OpenCTI Server icon

OpenCTI Server

Enables querying and retrieving threat intelligence data from an OpenCTI platform through a standardized Model Context Protocol (MCP) interface.

About

OpenCTI Server is a Model Context Protocol (MCP) server designed to provide seamless integration with the OpenCTI (Open Cyber Threat Intelligence) platform. It serves as a bridge, allowing users to efficiently query and retrieve threat intelligence data through a standardized interface. With OpenCTI Server, you can access the latest reports, search for malware and threat actors, query indicators of compromise, and manage users and groups within your OpenCTI environment, all while leveraging full GraphQL query support and customizable query limits.

Key Features

  • Fetch and search threat intelligence data
  • User and group management
  • STIX object operations
  • System management tools
  • File operations
  • Reference data access
  • Full GraphQL query support

Use Cases

  • Incident response
  • Threat intelligence analysis
  • Security operations automation