MCPVault

Osint MCP Server

Unclaimed

by badchars

OSINT intelligence MCP server for AI agents — 37 tools, 12 sources. Shodan, VirusTotal, Censys, SecurityTrails, DNS reconnaissance, WHOIS, certificate transparency, BGP routing, Wayback Machine, GeoIP. Automated open source intelligence and attack surface mapping via Model Context Protocol.

Install

$npx osint-mcp-server

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Tools (37)

bgp_asn

ASN details + all announced IPv4/IPv6 prefixes

bgp_ip

IP prefix/ASN routing lookup with RIR allocation

bgp_prefix

Prefix details + announcing ASNs

censys_certificates

Certificate search by domain, fingerprint, issuer

censys_host_details

Single host full details with all services

censys_hosts

Host search — IPs, services, ports, location, ASN

crtsh_search

Search CT logs via crt.sh — subdomain discovery + certificate details

dns_email_security

SPF + DMARC + DKIM analysis with risk scoring and recommendations

dns_lookup

Resolve A, AAAA, MX, TXT, NS, SOA, CNAME, SRV records

dns_reverse

Reverse DNS (PTR) lookup for an IP address

dns_spf_chain

Recursive SPF include chain resolution with service detection

dns_srv_discover

SRV + CNAME service discovery (Autodiscover, LDAP, SIP, Kerberos, etc.)

dns_wildcard_check

Wildcard DNS detection via random subdomain probe

geoip_batch

Batch IP geolocation (up to 100 IPs at once)

geoip_lookup

IP geolocation: country, city, ISP, ASN, proxy/hosting/VPN detection

hackertarget_aslookup

ASN information lookup

hackertarget_hostsearch

Host/subdomain discovery with resolved IPs

hackertarget_reverseip

Reverse IP lookup — find all domains on an IP

m365_tenant

Discover M365 tenant ID, region, and OpenID configuration

m365_userrealm

Detect auth type (Managed/Federated), federation brand, auth endpoints

osint_domain_recon

Quick recon combining all free sources (DNS + WHOIS + crt.sh + HackerTarget + email security)

osint_list_sources

List all OSINT sources, API key status, and tool counts

shodan_dns_resolve

Bulk hostname-to-IP resolution via Shodan

shodan_exploits

Search public exploit database (PoC, Metasploit modules)

shodan_host

IP details: open ports, services, banners, vulnerabilities, OS, ASN

shodan_search

Search Shodan query language (e.g. apache port:443 country:US)

st_dns_history

Historical DNS records with first/last seen dates

st_subdomains

Subdomain enumeration (returns FQDNs)

st_whois

Enhanced WHOIS with registrant/admin/technical contacts

vt_domain

Domain reputation, detection stats, categories, DNS records

vt_ip

IP reputation, detection stats, ASN, network

vt_subdomains

Subdomain enumeration via VirusTotal

vt_url

URL scan + malware/phishing analysis

wayback_snapshots

Snapshot history with timestamps and direct archive links

wayback_urls

Archived URL discovery — find old endpoints, hidden paths, removed content

whois_domain

RDAP domain lookup — registrar, dates, nameservers, contacts

whois_ip

RDAP IP lookup — network name, CIDR, country, entities