MCP Server
Secure AI for Threat Intelligence
Threat Intelligence MCP Server
Connect AI tools and LLMs directly to Malware Patrol’s current threat intelligence using the Model Context Protocol (MCP).
The Malware Patrol MCP Server gives analysts, security teams, and AI workflows natural-language access to curated intelligence on threat actors, campaigns, indicators of compromise (IOCs), MITRE ATT&CK TTPs, vulnerabilities, and related security research.
Instead of relying solely on an LLM’s existing knowledge, your AI tools can query Malware Patrol for relevant threat context when they need it. Intelligence is continuously updated and derived from Malware Patrol research and trusted cybersecurity sources.
Available intelligence includes:
- Threat actor profiles, aliases, motivations, targets, tools, and techniques
- Associated IP addresses, hashes, email addresses, and cryptocurrency addresses
- MITRE ATT&CK TTPs
- CVEs and related vulnerability context
- Supporting cybersecurity research and source material
How Does It Work?
Configure your MCP-compatible AI tool or agent with the Malware Patrol MCP endpoint and your API key. The tool can then securely query our intelligence as part of natural-language conversations, investigations, enrichment workflows, and automated processes.
The MCP Server is hosted and maintained by Malware Patrol, so there is no server infrastructure to deploy or manage.
Built for Security Teams and Developers
SOC and threat intelligence teams can use the MCP Server to investigate threats, enrich indicators, research threat actors, and explore relationships between intelligence. Developers and AI engineers can use it as a threat intelligence source for agents, internal applications, and automated security workflows.
Works With MCP-Compatible Tools
Because the service uses the open Model Context Protocol, Malware Patrol intelligence can be accessed by compatible LLM applications, AI agents, development environments, and security workflows.
What You Can Ask: Real-World Use Cases and Queries
Below are examples of the types of queries supported by our MCP Server, organized by role and use case. SOCs can use these to accelerate investigations, correlate indicators, and surface connections that might otherwise take hours to uncover. The same data can also be used to generate threat actor profiles, summaries, and reports suitable for management and board-level briefings. All intelligence served through the MCP is curated and continuously updated by our team to ensure accuracy, relevance, and consistency across use cases.
SOC Analysts and Threat Researchers
Use the MCP Server to accelerate investigations and enrich ongoing monitoring with up-to-date threat context.
- What is the profile or summary of APT29, including aliases, tactics, and timeline?
- List all known IPs and hashes related to APT41 and OceanLotus.
- Which actors use Cobalt Strike and target government institutions?
- Get the latest IOCs associated with APT41.
- Which threat actors are known to be currently active?
Threat Hunting and Attribution
Correlate campaigns, shared infrastructure, and overlapping tools to uncover links between threat actors.
- Which TTPs are shared by Turla and Cozy Bear?
- Has APT33 ever used the same malware as APT34?
- Are Bronze Butler and APT10 the same threat actor?
- Any there any infrastructure overlaps between Wizard Spider and APT29?
- Considering APT15 and APT35, what CVEs do they use in common?
- Provide CWE, CAPEC and DEFEND information on CVE-2025-23366.
CISOs and Report Authors
Generate executive-level summaries and track trends across campaigns and threat actor activity.
- Who are the most active threat actors at the moment?
- Summarize campaigns tied to UNC2452 and APT29.
- What sectors are most frequently targeted by FIN7?
- Show all significant changes in behavior for the Lazarus Group over time.
Incident Responders
Quickly attribute activity and validate indicators during investigations and containment.
- Which actor is associated with the hash ab09f6a249ca88d1a036eee7a02cdd16?
- Are these IPs linked to any known threat activity: 139.59.60.116, 172.105.114.27?
- Are there crypto addresses related to Lazarus Group?
- What threat actors are known to use the crypto address 1HvEZ1jZ7BWgBYPxqCvWtKja3a9hsNa9Eh?
- What are mitigation strategies for T1134.001?
Malware and Detection Analysts
Identify malware families, tools, and TTPs associated with known adversaries for better detection engineering.
- What malware family is associated with MuddyWater?
- Show email addresses linked to APT41.
- Please provide information on the MITRE ATT&CK technique T1111.
- What threat actors are known to exploit CVE-2025-7775?
- Retrieve file hashes related to Gamaredon Group.
- What are defense strategies for T1102?
Geopolitical and Strategic Intelligence Teams
Assess actor motivations, targeting, and alignment with regional or global developments.
- What regions are targeted by TA505?
- Where is Charming Kitten based, and what are its motivations?
- Has Scattered Spider shifted its target geography recently?
- Which threat actors have information theft as their motivation?
- What is the timeline of known activities for Nobelium?
Video Guide: Connecting and Running Your First Query
This short video demonstrates how to connect to our MCP Server using the API key provided by Malware Patrol. The example uses Witsy, a lightweight interface that lets you interact with models and MCP tools without additional setup. Witsy is one of several available MCP-compatible clients, sometimes referred to as model interfaces or AI connectors, that can be used to run queries, test integrations, or explore results. You can use any tool that supports the MCP protocol in a similar way; many open-source and commercial options are available depending on your workflow and environment.
Learn More
Empower your AI with real-time, actionable threat intelligence. Our MCP Server is built, supported, and maintained by Malware Patrol, a trusted provider with deep expertise in cyber threat intelligence. That means you gain a strategic partner committed to keeping the LLM sharp, relevant, and secure.
Interested? Contact us to discuss.
Frequently Asked Questions (FAQ)
Do I need to install the MCP on my computer?
No, Malware Patrol’s MCP server runs remotely on our infrastructure. All you need to do is point your AI-enabled tool to our MCP server address.
Why a remote MCP server?
Remote MCP servers are a more secure and easier way to use MCP. All you need is to copy & paste the server URL; it is not necessary to install any NPM packages. Remote MCPs are the only ones that can be used with web based clients.
Why isn’t my LLM using your MCP?
This is a common issue because the LLM ‘decides’ whether or not to call on an MCP to gather information. We can, however, remind the LLM to do so. Simply append the following text to your question: “Use external tools.”
Note: Not all tools show “MCP command” when they are connecting to a remote server. Check your specific client for details about how to determine what is being used to answer your query.
For a detailed and technical troubleshooting guide, this article discusses the discrepancies that can occur when an LLM doesn’t properly interpret or prioritize external data sources such as MCP outputs. It outlines several steps you can take to troubleshoot, including verifying your tool’s configuration, checking model context limits, and ensuring your MCP data connection is correctly initialized.
If you’ve followed these steps and still think the LLM is not using the MCP server, we’d like to hear from you.
What should I do if I think information returned by my AI-enabled tool + your MCP isn’t accurate?
Please contact our support team with the following information so we can determine whether the issue originates in your setup or on our server side:
- The name and version of your AI-enabled tool
- The name and version of the LLM you’re using
- The complete query, including both question and answer
- A note describing what you believe isn’t accurate.
Our team will review the details to help identify and resolve the problem.