MISP MCP Server

MISP MCP Server

Provides read-only access to MISP threat intelligence data, enabling event and attribute search, tag and taxonomy browsing, and galaxy lookups through natural language.

Category
Visit Server

README

MISP MCP Server

An MCP server that provides read-only access to MISP threat intelligence data.

Features

  • Event search - Find threat intelligence events by IOC values, tags, dates, organisations
  • Attribute search - Search individual indicators of compromise across all events
  • Object search - Find grouped attributes (file objects, network connections, etc.)
  • Event index - Lightweight event metadata browsing
  • Tags & Taxonomies - Search tags and browse taxonomy vocabularies (TLP, kill chain, etc.)
  • Galaxies - Search threat actors, malware, ATT&CK techniques, and other knowledge bases
  • Feeds - Browse configured threat intelligence feeds

All access is read-only - no data modification is possible through this server.

Installation

pip install misp-mcp

Or install from source:

cd misp-mcp
pip install -e .

Configuration

Set the following environment variables:

Variable Required Description
MISP_URL Yes URL of your MISP instance (e.g. https://misp.example.com)
MISP_API_KEY Yes Your MISP API authentication key
MISP_VERIFYCERT No Verify TLS certificates (default: true)

Usage

Claude Desktop / Claude Code

Add to your MCP configuration:

{
  "mcpServers": {
    "misp": {
      "command": "misp-mcp",
      "env": {
        "MISP_URL": "https://misp.example.com",
        "MISP_API_KEY": "your-api-key-here"
      }
    }
  }
}

Standalone (stdio)

export MISP_URL="https://misp.example.com"
export MISP_API_KEY="your-api-key"
misp-mcp

Available Tools

Events & Attributes

  • search_events - Search events by IOC values, tags, dates, organisations
  • search_attributes - Search individual attributes/indicators
  • search_objects - Search MISP objects
  • search_event_index - Lightweight event metadata search
  • get_event - Get full event by ID
  • get_attribute - Get attribute by ID
  • get_object - Get object by ID

Tags & Taxonomies

  • search_tags - Search tags by name
  • list_taxonomies - List all taxonomy vocabularies
  • get_taxonomy - Get taxonomy details and entries

Galaxies

  • search_galaxies - Search galaxies (threat actors, malware, ATT&CK, etc.)
  • get_galaxy - Get galaxy with clusters
  • search_galaxy_clusters - Search within a specific galaxy

Feeds

  • search_feeds - Search/list configured threat intelligence feeds

License

AGPL-3.0-or-later - same as MISP.

Copyright (C) 2026 Andras Iklody

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured