings into reports.
Connect MISP to MCP clients for plain-language threat indicator lookup and submission.
Search MISP threat intelligence events, attributes, tags, and galaxies in natural language.
Analyze security incidents, map ATT&CK techniques, score severity, and recommend remediation.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
Lets AI agents query Google Threat Intelligence for IOC and artifact analysis.
Retrieve normalized OpenCTI threat intelligence with context for indicators, actors, and reports.