security MCP Server
MCP server for MITRE ATT&CK knowledge base. Map alerts to techniques, profile threat groups, analyze detection gaps, and enrich SOC workflows with adversary intelligence.
Discovered via github-topic:mcp and last synced 2mo ago.
1. Install the package
npx mitre-mcp
2. Add to claude_desktop_config.json
{
"mcpServers": {
"mitre-mcp": {
"command": "npx",
"args": [
"mitre-mcp"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
List all known ATT&CK campaigns
Wazuh API password
Verify SSL certs (default: `true`, set `false` for self-signed)
Get group details including techniques and software used
Get all mitigations for a specific technique
Search campaigns by keyword or technique
Description
`~/.mitre-mcp/data`
`enterprise`
TheHive API key
Get current data version and object counts
List cases with ATT&CK technique filtering
List all tactics in kill-chain order
Search software by name, technique, or type (malware/tool)
Build a technique profile with group/software/campaign matching
Map Cortex analyzers to ATT&CK data sources
Connection status for all SOC integrations
Wazuh API URL (e.g., `https://wazuh.example.internal:55000`)
MISP URL (e.g., `https://misp.example.internal`)
Map security alerts to likely ATT&CK techniques
`86400`
Cortex URL (e.g., `http://cortex.example.internal:9001`)
Wazuh manager status, agents, and rule stats
Assist with threat attribution
Wazuh API username (default: `wazuh-wui`)
MISP API key (authkey)
Find technique overlap between groups for attribution
Verify SSL certs (default: `true`, set `false` for self-signed)
Search mitigations by keyword
Description
Enrich a TheHive case with ATT&CK techniques and mitigations
Search MISP IOCs by technique or group
Get full details of a technique by ID (T1059, T1059.001)
List all known threat groups
Force update of the local ATT&CK data cache
Generate ATT&CK Navigator JSON layers (coverage, group, campaign, diff)
Create a case pre-populated with ATT&CK context
Create events pre-tagged with ATT&CK techniques
Generate a threat hunting plan
Analyze Wazuh rules mapped to ATT&CK techniques
Search for techniques across Wazuh, TheHive, and MISP simultaneously
List events with ATT&CK enrichment
Perform detection gap analysis
Description
TheHive URL (e.g., `http://thehive.example.internal:9000`)
Search techniques by keyword, tactic, platform, data source
Get software details with techniques and associated groups
Get campaign details with techniques, software, and groups
Fetch recent alerts enriched with ATT&CK context
Map MISP event attributes/galaxies to ATT&CK
Map incident observables to ATT&CK techniques
Cortex API key
Get tactic details with all associated techniques
Get mitigation details with addressed techniques
Generate possible attack paths through the kill chain
Search groups by keyword or technique usage
Get data source details with detectable techniques
Map Wazuh alerts to ATT&CK techniques by rule ID/description/groups
Run analyzers on observables with ATT&CK context
Description
Analyze detection coverage based on available data sources
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.