Lets AI agents query Google Threat Intelligence for IOC and artifact analysis.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Google Threat Intelligence MCP Server" yet — see the docs or source repo.
Use the Google Threat Intelligence MCP Server to analyze this suspicious IP: 8.8.8.8. Return relevant threat intelligence, a risk assessment, and suggested next investigation steps.
Returns intelligence findings for the IP, potential risk notes, and recommended investigation steps.
Use the Google Threat Intelligence MCP Server to search this IOC: example.com, and summarize whether it is linked to known threat activity.
Returns IOC search results and a summary of any links to threat activity.
Use the Google Threat Intelligence MCP Server to list threat hunting rulesets relevant to this security investigation and explain when to use them.
Returns relevant rulesets and explains the investigation scenarios where each applies.
Security or operations staff can use this tool through an AI agent when alerts involve suspicious files, domains, IPs, or URLs. It helps enrich threat intelligence and speed up risk triage.
Researchers or developers can search around a specific IOC to see whether it is associated with known threat activity. This is useful for quickly gathering context during an investigation.
During proactive threat hunting, teams can use this tool to access threat hunting rulesets that support investigations. It is useful for expanding hunting ideas and narrowing targets.
It enables LLM agents to access Google Threat Intelligence data for IOC search, file/domain/IP/URL analysis, and threat hunting rulesets to support security investigations.
Based on the description, it supports IOC search and analysis of files, domains, IPs, and URLs. These capabilities are primarily aimed at security investigations.
The provided materials do not include installation steps, runtime requirements, or key details. For prerequisites and deployment, see the source repository.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
Look up threat intel, CVEs, breached credentials, and dark web data.
Investigate threat indicators via urlscan and VirusTotal with compact structured results.
Query GA4 data via MCP for real-time metrics, reports, and metadata.
Access Google Search Console data for performance, indexation, and SEO diagnostics.
Connect Google Workspace apps to automate email, documents, calendars, and tasks.