Lets AI assistants query and manage OpenCTI threat intelligence entities and data.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "OpenCTI MCP Server" yet — see the docs or source repo.
Please query OpenCTI for this indicator: 198.51.100.42. Return its type, related observables, linked reports, and known context.
A summary of the indicator plus its related observables, reports, and other linked intelligence entities.
Please retrieve intelligence on the malware named "Emotet" from OpenCTI, including related reports, indicators, and observables, and briefly explain their relationships.
A structured summary of the malware entity and its linked reports, indicators, and observables.
If write operations are enabled on this server, help me record newly discovered threat intelligence in OpenCTI; if not, only state that writing is unavailable.
Either perform the update if permitted or clearly state that the server is currently read-only.
Security researchers can have an AI assistant query indicators, observables, and reports in OpenCTI while investigating suspicious activity or malware. This helps gather context faster and supports analysis.
Developers can use it to connect an AI assistant to OpenCTI so the assistant can answer questions or perform management actions on threat intelligence data. It fits workflows that need a unified interface to intelligence entities.
When optional write access is enabled, teams can use an AI assistant to manage some data in OpenCTI. In read-only mode, it is better suited for querying and review workflows.
It enables AI assistants to query and manage threat intelligence data in OpenCTI. Supported entities include indicators, observables, reports, malware, and more.
The provided description says it supports read-only access with optional write operations. Whether writing is available depends on the current deployment or configuration.
The provided material does not include installation steps, runtime requirements, or authentication details. Please see the source repository for prerequisites.
Retrieve normalized OpenCTI threat intelligence with context for indicators, actors, and reports.
Look up threat intel, CVEs, breached credentials, and dark web data.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
Automate OSINT reconnaissance for asset discovery, secret scanning, and JavaScript analysis.
Discover and shortlist OSINT MCP servers for research and investigation workflows.
Connect OSSEC security monitoring to AI for alerts, host status, and event analysis.