Skip to content

Releases: MISP/misp-galaxy-mcp

MISP galaxy MCP v1.0.0 release

Choose a tag to compare

@iglocska iglocska released this 13 Jul 07:58
v1.0.0
ed34579

misp-galaxy-mcp v1.0.0

First release of misp-galaxy-mcp — a lightweight Model Context Protocol (https://modelcontextprotocol.io) (MCP) server for searching the MISP galaxy
(https://github.com/MISP/MISP-galaxy) knowledge base.

Unlike misp-mcp (https://github.com/MISP/misp-mcp), which talks to a live MISP instance, this server runs entirely against the MISP-galaxy dataset
vendored as a git submodule — no MISP instance, API key, or network access required at runtime. Point an LLM at it to map free-text mentions of threat
actors, malware, techniques, sectors, and more to their canonical MISP galaxy tags (e.g. misp-galaxy:threat-actor="APT28").

Highlights

  • Keyword search across galaxy cluster names and synonyms, with an exact-first / substring-fallback strategy that keeps precise queries precise.
  • Metadata search over any meta key/value (country, sector, suspected victims, references, …).
  • Discovery tool so a client can learn the available galaxies and their metadata keys without guessing.
  • Ready-to-use tags — every match returns the misp-galaxy:{type}="{value}" tag you can apply directly to MISP events.
  • Local & offline — an in-memory index is built at startup over the full dataset (130+ galaxies, 55,000+ clusters at the pinned submodule revision).

Tools

search_galaxy_clusters(query, galaxy_type=None, limit=50)

Keyword search over each cluster's name (value) and its synonyms, using an exact-first waterfall: case-insensitive exact matches are returned when any
exist, otherwise it falls back to case-insensitive substring matches. This stops a precise query like apt1 from dragging in apt11/apt28, while a loose
query like apt still matches broadly. Descriptions are never searched.

search_galaxy_clusters_by_meta(key, value, galaxy_type=None, limit=50)

Search clusters by an arbitrary metadata key/value under values[].meta, using case-insensitive exact matching only (no substring fallback). A match on any
element of a list or nested metadata value counts.

list_galaxies(galaxy_type=None)

Discovery helper. With no argument, lists every galaxy (galaxy_type, galaxy_name, cluster_count). With a galaxy_type, it additionally returns the
meta_keys present on that galaxy's clusters — i.e. the valid keys for search_galaxy_clusters_by_meta.

All searches accept an optional galaxy_type filter and a limit, and return a { match_mode, count, truncated, results } envelope where each result is {
tag, galaxy_type, value, uuid }.

Install

  git clone --recurse-submodules https://github.com/MISP/misp-galaxy-mcp.git
  cd misp-galaxy-mcp
  pip install -e .        # or: uv pip install -e .
  Already cloned without submodules? Run git submodule update --init --recursive.

Configure

Claude Code:

  claude mcp add misp-galaxy -- misp-galaxy-mcp
  Any MCP client:
  {
    "mcpServers": {
      "misp-galaxy": { "command": "misp-galaxy-mcp" }
    } 
  }

Set the MISP_GALAXY_PATH environment variable to override the default MISP-galaxy/clusters data location.

Requirements

  • Python ≥ 3.10
  • stdio transport — works with Claude Code, Claude Desktop, and any MCP-compatible client