MCPMarket
Sell SkillsPower Your AgentsConnect
  1. Home
  2. Servers
  3. Threat Hunting

Threat Hunting

THORCollectivebyTHORCollective
•
17
•
Data Science & ML
Analytics & Monitoring
Security & Testing

Provides a production-ready Model Context Protocol server for threat hunting knowledge base systems, integrating PEAK, SQRRL, and intelligence-driven methodologies.

Related MCPs

View more
  • datawiz168

    Snowflake Integration

    Enables Claude to execute SQL queries and interact with Snowflake databases.

  • tinybirdco

    Tinybird

    Connects to a Tinybird Workspace and interacts with data sources and API endpoints using the Model Context Protocol.

  • ThetaBird

    Axiom

    Enables AI agents to query data stored in Axiom using the Axiom Processing Language (APL).

Related Skills

View all
  • openclaw

    Diagram Maker & Visualizer

    Generates professional SVG, HTML, and Excalidraw diagrams for software architecture, system flows, and educational concepts.

  • openclaw

    GH Issues Auto-Fixer

    Automates the end-to-end GitHub issue lifecycle by spawning sub-agents to implement code fixes, open pull requests, and resolve review comments.

  • openclaw

    Discord Integration

    Manages Discord operations including messaging, reactions, and channel management directly through Claude.

MCPMarket

Discover MCP servers that connect MCP clients like Claude and Cursor to your favorite tools. Browse the MCP Market to get started.

Browse

  • MCP Search
  • MCP Servers
  • MCP Clients
  • Agent Skills
  • MCP Market Hub
  • Categories
  • What is an MCP server?
  • Model Context Protocol

Rankings

  • Top MCPs Today
  • Top Agent Skills Today
  • Top 100 Agent Skills
  • Top 100 MCP Servers

About

  • News
  • Submit
  • Contact

© 2026 MCP Market. All rights reserved.·Privacy·Terms

The Threat Hunting server is a robust Model Context Protocol (MCP) solution designed to empower security teams with advanced threat hunting capabilities. It seamlessly integrates leading methodologies like PEAK, SQRRL, and intelligence-driven approaches. Featuring natural language processing to convert queries into executable hunts, the server connects with Atlassian for knowledge management and Splunk for sophisticated query execution and machine learning analysis. It leverages the MITRE ATT&CK framework for comprehensive threat intelligence and includes robust security controls such as JWT authentication, data encryption, and audit logging, all optimized for performance with Redis-based caching.

Key Features

01Supports multiple threat hunting frameworks: PEAK, SQRRL, and Intelligence-driven
02Converts natural language queries into executable threat hunts using NLP
03Executes sophisticated hunting queries and ML analysis via Splunk SDK
04Leverages MITRE ATT&CK framework for comprehensive threat intelligence
05Seamless integration with Atlassian (Confluence, Jira) for knowledge management
060 GitHub stars

Use Cases

01Establishing baselines for normal system behavior to detect anomalies
02Performing intelligence-driven threat actor analysis and mapping to MITRE ATT&CK
03Automating threat hunt execution from natural language queries