Threatintel MCP Server
by aplaceforallmystuffio.github.aplaceforallmystuff/mcp-threatintelv1.0.1
MCP server for unified threat intelligence - AlienVault OTX, AbuseIPDB, GreyNoise, and abuse.ch feeds
context tax
queued
security
queued
cold start
queued
freshness
Maintained2mo ago
Install Threatintel MCP server
Install in Claude Code
claude mcp add threatintel -e OTX_API_KEY='<otx-api-key>' -e ABUSEIPDB_API_KEY='<abuseipdb-api-key>' -e GREYNOISE_API_KEY='<greynoise-api-key>' -e ABUSECH_AUTH_KEY='<abusech-auth-key>' -- npx -y mcp-threatintel-serverInstall in Cursor
{
"mcpServers": {
"threatintel": {
"command": "npx",
"args": [
"-y",
"mcp-threatintel-server"
],
"env": {
"OTX_API_KEY": "<otx-api-key>",
"ABUSEIPDB_API_KEY": "<abuseipdb-api-key>",
"GREYNOISE_API_KEY": "<greynoise-api-key>",
"ABUSECH_AUTH_KEY": "<abusech-auth-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"threatintel": {
"command": "npx",
"args": [
"-y",
"mcp-threatintel-server"
],
"env": {
"OTX_API_KEY": "<otx-api-key>",
"ABUSEIPDB_API_KEY": "<abuseipdb-api-key>",
"GREYNOISE_API_KEY": "<greynoise-api-key>",
"ABUSECH_AUTH_KEY": "<abusech-auth-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"threatintel": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"mcp-threatintel-server"
],
"env": {
"OTX_API_KEY": "<otx-api-key>",
"ABUSEIPDB_API_KEY": "<abuseipdb-api-key>",
"GREYNOISE_API_KEY": "<greynoise-api-key>",
"ABUSECH_AUTH_KEY": "<abusech-auth-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"threatintel": {
"command": "npx",
"args": [
"-y",
"mcp-threatintel-server"
],
"env": {
"OTX_API_KEY": "<otx-api-key>",
"ABUSEIPDB_API_KEY": "<abuseipdb-api-key>",
"GREYNOISE_API_KEY": "<greynoise-api-key>",
"ABUSECH_AUTH_KEY": "<abusech-auth-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| OTX_API_KEY | — | yes | AlienVault OTX API key (free at otx.alienvault.com) |
| ABUSEIPDB_API_KEY | — | yes | AbuseIPDB API key (free at abuseipdb.com) |
| GREYNOISE_API_KEY | — | yes | GreyNoise API key (free at greynoise.io) |
| ABUSECH_AUTH_KEY | — | yes | abuse.ch Auth Key for URLhaus, MalwareBazaar, ThreatFox (free at auth.abuse.ch) |
Freshness
Maintained — last maintenance signal 2mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-08-09 · 2mo ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2025-11-28 · 11mo ago · official registry · v1.0.1
FAQ
›How do I install the Threatintel MCP server in Claude Code?
Run: claude mcp add threatintel -e OTX_API_KEY='<otx-api-key>' -e ABUSEIPDB_API_KEY='<abuseipdb-api-key>' -e GREYNOISE_API_KEY='<greynoise-api-key>' -e ABUSECH_AUTH_KEY='<abusech-auth-key>' -- npx -y mcp-threatintel-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Threatintel require an API key?
Yes. It expects OTX_API_KEY, ABUSEIPDB_API_KEY, GREYNOISE_API_KEY, ABUSECH_AUTH_KEY, of which 4 are secrets.
›Can I use Threatintel as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Threatintel in the official MCP registry?
Yes, as io.github.aplaceforallmystuff/mcp-threatintel.
Alternatives to Threatintel
Other security MCP servers.