Opencti MCP
UnclaimedMCP server for querying OpenCTI threat intelligence, indicators, reports, malware, and threat actors.
Install
npx -y @smithery/cli install opencti-server --client claudeSet up this server
More in Developer Tools
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
16 of 16 tools
Documented tools (16)
From project documentation. A server handshake does not verify each tool’s description or behavior.
get_campaign_by_name
Retrieves campaign information by name.
get_file_by_id
Retrieves file information by ID.
get_latest_reports
Retrieves the most recent threat intelligence reports.
get_report_by_id
Retrieves a specific report by its ID.
get_user_by_id
Retrieves user information by ID.
list_attack_patterns
Lists all attack patterns in the system.
list_connectors
Lists all system connectors.
list_files
Lists all files in the system.
list_groups
Lists all groups with their members.
list_labels
Lists all available labels.
list_marking_definitions
Lists all marking definitions.
list_status_templates
Lists all status templates.
list_users
Lists all users in the system.
search_indicators
Searches for indicators of compromise.
search_malware
Searches for malware information in the OpenCTI database.
search_threat_actors
Searches for threat actor information.
Tool change history
FAQ
Questions about Opencti MCP Server
- How do I connect Opencti MCP Server to Claude?
- The listing records `npx -y @smithery/cli install opencti-server --client claude` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop as compatible clients.
- Is Opencti MCP Server free?
- The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Opencti MCP Server do?
- Opencti MCP Server documents 16 tools to the agent, including get_campaign_by_name, get_file_by_id, get_latest_reports. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.