Complete AI Training

MCP server · Security

Cortex MCP server

by gbrigandi

Lets your AI check suspicious IPs, links, and files using your Cortex security tool.

Flow diagram: you ask your AI “Is 8.8.8.8 a suspicious IP? Check it with AbuseIPDB.”, the Cortex MCP server connects it to Cortex, and you get back A report in your chat.

This is a small helper program that connects your AI assistant to Cortex, a free security tool that checks whether an IP address, web link, or file looks dangerous. It is handy if you work in IT or security and already have Cortex running, because you can just ask your AI to look something up instead of clicking around the Cortex website.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to another app. This one connects your AI to your Cortex instance, so when you ask about a suspicious IP or link, the AI can send that question to Cortex and bring the answer back to you in the chat.

What this MCP server does

You ask your AI something like whether an IP address looks bad. The AI passes that to this helper program. The helper program talks to your Cortex instance, which runs an analyzer such as AbuseIPDB or VirusTotal on the item. Cortex does the actual checking and sends a report back. The helper hands that report to your AI, and your AI shows it to you in plain language.

Flow diagram: you ask your AI “Is 8.8.8.8 a suspicious IP? Check it with AbuseIPDB.”, the Cortex MCP server connects it to Cortex, and you get back A report in your chat. Click to zoom

What you can do with it

  • Check an IP address for a bad reputation using AbuseIPDB
  • Look up an IP, domain, URL, or email address with AbuseFinder
  • Scan a web link with VirusTotal
  • Analyze a web link with urlscan.io
  • Pick which Cortex analyzer to use for a request
  • Get a structured report back from Cortex in the chat

Try asking your AI

  • “Is 8.8.8.8 a suspicious IP? Check it with AbuseIPDB.”
  • “Use AbuseFinder to look up the domain example.com.”
  • “Scan this link with VirusTotal: http://suspicious-site.example”
  • “Analyze this URL with urlscan.io and tell me what it found.”

What it gives back to you

You get back the report from Cortex for the item you asked about, shown in the chat. That usually includes a summary of what the analyzer found, such as a reputation score, a list of warnings, or details about the domain or link. If the analyzer is not set up correctly, you will see an error message instead.

Before you start

What you need

  • A running Cortex instance that this server can reach over the network
  • A Cortex API key with permission to list analyzers and run jobs
  • The analyzers you want to use (like AbuseIPDB or VirusTotal) enabled and configured inside Cortex
  • The mcp-server-cortex program installed on your computer

Good to know

The tools only read and analyze data through your Cortex instance, but they need a working Cortex API key, and each analyzer may use its own paid or rate-limited service, so keep an eye on your analyzer settings.

Install it with your AI

Add Cortex MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check Cortex MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

IT and security people who already use Cortex and want to ask their AI assistant to check suspicious IPs, links, and domains.