Cortex Bridge
Connects MCP clients to Cortex, enabling threat intelligence analysis via tools consumable by large language models.
About
Acts as a bridge between Model Context Protocol (MCP) clients and a Cortex instance, allowing clients like large language models to leverage Cortex analyzers for threat intelligence. It exposes the analysis capabilities of Cortex as consumable tools, automating the process of enriching observables with data from various analyzers. This integration centralizes analysis, promotes extensibility through modular analyzers, and enhances security through API-key based access.
Key Features
- API-key based authentication.
- 1 GitHub stars
- Detailed logging.
- Configurable analyzer selection.
- Supports IP, URL, domain, and email analysis.
- Exposes Cortex analyzers as MCP tools.
Use Cases
- Automated threat intelligence analysis for LLMs.
- Enriching observables with threat data.
- Integrating Cortex with MCP-compatible security tools.