Releases: MISP/misp-galaxy-mcp
Release list
MISP galaxy MCP v1.0.0 release
misp-galaxy-mcp v1.0.0
First release of misp-galaxy-mcp — a lightweight Model Context Protocol (https://modelcontextprotocol.io) (MCP) server for searching the MISP galaxy
(https://github.com/MISP/MISP-galaxy) knowledge base.
Unlike misp-mcp (https://github.com/MISP/misp-mcp), which talks to a live MISP instance, this server runs entirely against the MISP-galaxy dataset
vendored as a git submodule — no MISP instance, API key, or network access required at runtime. Point an LLM at it to map free-text mentions of threat
actors, malware, techniques, sectors, and more to their canonical MISP galaxy tags (e.g. misp-galaxy:threat-actor="APT28").
Highlights
- Keyword search across galaxy cluster names and synonyms, with an exact-first / substring-fallback strategy that keeps precise queries precise.
- Metadata search over any meta key/value (country, sector, suspected victims, references, …).
- Discovery tool so a client can learn the available galaxies and their metadata keys without guessing.
- Ready-to-use tags — every match returns the misp-galaxy:{type}="{value}" tag you can apply directly to MISP events.
- Local & offline — an in-memory index is built at startup over the full dataset (130+ galaxies, 55,000+ clusters at the pinned submodule revision).
Tools
search_galaxy_clusters(query, galaxy_type=None, limit=50)
Keyword search over each cluster's name (value) and its synonyms, using an exact-first waterfall: case-insensitive exact matches are returned when any
exist, otherwise it falls back to case-insensitive substring matches. This stops a precise query like apt1 from dragging in apt11/apt28, while a loose
query like apt still matches broadly. Descriptions are never searched.
search_galaxy_clusters_by_meta(key, value, galaxy_type=None, limit=50)
Search clusters by an arbitrary metadata key/value under values[].meta, using case-insensitive exact matching only (no substring fallback). A match on any
element of a list or nested metadata value counts.
list_galaxies(galaxy_type=None)
Discovery helper. With no argument, lists every galaxy (galaxy_type, galaxy_name, cluster_count). With a galaxy_type, it additionally returns the
meta_keys present on that galaxy's clusters — i.e. the valid keys for search_galaxy_clusters_by_meta.
All searches accept an optional galaxy_type filter and a limit, and return a { match_mode, count, truncated, results } envelope where each result is {
tag, galaxy_type, value, uuid }.
Install
git clone --recurse-submodules https://github.com/MISP/misp-galaxy-mcp.git
cd misp-galaxy-mcp
pip install -e . # or: uv pip install -e .
Already cloned without submodules? Run git submodule update --init --recursive.
Configure
Claude Code:
claude mcp add misp-galaxy -- misp-galaxy-mcp
Any MCP client:
{
"mcpServers": {
"misp-galaxy": { "command": "misp-galaxy-mcp" }
}
}
Set the MISP_GALAXY_PATH environment variable to override the default MISP-galaxy/clusters data location.
Requirements
- Python ≥ 3.10
- stdio transport — works with Claude Code, Claude Desktop, and any MCP-compatible client