Skip to content

Complete MCP Tools

OSINT Tools

ToolParametersDescription
virustotal_ip_lookupip: strIP reputation, AV detections, associated domains
virustotal_domain_lookupdomain: strCategories, reputation, WHOIS, detections
virustotal_hash_lookuphash: strFile reputation, AV detections, metadata
abuseipdb_check_ipip: strAbuse confidence (0-100%), reports, ISP
alienvault_ip_lookuptarget: strOTX threat pulses, ASN, country
shodan_host_lookupip: strPorts, services, CVEs
ipinfo_lookupip: strGeolocation, org, hostname
urlscan_lookupurl: strPage scan, verdict, technologies
whois_lookupdomain: strRegistrar, dates, registrant
dns_lookupdomain: strA, AAAA, MX, NS, TXT, CNAME records
crtsh_lookupdomain: strSubdomains by Certificate Transparency
fetch_threat_feedfeed: str, limit: intIOCs from Feodo, URLhaus, IPsum, etc.

Agent and Scoring

ToolParametersDescription
investigate_iocioc: strComplete investigation with ReAct agent
get_risk_scoreioc: strRisk score 0-100
generate_reportGenerates threat intel report from session
classify_iocioc: strClassifies threat type
list_available_feedsLists available threat feeds
list_toolsLists all registered OSINT tools

Intelligence and Context

ToolParametersDescription
gdelt_entity_searchentity: str, days: intRecent news about an entity
gdelt_topic_searchtopic: str, days: intNews about a topic
gdelt_tone_analysisentity: str, days: intMedia tone analysis
rss_news_searchquery: strSearch in general RSS feeds
rss_security_newsquery: strCybersecurity news
rss_financial_newsquery: strFinancial news
get_crypto_pricescoins: list[str]Cryptocurrency prices (CoinGecko)
get_economic_indicatorindicator: strMacroeconomic indicators (FRED)
acled_conflict_eventscountry: str, days: intConflict events (ACLED)
get_country_risk_scorecountry_code: strCountry Instability Index
ais_vessel_lookupmmsi: strVessel information (AISStream)
ais_chokepoint_activitychokepoint: strTraffic at strategic maritime chokepoint
check_entity_anomalyentity: strAnomaly detection in mentions
search_historyquery: strSearch in investigation history

Investigation Management

ToolParametersDescription
create_investigationname: str, goal: strCreate new investigation
list_investigationsList all investigations
get_investigation_summaryslug: strInvestigation summary
ingest_evidencesource: str, investigation_slug: strIngest evidence
add_entitytype: str, name: str, slug: strManually add entity
list_entitiesslug: strList investigation entities
add_claimtext: str, evidence_id: str, slug: strRecord claim with traceability
list_claimsslug: strList investigation claims
verify_claimclaim_id: str, status: strChange claim status
semantic_search_evidencequery: str, slug: str, n: intSemantic search in evidence

The 5 Resources

URIDescription
osint://feedsAvailable feeds with description and URL
osint://toolsAll tools with name and description
osint://history/{query}Past results for an IOC
osint://investigationsJSON list of all investigations
osint://investigation/{slug}Complete investigation details

The 3 Prompts

PromptVariablesUsage
investigate_ipip: strComplete template for investigating an IP
investigate_domaindomain: strComplete template for investigating a domain
investigate_urlurl: strComplete template for investigating a URL