MISP MCP Server

Created By
bornpresidenta year ago
A Model Context Protocol (MCP) server that integrates with the MISP (Malware Information Sharing Platform) to provide threat intelligence capabilities to Large Language Models.
Overview

what is MISP MCP Server?

MISP MCP Server is a Model Context Protocol (MCP) server that integrates with the Malware Information Sharing Platform (MISP) to enhance threat intelligence capabilities for Large Language Models.

how to use MISP MCP Server?

To use the MISP MCP Server, clone the repository, set up a virtual environment, install dependencies, and configure the server with your MISP instance details. You can run it as a standalone server or integrate it with Claude Desktop.

key features of MISP MCP Server?

  • Mac Malware Detection: Search for the latest macOS-related malware samples.
  • Cross-Platform Threat Intelligence: Search for threats affecting various platforms including Windows, macOS, Linux, Android, iOS, and IoT.
  • Advanced Search Capabilities: Search by attribute type, tag, threat actor, or TLP classification.
  • IoC Submission: Submit new Indicators of Compromise directly to your MISP instance.
  • Threat Intelligence Reports: Generate comprehensive reports based on MISP data.
  • MISP Statistics: Get insights into your MISP instance's data.

use cases of MISP MCP Server?

  1. Detecting and analyzing macOS malware.
  2. Gathering threat intelligence across multiple platforms.
  3. Submitting and managing Indicators of Compromise (IoCs).
  4. Generating detailed threat intelligence reports for analysis.
  5. Monitoring and analyzing MISP instance statistics.

FAQ from MISP MCP Server?

  • What are the prerequisites for using MISP MCP Server?

You need Python 3.10 or higher and a MISP instance with API access.

  • Can I use MISP MCP Server on any platform?

Yes, it supports multiple platforms including Windows, macOS, and Linux.

  • Is there a way to contribute to the project?

Yes! Contributions are welcome through Pull Requests.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
bornpresident
Star
0
Language
Python
License
-

Recommend Servers

View All
Tavily Mcp
@tavily-ai

JavaScript
a year ago
GovQL
@Alex Stout

# govql-mcp-server An MCP (Model Context Protocol) server for [GovQL](https://govql.us) — gives AI clients like Claude Desktop, Claude Code, and Cursor direct access to the US Congressional GraphQL API at [api.govql.us/graphql](https://api.govql.us/graphql) without bespoke HTTP wiring. For the design rationale (why FastMCP-Python, the passthrough+curated philosophy, roadmap through v0.4), see [design.md](https://github.com/govql/govql/blob/main/mcp-server/docs/design.md). ## What you can do with it Ask an agent questions like: - *"How did Vermont's two senators vote on the most recent nomination?"* - *"Which legislators in the 118th Congress switched parties during their service?"* - *"Compare Senator Sanders' voting record to Senator Murkowski's on cloture votes in the most recent Congress."* The agent picks the right tool, writes the GraphQL query against the live schema, and parses the response — no manual API wrangling. ## Install The server runs as a per-client subprocess over stdio. Pick your client: ### Claude Desktop Edit `claude_desktop_config.json` (Settings → Developer → Edit Config): ```json { "mcpServers": { "govql": { "command": "uvx", "args": ["govql-mcp-server"] } } } ``` Restart Claude Desktop. The `govql` tools appear in the tools panel. ### Claude Code Add to `.mcp.json` in your project (or `~/.mcp.json` for global): ```json { "mcpServers": { "govql": { "command": "uvx", "args": ["govql-mcp-server"] } } } ``` ### Cursor Settings → MCP → Add Server. Use the same `command` / `args` as above. ### Other clients Any MCP-compatible client that supports stdio servers will work. The command is `uvx govql-mcp-server` with no required arguments. ## Tools | Tool | Purpose | |---|---| | `execute_graphql` | Run any GraphQL query against the GovQL endpoint. Returns the result plus an `last_ingest` timestamp so the agent can reason about data freshness. | | `list_types` | Returns the names and kinds of every type in the GovQL schema. Optional `kind` filter (`"OBJECT"`, `"INPUT_OBJECT"`, `"ENUM"`, etc.) to narrow further. Start here when you don't know what's queryable. | | `describe_type` | Returns one type's full details — fields, arg signatures, input fields, enum values. Call after `list_types` to learn the shape of a specific type before writing a query. | ## Configuration All env vars are optional — the package is zero-config for end users. | Env var | Default | Purpose | |---|---|---| | `GOVQL_ENDPOINT` | `https://api.govql.us/graphql` | Endpoint to query. Override to point at a local dev stack. | | `GOVQL_TIMEOUT_MS` | `30000` | Per-request HTTP timeout. | | `LOG_LEVEL` | `INFO` | Logging level. Logs go to stderr only (stdout is reserved for the MCP transport). | ## Limits (enforced by the upstream API) - Max query depth: 10 - Max query complexity: ~10 billion points (`first: N` multiplies child cost by N — keep page sizes reasonable on deeply nested queries) - Rate limit: 100 requests / 60 s per source IP A depth or complexity violation surfaces as a GraphQL `errors` entry in the tool response so the agent can adjust and retry. ## Data freshness Every `execute_graphql` response includes a `last_ingest` ISO timestamp. Vote data refreshes hourly; legislator data refreshes daily. ## Status Version 0.1.0 ships three foundational tools: a GraphQL passthrough (`execute_graphql`) and two narrow schema-discovery tools (`list_types`, `describe_type`). Curated higher-level tools (`find_legislator`, `get_voting_record`, `compare_voters`, etc.) are planned for subsequent releases — see [design.md](https://github.com/govql/govql/blob/main/mcp-server/docs/design.md) for the roadmap. ## Links - [GovQL project site](https://govql.us) - [GraphQL API](https://api.govql.us/graphql) - [Source / issues](https://github.com/govql/govql)

2 days ago
Mercury X402 Mcp

20 hours ago