MITRE ATT&CK MCP 服务器

by stoyky

用于MITRE ATT&CK知识库的模型-上下文协议(Model-Context Protocol)服务器。需要MITRE ATT&CK相关数据,默认存储在用户的缓存目录中;也可以通过命令行参数指定自定义数据目录。

Education & sciencestdioCommunity

Repository-wide counts · Cached 2026-01-31

Overview

The MITRE ATT&CK MCP 服务器 MCP server is a publicly available project. Review the upstream repository for installation instructions, supported tools, compatibility, permissions, and current maintenance status.

Configuration

Configuration, transport, authentication, and runtime requirements vary by project. Open the repository before connecting and use the smallest set of credentials and permissions required.

Open the MITRE ATT&CK MCP 服务器 repository to read the latest documentation.

KEEP EXPLORING

Compare source, connection, and authentication details before choosing an implementation.

View the complete category

Deep Research

u14app

Community

Deep Research 使用强大的 AI 模型快速生成深入的研究报告。支持 SSE API 和 MCP 服务器。需要在 .env 文件中配置环境变量以设置服务器端的 API 密钥和相关参数。

TorchLeet

Exorust

Community

TorchLeet provides 68 PyTorch problems from real ML/AI interviews at companies like Google, Meta, and Anthropic. It includes an AI Tutor MCP server that gives AI assistants access to problems, hints, prep plans, and learning paths with a no-spoilers teaching style.

Zotero MCP

54yyyu

Community

用于 Zotero 的模型上下文协议(MCP)服务器,将您的 Zotero 研究库与 Claude 及其他 AI 助手连接。支持本地和 Web API 访问、PDF 注释提取以及高级搜索功能。完整本地 API 功能需要 Python 3.10 及 Zotero 7 以上版本。配置可以通过环境变量或 JSON 配置文件进行设置。

mcp-brasil

mcp-brasil

Community

MCP Server for 70 Brazilian public data sources covering economy, legislation, transparency, judiciary, elections, environment, health, education, public security, and more. Some APIs require optional API keys configured via environment variables (e.g., TRANSPARENCIA_API_KEY, DATAJUD_API_KEY, META_ACCESS_TOKEN).

FROM THE SOURCE

Repository README

Build-time snapshot · Retrieved 2026-10-05

View original


MITRE ATT&CK MCP Server

A Model-Context Protocol server for the MITRE ATT&CK knowledge base

Key Features • Installation • How To Use • Use Cases • Credits

Key Features

  • 50+ Tools for MITRE ATT&CK Querying
    • Comprehensive access to the MITRE ATT&CK knowledge base through structured API tools
  • Automatic ATT&CK Navigator Layer Generation
    • Generate visual representations of techniques used by threat actors
  • Threat Actor and Malware Attribution
    • Query relationships between malware, threat actors, and techniques
  • Technique Overlap Analysis
    • Compare techniques used by different threat actors or malware families

Installation

To clone and run this server, you'll need Git, Python, and PipX installed on your computer.

  1. Ensure Git, Python, and PipX have been installed using their official respective installation instructions for Windows/Mac/Linux
  2. Install the MCP Server using PipX
pipx install git+https://github.com/stoyky/mitre-attack-mcp

How To Use

Configure with Claude AI Desktop

  1. Open Claude's MCP server configuration file.
Windows
C:\Users\[YourUsername]\AppData\Roaming\Claude\claude_desktop_config.json
# or
C:\Users\[YourUsername]\AppData\Local\AnthropicClaude\claude_desktop_config.json
Linux / Mac
~/.config/Claude/claude_desktop_config.json
  1. Add the following to that file if it doesn't already exist. If it already exists, merge the two JSON structures accordingly.
{
  "mcpServers": {
    "mitre-attack": {
      "command": "mitre-attack-mcp",
      "args": [
      ]
    }
  }
}

Note: By default the MCP server stores the mitre-related data in the current users default cache directory. You can specify a custom data directory to use with the following config:

{
  "mcpServers": {
    "mitre-attack": {
      "command": "mitre-attack-mcp",
      "args": [
        "--data-dir",
        "<path-to-data-dir>"
      ]
    }
  }
}

Changelog

  • v1.0.2 - Now installable via PipX on Windows, Mac, and Linux. "data directory" argument is now optional and will use the default cache directory if omitted.
  • v1.0.0 - Initial release
  • V1.0.1 - Improved robustness of layer metadata generation and error handling in layer generation function

Use Cases

  • Query for detailed information about specific malware, tactics, or techniques
  • Discover relationships between threat actors and their tools
  • Generate visual ATT&CK Navigator layers for threat analysis
  • Find campaign overlaps between different threat actors
  • Identify common techniques used by multiple malware families

Please see my blog for more information and examples.

Credits


Created by Remy Jaspers