This project is an MCP (Model Context Protocol) server for querying ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) techniques and
Most developer tooling work still happens through a UI a human drives. AttAck MCP server moves it into the conversation instead. This project is an MCP (Model Context Protocol) server for querying ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) techniques and tactics. It provides a way to access and retrieve information about various attack techniques.
Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.
The server publishes 3 tools. What each one is for:
Arguments — **Example — **server_info — ** 返回服务与数据集的版本、维护者和Git信息。Configuration is passed through the environment: ATTACK_MCP_MODE, ATTACK_MCP_HOST, ATTACK_MCP_PORT, ATTACK_MCP_LOG_LEVEL. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. AttAck's toolset — Arguments, Example, server_info — is a fair guide to whether it matches your workflow. It is maintained by alex-llm; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| Arguments | ** |
| Example | ** |
| server_info | ** 返回服务与数据集的版本、维护者和Git信息。 |
| Variable | Description | Required |
|---|---|---|
| ATTACK_MCP_MODE | Configuration value read at startup. | Optional |
| ATTACK_MCP_HOST | Endpoint or connection string the server talks to. | Optional |
| ATTACK_MCP_PORT | Configuration value read at startup. | Optional |
| ATTACK_MCP_LOG_LEVEL | Configuration value read at startup. | Optional |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.