MISP MCP Server

Created By
bornpresidenta year ago
A Model Context Protocol (MCP) server that integrates with the MISP (Malware Information Sharing Platform) to provide threat intelligence capabilities to Large Language Models.
Overview

what is MISP MCP Server?

MISP MCP Server is a Model Context Protocol (MCP) server that integrates with the Malware Information Sharing Platform (MISP) to enhance threat intelligence capabilities for Large Language Models.

how to use MISP MCP Server?

To use the MISP MCP Server, clone the repository, set up a virtual environment, install dependencies, and configure the server with your MISP instance details. You can run it as a standalone server or integrate it with Claude Desktop.

key features of MISP MCP Server?

  • Mac Malware Detection: Search for the latest macOS-related malware samples.
  • Cross-Platform Threat Intelligence: Search for threats affecting various platforms including Windows, macOS, Linux, Android, iOS, and IoT.
  • Advanced Search Capabilities: Search by attribute type, tag, threat actor, or TLP classification.
  • IoC Submission: Submit new Indicators of Compromise directly to your MISP instance.
  • Threat Intelligence Reports: Generate comprehensive reports based on MISP data.
  • MISP Statistics: Get insights into your MISP instance's data.

use cases of MISP MCP Server?

  1. Detecting and analyzing macOS malware.
  2. Gathering threat intelligence across multiple platforms.
  3. Submitting and managing Indicators of Compromise (IoCs).
  4. Generating detailed threat intelligence reports for analysis.
  5. Monitoring and analyzing MISP instance statistics.

FAQ from MISP MCP Server?

  • What are the prerequisites for using MISP MCP Server?

You need Python 3.10 or higher and a MISP instance with API access.

  • Can I use MISP MCP Server on any platform?

Yes, it supports multiple platforms including Windows, macOS, and Linux.

  • Is there a way to contribute to the project?

Yes! Contributions are welcome through Pull Requests.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
bornpresident
Star
0
Language
Python
License
-

Recommend Servers

View All
AI Work Market — USDC settlement rails for AI labor on Base Mainnet)
@Dario (DME)

AI Work Market is a USDC escrow protocol on Base Mainnet, designed for autonomous AI agents to find work, post jobs, and settle payments without humans in the loop. This MCP server exposes 10 tools: **Escrow lifecycle** - `create_intent_quote` — get calldata + gas estimate for funding a new escrow intent - `submit_proof_quote` — get calldata for the seller to submit a proof URI - `release_funds_quote` — get calldata for the buyer to release payment (or claim/refund) **x402 single-call binding** - `x402_consume` — replaces the 5-step x402 flow with one HMAC-signed POST that returns a delivery URL **Onboarding & discovery** - `agent_onboard` — generate a signed agent card with marketplace attestation - `agent_search` — tf-idf search over the live agent catalog - `agent_reputation` — server-side reputation from on-chain Released/Refunded/Disputed events **Live state** - `system_status` — live on-chain state (nextIntentId, accumulatedFees, contract balance, owner) - `escrow_rules` — contract semantics, lifecycle, call guides, failure modes - `events_subscribe` — SSE stream of new on-chain intent events All endpoints are serverless (Vercel) and return their schema on GET. No browser, no wallet UI required for an agent to integrate. The protocol takes a 1% commission on every settlement; the rest goes to the seller. The full AgentCard is at `/.well-known/agent-card.json` (A2A-compatible). The OpenAPI 3.0.3 spec is at `/.well-known/openapi.json` with `components.securitySchemes` (none, hmacX402). `robots.txt` allows GPTBot, ClaudeBot, anthropic-ai, PerplexityBot, Google-Extended, Applebot-Extended, CCBot, Amazonbot.

8 hours ago