MITRE ATT&CK Mapper MCP
Enables cyber defenders to query ATT\&CK techniques, list tactics, map incidents to techniques, look up threat actor groups and mitigations, all via the MCP protocol.
README
MITRE ATT&CK Mapper MCP
Buy Starter — £29/mo
Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.
Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.
MITRE ATT&CK matrix lookup, tactic/technique/sub-technique mapper, and incident-to-technique correlation for cyber defenders.
Install
pip install mitre-attack-mcp
Tools
| Tool | Purpose |
|---|---|
query_technique |
Query ATT&CK technique by ID (Txxxx) or name |
list_tactics |
All 14 enterprise tactics (TA0001-TA0040+) |
map_incident |
Map incident IOCs/behaviors to ATT&CK techniques |
group_threat_actor |
Threat actor groups (G-codes) using a technique |
mitigation_lookup |
Mitigations (M-codes) for a technique |
Pairs with
meok-attestation-api— POST results to https://meok-attestation-api.vercel.app/sign for cryptographically signed compliance certsmeok-attestation-verify— public verification of any MEOK-signed cert- Other MEOK governance MCPs via SOV3
mcp_bridge_call
Pricing
- Free: 10 calls/day. No API key required.
- Pro £79/mo: unlimited + signed attestations. Subscribe
- Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai
Status
Scaffold v1.0.0 ships the MCP framework + 5 tool stubs. v1.1.0 will add real regulation data ingestion.
If your team needs this MCP fully-loaded faster, ping hello@meok.ai for sponsored development.
Wire it up — full stack
Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:
- bft-progress-council-mcp — anti-loop guardrail
- agent-token-budget-mcp — hard spend cap
- agent-prompt-injection-firewall-mcp — OWASP LLM01 scan
- agent-audit-logger-mcp — hash-chained evidence
- a2a-governance-bridge-mcp — fold N attestations → 1 signed event
- agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously
See meok.ai/mcp-stack for the architecture and meok.ai/mcp-stack/demo for the live in-browser demo.
License
MIT © MEOK AI Labs
<!-- mcp-name: io.github.CSOAI-ORG/mitre-attack-mcp -->
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.