Query threat intelligence and trace incidents for faster security triage automation.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "cti-mcp-server" yet — see the docs or source repo.
Use cti-mcp-server to look up threat intelligence for IP 8.8.8.8. Return reputation, geolocation, related tags, and handling recommendations.
A concise intelligence summary for the IP, including risk assessment, context, and recommended actions.
Use cti-mcp-server to backtrack this IoC: malicious-example.com. Find related events, linked indicators, and timeline details, then summarize the likely attack path.
An incident timeline, related IoC list, and a brief analysis of the likely attack chain.
Use cti-mcp-server to batch query the following alert evidence: IPs, domains, and file hashes. Classify each as high, medium, or low risk and explain the reasoning.
A structured triage report with risk levels, matched intelligence, and response priorities.
Look up threat intel, CVEs, breached credentials, and dark web data.
Retrieve normalized OpenCTI threat intelligence with context for indicators, actors, and reports.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
Lets AI assistants query and manage OpenCTI threat intelligence entities and data.
Look up and enrich IP threat intelligence with bulk hunting and ASN analysis.
Connect MISP to MCP clients for plain-language threat indicator lookup and submission.