FalconFeeds MCP server

by Technisanct

263 downloads Not rated yet
GitHub

About

Connect real-time cybersecurity threat intelligence to your AI workflows through standardized tools and resources. Access comprehensive IOCs, CVEs, TTPs, and threat actor data from FalconFeeds.io with seamless integration across Claude Desktop, VS Code, and other MCP-enabled appl

Explore

- Real-time cybersecurity threat intelligence access
- Comprehensive IOC, CVE, and TTP data
- Threat actor information and tracking
- Seamless MCP client integration
- TypeScript-based implementation
- MIT-licensed open source

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name FalconFeeds MCP server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install the npm package, configure your FalconFeeds API key, and add the server to your MCP client configuration. The server exposes tools and resources for querying threat intelligence data through standardized MCP interactions.

search_cves

Search for CVEs with various filters including ID, keyword, and date range

get_cve_by_id

Get a specific CVE by its ID

search_cves_by_keyword

Search CVEs by keyword in descriptions and titles

get_cves_by_date_range

Get CVEs published within a specific date range

get_next_cve_page

Get the next page of CVE results using pagination token

get_threat_actor_profile

**PREFERRED for threat actor searches by name**: Get comprehensive threat actor profile including attributed threat feeds. Use this tool when you have a threat actor NAME (like 'LockBit', 'LEAKBASE', 'APT29') and want to find their profile and associated threat feeds. This automatically searches for the actor by name first, then retrieves their feeds.

get_threat_feed_by_id

Get a specific threat feed by UUID

get_threat_feeds_by_actor

Get threat feeds for a threat actor when you already have their UUID. If you only have the actor's name, use 'get_threat_actor_profile' instead.

get_threat_feeds_by_category

Get threat feeds filtered by category

search_threat_feeds_by_keyword

Perform full-text search on threat feed content and titles using keywords. Use this for general content searches, NOT for country names, industry names, or threat actor names (use their dedicated tools instead).

get_threat_feeds_by_victim

Get threat feeds filtered by organization name or website/domain. Use this ONLY for specific organization names or websites. For countries, use 'get_threat_feeds_by_country'. For industries, use 'get_threat_feeds_by_industry'.

get_threat_feeds_by_country

**PREFERRED for country-based threat landscape**: Get threat feeds where victims are from a specific country. Use this tool when searching for threats by country (e.g., 'UAE', 'USA', 'Germany'). The country name must match exactly from the supported list.

get_threat_feeds_by_industry

**PREFERRED for industry-based threat analysis**: Get threat feeds where victims are from a specific industry sector. Use this tool when analyzing threats by industry (e.g., 'Healthcare & Pharmaceuticals', 'Financial Services', 'Government & Public Sector'). The industry name must match exactly from the supported list.

get_next_threat_feed_page

Get the next page of threat feed results

search_threat_feeds_with_images

**PREFERRED for comprehensive threat feed searches that need direct image urls**: Search threat feeds with direct image URLs included. This tool automatically includes image URLs in the response, providing direct access to screenshots and visual evidence from threat feeds. Use this for general threat intelligence gathering when you need complete information including visual assets.

search_threat_actors

Search threat actors with optional filters

get_threat_actor_by_id

Get a specific threat actor by UUID

search_threat_actors_by_name

Search threat actors by name prefix

get_next_threat_actor_page

Get the next page of threat actor results

search_iocs

**PREFERRED for general IOC searches**: Search Indicators of Compromise (IOCs) with optional filters. This API may have higher response times (~4 seconds) as it aggregates data from multiple sources.

get_iocs_by_country

**PREFERRED for country-specific IOC analysis**: Get IOCs filtered by a specific country. This tool is optimized for analyzing threats targeting or originating from particular countries. Use FULL country names, not abbreviations.

get_iocs_by_threat_type

Get IOCs filtered by a specific threat type. Use this tool to focus on particular types of threats from the available categories.

get_iocs_page

Get a specific page of IOC results. Use this for pagination when dealing with large result sets. Each request returns up to 100 IOCs.

- search_cves: Search for CVEs with various filters including ID, keyword, and date range
- get_cve_by_id: Get a specific CVE by its ID
- search_cves_by_keyword: Search CVEs by keyword in descriptions and titles
- get_cves_by_date_range: Get CVEs published within a specific date range
- get_next_cve_page: Get the next page of CVE results using pagination token
- get_threat_actor_profile: PREFERRED for threat actor searches by name: Get comprehensive threat actor profile including attributed threat feeds. Use this tool when you have a threat actor NAME (like 'LockBit', 'LEAKBASE', 'APT29') and want to find their profile and associated threat feeds. This automatically searches for the actor by name first, then retrieves their feeds.
- get_threat_feed_by_id: Get a specific threat feed by UUID
- get_threat_feeds_by_actor: Get threat feeds for a threat actor when you already have their UUID. If you only have the actor's name, use 'get_threat_actor_profile' instead.
- get_threat_feeds_by_category: Get threat feeds filtered by category
- search_threat_feeds_by_keyword: Perform full-text search on threat feed content and titles using keywords. Use this for general content searches, NOT for country names, industry names, or threat actor names (use their dedicated tools instead).
- get_threat_feeds_by_victim: Get threat feeds filtered by organization name or website/domain. Use this ONLY for specific organization names or websites. For countries, use 'get_threat_feeds_by_country'. For industries, use 'get_threat_feeds_by_industry'.
- get_threat_feeds_by_country: PREFERRED for country-based threat landscape: Get threat feeds where victims are from a specific country. Use this tool when searching for threats by country (e.g., 'UAE', 'USA', 'Germany'). The country name must match exactly from the supported list.
- get_threat_feeds_by_industry: PREFERRED for industry-based threat analysis: Get threat feeds where victims are from a specific industry sector. Use this tool when analyzing threats by industry (e.g., 'Healthcare & Pharmaceuticals', 'Financial Services', 'Government & Public Sector'). The industry name must match exactly from the supported list.
- get_next_threat_feed_page: Get the next page of threat feed results
- search_threat_feeds_with_images: PREFERRED for comprehensive threat feed searches that need direct image urls: Search threat feeds with direct image URLs included. This tool automatically includes image URLs in the response, providing direct access to screenshots and visual evidence from threat feeds. Use this for general threat intelligence gathering when you need complete information including visual assets.
- search_threat_actors: Search threat actors with optional filters
- get_threat_actor_by_id: Get a specific threat actor by UUID
- search_threat_actors_by_name: Search threat actors by name prefix
- get_next_threat_actor_page: Get the next page of threat actor results
- search_iocs: PREFERRED for general IOC searches: Search Indicators of Compromise (IOCs) with optional filters. This API may have higher response times (~4 seconds) as it aggregates data from multiple sources.
- get_iocs_by_country: PREFERRED for country-specific IOC analysis: Get IOCs filtered by a specific country. This tool is optimized for analyzing threats targeting or originating from particular countries. Use FULL country names, not abbreviations.
- get_iocs_by_threat_type: Get IOCs filtered by a specific threat type. Use this tool to focus on particular types of threats from the available categories.
- get_iocs_page: Get a specific page of IOC results. Use this for pagination when dealing with large result sets. Each request returns up to 100 IOCs.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "falconfeeds mcp server": {
            "falconfeeds": {
                "command": "npx",
                "args": [
                    "-y",
                    "@falconfeeds/mcp@latest"
                ],
                "env": {
                    "FALCONFEEDS_API_KEY": "your_api_key_here",
                    "FALCONFEEDS_TIMEOUT": "30000"
                }
            }
        }
    }
}

McpServers

{
    "falconfeeds": {
        "command": "npx",
        "args": [
            "-y",
            "@falconfeeds/mcp@latest"
        ],
        "env": {
            "FALCONFEEDS_API_KEY": "your_api_key_here",
            "FALCONFEEDS_TIMEOUT": "30000"
        }
    }
}

<div align="center">
FalconFeeds Logo

# FalconFeeds MCP Server

npm version
License: MIT
TypeScript

MCP server providing cybersecurity threat intelligence tools and resources

Documentation • API Reference • Dashboard • Support
</div>

---

Connect real-time cybersecurity threat intelligence to MCP clients through standardized tools and resources. Access comprehensive IOCs, CVEs, TTPs, and threat actor data from FalconFeeds.io with seamless integration across Claude Desktop, VS Code, and other MCP-enabled applications.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.