watchlist.add
Adds an entity to the analyst's watchlist to receive notifications when new intelligence mentions it.
How to use it
watchlist.add is exposed by the OPTIX MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the watchlist.add tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install OPTIX MCP
pip install -r requirements.txtOther tools in OPTIX MCP (39)
Returns your current OPTIX credit balance, monthly allocation, usage, reset date, and account context.
string
string
string
Retrieves the OPTIX MITRE ATT&CK coverage matrix — which techniques have been observed in intelligence data and which have detection rules.
integer
Fetches a specific intelligence document by its numeric OPTIX ID.
integer
string
Fetches a named threat intelligence entity (threat actor, malware, campaign, CVE, technique) by name or ID.
Returns profile-matched situational awareness threat cards showing active threats with observed TTPs and targeted sectors.
Returns a paginated stream of curated, scored intelligence documents from all OPTIX sources.
Returns AI-synthesised threat intelligence headlines summarising the most active current threats.
string[]
Returns enriched community context for an IOC including analyst vote tallies, co-occurring threat actors and malware, ATT&CK techniques, and source documents.
integer
integer
string
string
integer
string
Retrieves the full content of a specific intelligence report.
Lists generated intelligence reports (tactical, strategic, operational, technical, RFI) stored in OPTIX.
Full-text search across all OPTIX intelligence documents.
Searches OPTIX for a specific indicator of compromise (IOC) by value.
string
string
string
string
string
string
string
string
string
string
string
string
Lists all entities on the analyst's OPTIX watchlist.
Removes an entity from the analyst's watchlist.