Cybersecurity Threat Intelligence MCP Server

CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.

Local serverstdio

What is the Cybersecurity Threat Intelligence MCP MCP server?

Connect Cybersecurity Threat Intelligence MCP to Claude, Cursor or any other MCP client and it stops being a tab you switch to. CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed. The cybersecurity threat intelligence mcp mcp server is what makes that connection.

What the server does

Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the probability it'll be exploited) and a CISA KEV flag (whether it's actively exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood — so an agent triaging a dependency sees what actually matters first.

Available tools

The toolset is worth reading before you wire it up, because it tells you what the integration is really for:

  • search_cve — $0.01
  • cve_detailfree
  • check_ip — $0.01
  • check_domain — $0.01
  • vulnerability_scan — $0.05
  • threat_feed — $0.01
  • brief_summary — $0.50
  • daily_brief — $15
  • mint_infofree

Installation

Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client. The configuration blocks on this page cover the common clients.

Where it fits

Plenty of database access servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Cybersecurity Threat Intelligence MCP's toolset — search_cve, cve_detail, check_ip and 6 more — is a fair guide to whether it matches your workflow. It is maintained by FoundryNet; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 9 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Cybersecurity Threat Intelligence MCP.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Available tools

ToolWhat it does
search_cve$0.01
cve_detail**free**
check_ip$0.01
check_domain$0.01
vulnerability_scan$0.05
threat_feed$0.01
brief_summary$0.50
daily_brief$15
mint_info**free**

How to install the Cybersecurity Threat Intelligence MCP MCP server

```json
{ "mcpServers": { "cyber-intel": { "url": "https://cyber-intel-mcp-production.up.railway.app/mcp" } } }

Configuration as documented by the project. Restart the client after saving.

Example prompts to try

  • Use Cybersecurity Threat Intelligence MCP to search cve.
  • Use Cybersecurity Threat Intelligence MCP to cve detail.
  • Use Cybersecurity Threat Intelligence MCP to check ip.

Frequently asked questions

It connects Cybersecurity Threat Intelligence MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 9 tools (search_cve, cve_detail, check_ip, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Cybersecurity Threat Intelligence MCP directly.