MCPs tagged with threat-intelligence
-
MCP Server for Cortex
Bridge Cortex threat analysis capabilities to MCP-compatible clients like Claude.
MCP Server for Cortex exposes the analysis capabilities of a Cortex instance as tools consumable by Model Context Protocol (MCP) clients, such as large language models. It enables these clients to request threat intelligence analyses via Cortex and receive structured results. The server supports easy configuration, secure authentication, and flexible analyzer selection for integrating threat intelligence tasks into automated AI workflows.
- ⭐ 12
- MCP
- gbrigandi/mcp-server-cortex
-
ORKL MCP Server
A Model Context Protocol server for threat intelligence queries via the ORKL API.
ORKL MCP Server is an implementation of the Model Context Protocol (MCP) designed for seamless integration with MCP-compatible applications. It enables secure querying of the ORKL API, offering tools to fetch and analyze threat reports, threat actors, and intelligence sources. The server streamlines access to detailed cyber threat data for security operations and research.
- ⭐ 45
- MCP
- fr0gger/MCP_Security
-
VirusTotal MCP Server
Security analysis server for VirusTotal with comprehensive relationship data, compatible with MCP-enabled applications.
VirusTotal MCP Server is a Model Context Protocol server that interfaces with the VirusTotal API to deliver detailed security analysis of URLs, files, IPs, and domains. It provides comprehensive reports with automatically fetched relationship data, supporting rich security insights in a single request. Designed for seamless integration with MCP-compatible clients like Claude Desktop, it supports easy installation and flexible configuration options.
- ⭐ 88
- MCP
- BurtTheCoder/mcp-virustotal
-
Beelzebub
AI-driven honeypot framework with advanced threat detection and context protocol support.
Beelzebub is an advanced honeypot framework that utilizes AI and large language models (LLMs) to realistically simulate system interactions, enabling the detection and analysis of sophisticated cyber attacks. The platform supports modular service definitions via YAML, integrates with observability stacks, and supports multiple protocols including MCP, which is used to detect prompt injection against LLM agents. Designed for security researchers and professionals, it enables the creation of distributed honeypot networks for collaborative global threat intelligence.
- ⭐ 1,680
- MCP
- mariocandela/beelzebub