Skip to content

Releases: MISP/misp-mcp

Release list

MISP MCP v0.1

Choose a tag to compare

@iglocska iglocska released this 13 Jul 08:52
v0.1
745ce9a

v0.1.0 — Initial release

The first release of MISP MCP Server, a Model Context Protocol
server that gives LLM assistants (Claude Desktop, Claude Code, and any other MCP
client) read-only access to a MISP threat intelligence instance.

The server connects to MISP through PyMISP and
exposes MISP's search and retrieval surface as MCP tools. No tool can create,
modify, or delete data — access is strictly read-only.

If you are looking for an MCP server to utilise the galaxy repository, head over to misp-galaxy-mcp

Highlights

  • 14 tools covering the core MISP data model: events, attributes, objects,
    tags, taxonomies, galaxies, and feeds.
  • Zero-write guarantee — every tool is a search or a get; the server never
    mutates the MISP instance.
  • Simple configuration via three environment variables.
  • Ships as a console script (misp-mcp) that speaks MCP over stdio.

Available tools

Events & Attributes

  • search_events — search events by IOC value, tag, date, or organisation
  • search_attributes — search individual attributes / indicators of compromise
  • search_objects — search MISP objects (grouped attributes)
  • search_event_index — lightweight event metadata browsing
  • get_event — fetch a full event by ID
  • get_attribute — fetch an attribute by ID
  • get_object — fetch an object by ID

Tags & Taxonomies

  • search_tags — search tags by name
  • list_taxonomies — list all taxonomy vocabularies (TLP, kill chain, etc.)
  • get_taxonomy — get a taxonomy's details and entries

Galaxies

  • search_galaxies — search galaxies (threat actors, malware, ATT&CK techniques, …)
  • get_galaxy — get a galaxy with its clusters
  • search_galaxy_clusters — search within a specific galaxy

Feeds

  • search_feeds — list / search configured threat intelligence feeds

Configuration

Variable Required Description
MISP_URL Yes URL of your MISP instance (e.g. https://misp.example.com)
MISP_API_KEY Yes MISP API authentication key
MISP_VERIFYCERT No Verify TLS certificates (default: true)

Installation

pip install misp-mcp

Or from source:

cd misp-mcp
pip install -e .

Requirements

  • Python 3.10+
  • mcp[cli] >= 1.0.0
  • pymisp >= 2.5.0
  • A reachable MISP instance and a valid API key

Notes

  • Licensed under AGPL-3.0-or-later, matching MISP.
  • See README.md for MCP client configuration examples and docs/ for
    installation and usage guides.