MCP server Claude CodeCodexCursor +2
MCP server "huntable-cti-studio" as configured in dfirtnt/Huntable-CTI-Studio. Launched with bash scripts/run_mcp_server.sh.
6 tagged detection engineering, measured the same way as everything else here.
MCP server Claude CodeCodexCursor +2
MCP server "huntable-cti-studio" as configured in dfirtnt/Huntable-CTI-Studio. Launched with bash scripts/run_mcp_server.sh.
MCP server Claude CodeCodexCursor +2
MCP server "wrg-sigma-rules" as configured in WRG-11/wrg-sigma-rules. Runs ${CLAUDE_PLUGIN_ROOT}/server.py with python. Needs 1 environment variable to run.
badchars/living-off-the-land-lolbins-mcp-server
MCP server Claude CodeCodexCursor
Living off the Land binaries MCP server — GTFOBins, LOLBAS, LOOBins, LOLDrivers, LOLRMM, LOLESXi, LOTP, LOLC2, WADComs intelligence with attack graph reasoning, privilege escalation paths, defense evasion, detection engineering. Runs locally from the living-off-the-land-lolbins-mcp-server npm package.
threadlinqs-cmd/intelthreadlinqs-mcp
MCP server Claude CodeCodexCursor +2
MCP server for Threadlinqs Intelligence Platform — 81 tools, 25 prompts and 14 resources across threat intel, detections, IOCs, actors, C2, MITRE chains, correlations and Purple-tier composite intelligence. Runs locally from the intelthreadlinqs-mcp npm package. Needs 1 environment variable to run.
threadlinqs-cmd/intelthreadlinqs-mcp
MCP server Claude CodeCodexCursor +2
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs. Runs locally from the intelthreadlinqs-mcp npm package. Needs 2 environment variables to run.
ChristianPresley/threatintel-mcp
MCP server Claude CodeCodexCursor +2
MCP server "threatintel-mcp" as configured in ChristianPresley/threatintel-mcp. Runs locally from the threatintel-mcp Python package.