MCP server · Security
MISP MCP server
by ppcvote
Lets your AI look up threat intel in MISP, like events, tags and indicators, safely.

This is a small helper that connects your AI assistant to MISP, a platform many security teams use to store threat intelligence. Once it is set up, you can ask your AI questions about events, indicators and tags in plain English. It is handy for security analysts, incident responders and anyone who already works with MISP and wants faster answers.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you using what it already knows. An MCP server is a small helper program that gives your AI a new skill, in this case the ability to talk to your MISP instance. When you ask a question, your AI passes it to this helper, the helper asks MISP, and the answer comes back into your chat. This particular helper is read-only, so it can look things up but never change anything in MISP.
What this MCP server does
You ask your AI something like which events were tagged tlp:white this week. The AI sends that request to this helper, and the helper asks your MISP server through its normal interface. MISP sends back the matching events, attributes, tags, feeds or galaxies. Before showing anything to your AI, the helper scans the response for hidden prompt-injection tricks and blocks anything risky. Then your AI turns the result into a readable answer in the chat.
Click to zoomWhat you can do with it
- List MISP events, with paging, so you can browse what is there
- Open a single event and see all its attributes
- Search events by tag, type, value or date range
- Look up a specific indicator like an IP address or a file hash
- List all tags your MISP instance uses, including TLP tags
- See which threat intel feeds are configured
- Browse threat actor and campaign galaxies
Try asking your AI
- “What MISP events are tagged tlp:white from the last 7 days?”
- “Show me event 12345, I am investigating a phishing report.”
- “What threat actor galaxies do we have configured?”
- “Find all attributes matching the IP 198.51.100.42.”
What it gives back to you
You get back plain answers in the chat: lists of events with their titles, dates and tags, or a single event with all its attributes laid out. Searches come back as matching indicators with the event they belong to. If a response contains something suspicious, the helper replaces it with a short safe summary instead of the raw text.
Before you start
What you need
- A MISP account with access to your organisation's MISP instance
- A MISP API key (a kind of password for apps; you create one in your MISP profile under Auth Keys)
- The web address of your MISP instance, like https://misp.example.com
- An MCP client such as Claude Desktop, Cursor, Continue or Cline
Good to know
It can read whatever your MISP API key can see, so use a key scoped to what you are comfortable sharing with your AI, and remember the server is read-only so it will not change anything in MISP.
Install it with your AI
Add MISP MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check MISP MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Security analysts, incident responders and threat intel teams who already use MISP and want to ask questions in plain English instead of clicking through the interface.





