Developer Tools · Security

OpenCTI logo

OpenCTI

spathodea-network/opencti-mcp

OpenCTI MCP Server is a Model Context Protocol (MCP) server that provides seamless integration with OpenCTI (Open Cyber Threat Intelligence) platform. It enables querying and retrieving threat intelligence data through a standardized interface.

Install

npx -y @smithery/cli install opencti-server --client claude

Client configuration

{
  "mcpServers": {
    "opencti": {
      "command": "node",
      "args": [
        "<value>"
      ],
      "env": {
        "OPENCTI_URL": "<OPENCTI_URL>",
        "OPENCTI_TOKEN": "<OPENCTI_TOKEN>"
      }
    }
  }
}

Environment variables

OPENCTI_URLOPENCTI_TOKEN
GitHub stars
11
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

Features

  • Fetch and search threat intelligence data

  • User and group management

  • STIX object operations

  • System management

  • File operations

  • Reference data access

  • Customizable query limits

  • Full GraphQL query support

Tools (16)

  • get_latest_reports

    Retrieves the most recent threat intelligence reports.

  • get_report_by_id

    Retrieves a specific report by its ID.

  • search_malware

    Searches for malware information in the OpenCTI database.

  • search_indicators

    Searches for indicators of compromise.

  • search_threat_actors

    Searches for threat actor information.

  • get_user_by_id

    Retrieves user information by ID.

  • list_users

    Lists all users in the system.

  • list_groups

    Lists all groups with their members.

  • list_attack_patterns

    Lists all attack patterns in the system.

  • get_campaign_by_name

    Retrieves campaign information by name.

  • list_connectors

    Lists all system connectors.

  • list_status_templates

    Lists all status templates.

  • get_file_by_id

    Retrieves file information by ID.

  • list_files

    Lists all files in the system.

  • list_marking_definitions

    Lists all marking definitions.

  • list_labels

    Lists all available labels.

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools