OpenCTI MCP Server

OpenCTI MCP Server

Enables AI assistants to query and manage OpenCTI threat intelligence data, including indicators, observables, reports, malware, and more, with read-only and optional write operations.

Category
访问服务器

README

OpenCTI MCP Server

Python versions License: MIT MCP CI

A Model Context Protocol server that exposes OpenCTI, the open-source threat-intelligence platform, to AI assistants. Built on the official pycti client, it registers 45 typed tools (91 when writes are enabled) across 15 threat-intel domains — indicators, observables, reports, malware, threat actors, intrusion sets, campaigns, attack patterns, tools, vulnerabilities, incidents, cases, relationships, identities, and labels/markings — plus platform/operations tools (connectors, users, groups, files), STIX bundle import/export, a graphql_query escape-hatch, and cross-cutting search/relationship/observable-lookup tools for anything the typed per-domain tools don't cover.

[!IMPORTANT] This is an unofficial, community-maintained project. It is not affiliated with, endorsed by, or supported by Filigran or the OpenCTI project.

[!WARNING] Ships read-only by default. With the default configuration, only list/get/query tools are registered and graphql_query rejects mutations. Setting OPENCTI_READ_ONLY=false exposes *_create, *_update, and the destructive *_delete tools, and lets graphql_query run mutations. Only enable writes with a least-privilege OpenCTI API token, and understand that an assistant with write access can create, modify, and permanently delete intelligence data in your instance.

Tools

Domain Reads Writes Notable tools
Indicators 2 3 indicators_list, indicators_get, indicators_create
Observables 2 3 observables_list, observables_get, observables_create
Reports 2 3 reports_list, reports_get, reports_create
Malware 2 3 malware_list, malware_get, malware_create
Threat actors 2 3 threat_actors_list, threat_actors_get, threat_actors_create
Intrusion sets 2 3 intrusion_sets_list, intrusion_sets_get, intrusion_sets_create
Campaigns 2 3 campaigns_list, campaigns_get, campaigns_create
Attack patterns 2 3 attack_patterns_list, attack_patterns_get, attack_patterns_create
Tools 2 3 tools_list, tools_get, tools_create
Vulnerabilities 2 3 vulnerabilities_list, vulnerabilities_get, vulnerabilities_create
Incidents 2 3 incidents_list, incidents_get, incidents_create
Cases 2 3 cases_list, cases_get, cases_create
Relationships 2 3 relationships_list, relationships_get, relationships_create
Identities 2 2 identities_list, identities_get, identities_create (organizations/individuals/systems/sectors), identities_delete
Labels & markings 4 3 labels_list, labels_create, markings_list, markings_get

Every domain also has an _update and _delete tool once writes are enabled (markings are read-only; identities has _create/_delete but no _update). In addition, graphql_query runs a raw GraphQL query/mutation against the OpenCTI API for anything not covered by a typed tool above — reads always work, mutations are rejected unless OPENCTI_READ_ONLY=false. See docs/ENDPOINTS.md for the full tool-to-pycti-call mapping.

Every *_list tool also accepts order_by (a field name, e.g. "created_at") and descending (default true), so order_by="created_at" gives most-recent-first without any extra filtering.

observables_create also accepts StixFile.* observable keys (normalized to File.*), coerces Autonomous-System.number values to an integer, and takes an optional additional_hashes param (a list of "ALGO:VALUE" entries, e.g. "SHA-1:...") to attach extra hashes to a file observable alongside the primary one.

Cross-cutting read tools

  • search_all(query, types?, first?) — full-text search across all STIX object types at once, optionally restricted to specific types.
  • relationships_for_entity(entity_id, relationship_type?, first?) — lists relationships touching an entity as either source or target, e.g. "what is related to X".
  • observables_by_value(value, first?) — exact-value lookup for an observable (IP, domain, URL, hash, etc.) without knowing its id.

Platform & operations

  • connectors_list / connectors_get(connector_id) — list connectors and check one's status/health (active, state, queue details).
  • users_list / users_get(id) — list/get OpenCTI users.
  • groups_list / groups_get(id) — list/get OpenCTI groups.
  • files_for_entity(entity_id) — list files/attachments on an entity.
  • stix_export_entity(entity_type, entity_id, mode?) / stix_export_list(entity_type, first=25, mode?) — export a single entity, or up to first entities of a type (max 500), as a STIX 2 bundle; large exports are capped by first, and if the bundle is still too large a small note (_note, entity_type, first, object_count) is returned instead.
  • stix_import_bundle(bundle_json, update?) — write, requires OPENCTI_READ_ONLY=false — bulk create/update entities and relationships from a STIX bundle.
  • entity_ask_enrichment(entity_id, connector_id) — write, requires OPENCTI_READ_ONLY=false — trigger a connector to enrich an entity.

Two related capabilities are intentionally not exposed as typed tools and remain available via graphql_query: OpenCTI status templates, and connector start/stop/reset (pycti exposes no dedicated method for either).

Bundled skill

A Claude Skill lives at skills/opencti-usage/ that teaches an AI agent OpenCTI's model — the STIX data model, entity types, indicators vs observables, relationships, containers, TLP markings, confidence, connectors, and RBAC — and maps each concept to the right MCP tool above. An agent operating the opencti tools loads this skill to understand the platform before creating, relating, or reasoning about OpenCTI data.

  • skills/opencti-usage/SKILL.md is the entry point; the references/ folder holds the per-topic detail.
  • The content is distilled from the official OpenCTI docs (docs.opencti.io/latest), distilled 2026-07-10. Each reference file has a ## Source link back to the docs it was drawn from, so it can be refreshed later.

Quick start

Install

git clone https://github.com/Space-C0wboy/OpenCTI-MCP-Server.git
cd OpenCTI-MCP-Server
uv venv
uv pip install -e ".[dev]"

Or with plain pip:

pip install -e .

Get an API token

In OpenCTI, open your profile menu → API access, then copy your personal access token.

Configuration

Configuration is read from environment variables, or from a .env file in the working directory (either a standard KEY=value dotenv file or a JSON-style fragment). OS environment variables always take precedence over the file.

Variable Required Default Description
OPENCTI_URL Yes — Base URL of your OpenCTI instance
OPENCTI_TOKEN Yes — OpenCTI API token
OPENCTI_READ_ONLY No true When true, hides all write tools and blocks mutations
OPENCTI_TIMEOUT No 30 Request timeout in seconds
OPENCTI_SSL_VERIFY No true Verify TLS certificates
LOG_LEVEL No INFO Logging verbosity
MCP_HTTP_HOST No 127.0.0.1 Bind host when using --transport http
MCP_HTTP_PORT No 8765 Bind port when using --transport http

Run

Stdio (default, for editor/IDE integrations):

uv run opencti-mcp

HTTP transport:

uv run opencti-mcp --transport http --host 127.0.0.1 --port 8765

Read-only mode

OPENCTI_READ_ONLY defaults to true. In read-only mode, only list/get tools and markings_list/markings_get are registered — no *_create, *_update, or *_delete tool is available for any domain, and graphql_query raises an error if the query document contains a mutation. Set OPENCTI_READ_ONLY=false to register the write tools and allow graphql_query to run mutations.

Editor integration

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "opencti": {
      "command": "uv",
      "args": ["--directory", "/absolute/path/to/OpenCTI-MCP-Server", "run", "opencti-mcp"],
      "env": {
        "OPENCTI_URL": "https://your-opencti-instance.example.com/",
        "OPENCTI_TOKEN": "your-api-token"
      }
    }
  }
}

Claude Code

claude mcp add opencti -- uv --directory /absolute/path/to/OpenCTI-MCP-Server run opencti-mcp

Example prompts

  • "List the 10 most recent indicators."
  • "Search reports mentioning 'Emotet'."
  • "Show me the MITRE ATT&CK technique T1059."
  • "Create an IPv4 observable for 1.2.3.4." (requires OPENCTI_READ_ONLY=false)
  • "Which threat actors are linked to intrusion set APT29?"
  • "Get the full detail on case CASE-ID, including its labels and markings."
  • "What are the 10 most recent reports?"
  • "Is 1.2.3.4 in OpenCTI?"
  • "What is this threat actor related to?"
  • "Search across everything for 'Emotet'."
  • "Are our OpenCTI connectors healthy?"
  • "Export this report as a STIX bundle."
  • "List the groups in OpenCTI."
  • "Add the victim organization 'Acme Corp' to OpenCTI." (requires OPENCTI_READ_ONLY=false)
  • "Create an individual identity for John Doe with a description."

Development

uv run pytest
uv run ruff check .

License

MIT — see LICENSE.

Support

This is a community-maintained project provided as-is, with no guaranteed support SLA. Issues and pull requests are welcome.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选