Connect MISP to MCP clients for plain-language threat indicator lookup and submission.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "misp-mcp" yet — see the docs or source repo.
Look up the IP 198.51.100.24 in MISP and summarize any known threat intelligence or risk.
A lookup result for the IP's threat indicators, with a brief plain-language risk summary.
Submit the suspicious domain example-bad-site.com to MISP as a new threat indicator with a short note.
The domain indicator is submitted to MISP, with confirmation of success or any missing details.
Check whether these indicators already exist in MISP: hash abc123, domain bad.example, and IP 203.0.113.10.
A result for each indicator showing whether it matches existing threat intelligence records.
Researchers or security-focused users can query whether an IP, domain, or hash already exists in MISP using plain language. This helps them assess whether an alert artifact is related to known threat intelligence.
When a team discovers a new suspicious indicator, they can submit it to MISP through an MCP client. This reduces context switching between different tools and interfaces.
Developers can integrate this tool into MCP-enabled AI workflows so the model can perform threat indicator lookups and submissions directly. It is useful when security intelligence systems need to be operated through natural language.
It connects MISP to MCP clients so users can look up and submit threat indicators in plain language. Its core capabilities are indicator retrieval and submission.
Based on the description, you at least need a working MISP environment and an MCP-compatible client. For exact configuration details, see the source repository.
It focuses on performing lookups and submissions through an MCP client in plain language rather than manual operation in the traditional interface. For supported commands or field coverage, see the source repository.
Search MISP threat intelligence events, attributes, tags, and galaxies in natural language.
Look up threat intel, CVEs, breached credentials, and dark web data.
Retrieve normalized OpenCTI threat intelligence with context for indicators, actors, and reports.
Wrap enterprise data APIs into MCP tools for querying companies, trademarks, and patents.
Analyze MCP tool security risks, detect malicious behavior, and provide risk scores.
Investigate threats and respond to incidents across security data with natural language.