security MCP Server
MCP server for MISP threat intelligence platform
Discovered via github-topic:mcp and last synced 2mo ago.
1. Install the package
npx -y misp-mcp
2. Add to claude_desktop_config.json
{
"mcpServers": {
"misp-mcp": {
"command": "npx",
"args": [
"-y",
"misp-mcp"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
Get full event details including attributes, objects, galaxies, related events
Yes
Update event metadata (info, threat level, analysis, publish state)
Export IOCs in CSV, STIX, Suricata, Snort, text, or RPZ format
No
Get all available attribute types and category mappings
Report a sighting, false positive, or expiration for an IOC
List galaxies (MITRE ATT&CK, threat actors, malware, tools, etc.)
Required
Search events by IOC value, type, tags, date range, organization
Create a new event with threat level, distribution, and analysis status
Add a single IOC to an event
Soft or hard delete an attribute
Yes
Publish an event to trigger alerts to sharing partners
Find all events and attributes matching a value, with cross-event correlations
Export file hashes (MD5, SHA1, SHA256) for HIDS integration
Network activity
Payload delivery
Add multiple IOCs to an event in one operation
Find events or attributes by tag
List available MISP object templates (file, domain-ip, email, etc.)
Attach a cluster (ATT&CK technique, etc.) to an event or attribute
Get organisation details
Generate a threat intelligence report from MISP data
Description
Cache feed data locally for correlation
Add a structured object (grouped attributes) to an event
List configured threat intel feeds
Get MISP version, permissions, and diagnostics
Network activity
Payload delivery
List available tags with usage statistics
List local and remote sharing partner organisations
Guided event creation from an incident description with IOC ingestion
Search IOCs across all events with type, category, and correlation filters
Get galaxy details with all clusters
Get template details with required/optional attributes
Category
Payload delivery
No
Discover events related through shared IOCs
Add or remove tags (TLP, MITRE ATT&CK, custom) from an event
Check if a value appears on known benign/false positive lists
Delete an object from an event
Trigger a fetch/pull from a feed
Description
Search clusters by keyword (find ATT&CK techniques, threat actors)
Enable or disable a feed
Delete a MISP event
Network activity
List sharing groups for controlled distribution
Network activity
Deep IOC investigation: search, correlate, check warninglists, summarize threat context
Payload delivery
Network activity
Payload delivery
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.