Releases: MISP/misp-mcp
Releases · MISP/misp-mcp
Release list
MISP MCP v0.1
v0.1.0 — Initial release
The first release of MISP MCP Server, a Model Context Protocol
server that gives LLM assistants (Claude Desktop, Claude Code, and any other MCP
client) read-only access to a MISP threat intelligence instance.
The server connects to MISP through PyMISP and
exposes MISP's search and retrieval surface as MCP tools. No tool can create,
modify, or delete data — access is strictly read-only.
If you are looking for an MCP server to utilise the galaxy repository, head over to misp-galaxy-mcp
Highlights
- 14 tools covering the core MISP data model: events, attributes, objects,
tags, taxonomies, galaxies, and feeds. - Zero-write guarantee — every tool is a search or a get; the server never
mutates the MISP instance. - Simple configuration via three environment variables.
- Ships as a console script (
misp-mcp) that speaks MCP over stdio.
Available tools
Events & Attributes
search_events— search events by IOC value, tag, date, or organisationsearch_attributes— search individual attributes / indicators of compromisesearch_objects— search MISP objects (grouped attributes)search_event_index— lightweight event metadata browsingget_event— fetch a full event by IDget_attribute— fetch an attribute by IDget_object— fetch an object by ID
Tags & Taxonomies
search_tags— search tags by namelist_taxonomies— list all taxonomy vocabularies (TLP, kill chain, etc.)get_taxonomy— get a taxonomy's details and entries
Galaxies
search_galaxies— search galaxies (threat actors, malware, ATT&CK techniques, …)get_galaxy— get a galaxy with its clusterssearch_galaxy_clusters— search within a specific galaxy
Feeds
search_feeds— list / search configured threat intelligence feeds
Configuration
| Variable | Required | Description |
|---|---|---|
MISP_URL |
Yes | URL of your MISP instance (e.g. https://misp.example.com) |
MISP_API_KEY |
Yes | MISP API authentication key |
MISP_VERIFYCERT |
No | Verify TLS certificates (default: true) |
Installation
pip install misp-mcpOr from source:
cd misp-mcp
pip install -e .Requirements
- Python 3.10+
mcp[cli]>= 1.0.0pymisp>= 2.5.0- A reachable MISP instance and a valid API key
Notes
- Licensed under AGPL-3.0-or-later, matching MISP.
- See
README.mdfor MCP client configuration examples anddocs/for
installation and usage guides.