Osint MCP Server
UnclaimedOSINT intelligence MCP server for AI agents — 37 tools, 12 sources. Shodan, VirusTotal, Censys, SecurityTrails, DNS reconnaissance, WHOIS, certificate transparency, BGP routing, Wayback Machine, GeoIP. Automated open source intelligence and attack surface mapping via Model Context Protocol.
Install
npx osint-mcp-serverUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverTools (37)
bgp_asn
ASN details + all announced IPv4/IPv6 prefixes
bgp_ip
IP prefix/ASN routing lookup with RIR allocation
bgp_prefix
Prefix details + announcing ASNs
censys_certificates
Certificate search by domain, fingerprint, issuer
censys_host_details
Single host full details with all services
censys_hosts
Host search — IPs, services, ports, location, ASN
crtsh_search
Search CT logs via crt.sh — subdomain discovery + certificate details
dns_email_security
SPF + DMARC + DKIM analysis with risk scoring and recommendations
dns_lookup
Resolve A, AAAA, MX, TXT, NS, SOA, CNAME, SRV records
dns_reverse
Reverse DNS (PTR) lookup for an IP address
dns_spf_chain
Recursive SPF include chain resolution with service detection
dns_srv_discover
SRV + CNAME service discovery (Autodiscover, LDAP, SIP, Kerberos, etc.)
dns_wildcard_check
Wildcard DNS detection via random subdomain probe
geoip_batch
Batch IP geolocation (up to 100 IPs at once)
geoip_lookup
IP geolocation: country, city, ISP, ASN, proxy/hosting/VPN detection
hackertarget_aslookup
ASN information lookup
hackertarget_hostsearch
Host/subdomain discovery with resolved IPs
hackertarget_reverseip
Reverse IP lookup — find all domains on an IP
m365_tenant
Discover M365 tenant ID, region, and OpenID configuration
m365_userrealm
Detect auth type (Managed/Federated), federation brand, auth endpoints
osint_domain_recon
Quick recon combining all free sources (DNS + WHOIS + crt.sh + HackerTarget + email security)
osint_list_sources
List all OSINT sources, API key status, and tool counts
shodan_dns_resolve
Bulk hostname-to-IP resolution via Shodan
shodan_exploits
Search public exploit database (PoC, Metasploit modules)
shodan_host
IP details: open ports, services, banners, vulnerabilities, OS, ASN
shodan_search
Search Shodan query language (e.g. apache port:443 country:US)
st_dns_history
Historical DNS records with first/last seen dates
st_subdomains
Subdomain enumeration (returns FQDNs)
st_whois
Enhanced WHOIS with registrant/admin/technical contacts
vt_domain
Domain reputation, detection stats, categories, DNS records
vt_ip
IP reputation, detection stats, ASN, network
vt_subdomains
Subdomain enumeration via VirusTotal
vt_url
URL scan + malware/phishing analysis
wayback_snapshots
Snapshot history with timestamps and direct archive links
wayback_urls
Archived URL discovery — find old endpoints, hidden paths, removed content
whois_domain
RDAP domain lookup — registrar, dates, nameservers, contacts
whois_ip
RDAP IP lookup — network name, CIDR, country, entities