Hunt threats using adversary TTPs with MITRE ATT&CK-based analysis.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Threat Hunting MCP Server" yet — see the docs or source repo.
Based on recent lateral movement behavior in a Windows environment, generate 5 actionable threat hunting hypotheses mapped to MITRE ATT&CK, and explain the key observations and possible data sources for each.
Returns 5 ATT&CK-mapped hunting hypotheses with behavioral traits, focal points, and recommended log sources.
I observed PowerShell execution, unusual credential use, and remote service creation. Analyze the possible attack chain from an adversary TTP perspective and list the evidence that should be validated next.
Provides likely attack stage correlations, mapped ATT&CK techniques, and next-step validation recommendations.
Provide community threat hunting ideas related to privilege escalation in cloud environments, prioritizing behavior patterns over IOCs, and organize them into an SOC-ready investigation checklist.
Returns a behavior-focused SOC checklist with community hypotheses, investigation steps, and prioritization guidance.
Look up threat intel, CVEs, breached credentials, and dark web data.
Analyze security incidents, map ATT&CK techniques, score severity, and recommend remediation.
Orchestrate red team assessments and manage targets, operations, and findings with ATT&CK alignment.
Retrieve normalized OpenCTI threat intelligence with context for indicators, actors, and reports.
Recon username footprints across 480+ platforms with reports and scores.
Analyze MCP tool security risks, detect malicious behavior, and provide risk scores.