Skip to content

v0.1.0

Latest

Choose a tag to compare

@magifd2 magifd2 released this 01 Sep 10:23
· 1 commit to main since this release

First release: threat context from Google Threat Intelligence as a CLI and a local MCP server, shipping the GTI Standard feature set (an untestable feature does not ship). Live-verified against the real API.

  • search (vulnerability catalogue) / search-iocs (GTI intelligence syntax)
  • threat with --related pivots and --mitre ATT&CK tree
  • ioc (hash/IP/domain/URL auto-detected) with association context
  • behaviour sandbox summary (index → paged sections)
  • hunting LiveHunt ruleset inspection (read-only, never cached)
  • MCP server with 12 tools, structured errors, response budgeting

Requires a commercial GTI licence key. See README for the tier notes.

🤖 Generated with Claude Code