{"repo":"zxzinn/opencti-mcp","free":true,"listed":false,"github":"https://github.com/zxzinn/opencti-mcp","clone":"git clone https://github.com/zxzinn/opencti-mcp.git","description":"MCP server for querying OpenCTI threat intelligence, indicators, reports, malware, and threat actors.","language":"TypeScript","stars":40,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"OpenCTI MCP Server Traditional Chinese (繁體中文) Overview OpenCTI MCP Server is a Model Context Protocol (MCP) server that provides seamless integration with OpenCTI (Open Cyber Threat Intelligence) platform. It enables querying and retrieving threat intelligence data through a standardized interface. Features - Fetch and search threat intelligence data - Get latest reports and search by ID - Search for malware information - Query indicators of compromise - Search for threat actors - User and group management - List all users and groups - Get user details by ID - STIX object operations - List attack patterns - Get campaign information by name - System management - List connectors - View status templates - File operations - List all files - Get file details by ID - Reference data access - List marking definitions - View available labels - Customizable query limits - Full GraphQL query support Prerequisites - Node.js 16 or higher - Access to an OpenCTI instance - OpenCTI API token Installation Installing via Smithery To install OpenCTI Server for Claude Desktop automatically via Smithery: Manual Installation Configuration Environment Variables Copy .env.example to .env and update with your OpenCTI credentials: Required environment variables: - OPENCTI URL : Your OpenCTI instance URL - OPENCTI TOKEN : Your OpenCTI API token MCP Settings Create a configuration file in your MCP settings location: Security Notes - Never commit .env file or API tokens to version control - Keep your Ope","default_branch":null,"files":null,"tree":[],"storefront":"/r/zxzinn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zxzinn/opencti-mcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}