Kaspersky Threat Intelligence

Integrates with Kaspersky's threat intelligence platform to provide conversational access to commercial threat feeds, STIX object

kasperskylab 25
Claude CodeClaude DesktopGeneric
View source ↗

Multi-component threat intelligence repository by Kaspersky Lab containing three distinct tools: a Python-based OpenCTI connector that imports threat intelligence data from Kaspersky's TAXII server at taxii.tip.kaspersky.com with STIX object transformation and relationship generation, a Go-based URL normalization utility for standardizing URLs by removing default ports and decoding parameters, and an OpenTIP MCP server that provides conversational access to Kaspersky's threat intelligence platform. The OpenCTI connector analyzes STIX object descriptions to generate additional threat intelligence relationships and supports configurable data feeds, update intervals, and object expansion, while the MCP component enables AI assistants to query threat data through natural language interactions, serving security analysts, threat researchers, and SOC teams requiring programmatic access to Kaspersky's commercial threat intelligence feeds.

Source

Repository: https://github.com/kasperskylab/threat-intelligence/tree/HEAD/opentip-mcp

Maintain Kaspersky Threat Intelligence?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[Kaspersky Threat Intelligence on getagentictools](https://getagentictools.com/mcp/kasperskylab-threat-intelligence?ref=badge)