FalconFeeds MCP server
About
Connect real-time cybersecurity threat intelligence to your AI workflows through standardized tools and resources. Access comprehensive IOCs, CVEs, TTPs, and threat actor data from FalconFeeds.io with seamless integration across Claude Desktop, VS Code, and other MCP-enabled appl
Explore
- Real-time cybersecurity threat intelligence access
- Comprehensive IOC, CVE, and TTP data
- Threat actor information and tracking
- Seamless MCP client integration
- TypeScript-based implementation
- MIT-licensed open source
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
FalconFeeds MCP serverCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Install the npm package, configure your FalconFeeds API key, and add the server to your MCP client configuration. The server exposes tools and resources for querying threat intelligence data through standardized MCP interactions.
search_cves
Search for CVEs with various filters including ID, keyword, and date range
get_cve_by_id
Get a specific CVE by its ID
search_cves_by_keyword
Search CVEs by keyword in descriptions and titles
get_cves_by_date_range
Get CVEs published within a specific date range
get_next_cve_page
Get the next page of CVE results using pagination token
get_threat_actor_profile
**PREFERRED for threat actor searches by name**: Get comprehensive threat actor profile including attributed threat feeds. Use this tool when you have a threat actor NAME (like 'LockBit', 'LEAKBASE', 'APT29') and want to find their profile and associated threat feeds. This automatically searches for the actor by name first, then retrieves their feeds.
get_threat_feed_by_id
Get a specific threat feed by UUID
get_threat_feeds_by_actor
Get threat feeds for a threat actor when you already have their UUID. If you only have the actor's name, use 'get_threat_actor_profile' instead.
get_threat_feeds_by_category
Get threat feeds filtered by category
search_threat_feeds_by_keyword
Perform full-text search on threat feed content and titles using keywords. Use this for general content searches, NOT for country names, industry names, or threat actor names (use their dedicated tools instead).
get_threat_feeds_by_victim
Get threat feeds filtered by organization name or website/domain. Use this ONLY for specific organization names or websites. For countries, use 'get_threat_feeds_by_country'. For industries, use 'get_threat_feeds_by_industry'.
get_threat_feeds_by_country
**PREFERRED for country-based threat landscape**: Get threat feeds where victims are from a specific country. Use this tool when searching for threats by country (e.g., 'UAE', 'USA', 'Germany'). The country name must match exactly from the supported list.
get_threat_feeds_by_industry
**PREFERRED for industry-based threat analysis**: Get threat feeds where victims are from a specific industry sector. Use this tool when analyzing threats by industry (e.g., 'Healthcare & Pharmaceuticals', 'Financial Services', 'Government & Public Sector'). The industry name must match exactly from the supported list.
get_next_threat_feed_page
Get the next page of threat feed results
search_threat_feeds_with_images
**PREFERRED for comprehensive threat feed searches that need direct image urls**: Search threat feeds with direct image URLs included. This tool automatically includes image URLs in the response, providing direct access to screenshots and visual evidence from threat feeds. Use this for general threat intelligence gathering when you need complete information including visual assets.
search_threat_actors
Search threat actors with optional filters
get_threat_actor_by_id
Get a specific threat actor by UUID
search_threat_actors_by_name
Search threat actors by name prefix
get_next_threat_actor_page
Get the next page of threat actor results
search_iocs
**PREFERRED for general IOC searches**: Search Indicators of Compromise (IOCs) with optional filters. This API may have higher response times (~4 seconds) as it aggregates data from multiple sources.
get_iocs_by_country
**PREFERRED for country-specific IOC analysis**: Get IOCs filtered by a specific country. This tool is optimized for analyzing threats targeting or originating from particular countries. Use FULL country names, not abbreviations.
get_iocs_by_threat_type
Get IOCs filtered by a specific threat type. Use this tool to focus on particular types of threats from the available categories.
get_iocs_page
Get a specific page of IOC results. Use this for pagination when dealing with large result sets. Each request returns up to 100 IOCs.
- search_cves: Search for CVEs with various filters including ID, keyword, and date range
- get_cve_by_id: Get a specific CVE by its ID
- search_cves_by_keyword: Search CVEs by keyword in descriptions and titles
- get_cves_by_date_range: Get CVEs published within a specific date range
- get_next_cve_page: Get the next page of CVE results using pagination token
- get_threat_actor_profile: PREFERRED for threat actor searches by name: Get comprehensive threat actor profile including attributed threat feeds. Use this tool when you have a threat actor NAME (like 'LockBit', 'LEAKBASE', 'APT29') and want to find their profile and associated threat feeds. This automatically searches for the actor by name first, then retrieves their feeds.
- get_threat_feed_by_id: Get a specific threat feed by UUID
- get_threat_feeds_by_actor: Get threat feeds for a threat actor when you already have their UUID. If you only have the actor's name, use 'get_threat_actor_profile' instead.
- get_threat_feeds_by_category: Get threat feeds filtered by category
- search_threat_feeds_by_keyword: Perform full-text search on threat feed content and titles using keywords. Use this for general content searches, NOT for country names, industry names, or threat actor names (use their dedicated tools instead).
- get_threat_feeds_by_victim: Get threat feeds filtered by organization name or website/domain. Use this ONLY for specific organization names or websites. For countries, use 'get_threat_feeds_by_country'. For industries, use 'get_threat_feeds_by_industry'.
- get_threat_feeds_by_country: PREFERRED for country-based threat landscape: Get threat feeds where victims are from a specific country. Use this tool when searching for threats by country (e.g., 'UAE', 'USA', 'Germany'). The country name must match exactly from the supported list.
- get_threat_feeds_by_industry: PREFERRED for industry-based threat analysis: Get threat feeds where victims are from a specific industry sector. Use this tool when analyzing threats by industry (e.g., 'Healthcare & Pharmaceuticals', 'Financial Services', 'Government & Public Sector'). The industry name must match exactly from the supported list.
- get_next_threat_feed_page: Get the next page of threat feed results
- search_threat_feeds_with_images: PREFERRED for comprehensive threat feed searches that need direct image urls: Search threat feeds with direct image URLs included. This tool automatically includes image URLs in the response, providing direct access to screenshots and visual evidence from threat feeds. Use this for general threat intelligence gathering when you need complete information including visual assets.
- search_threat_actors: Search threat actors with optional filters
- get_threat_actor_by_id: Get a specific threat actor by UUID
- search_threat_actors_by_name: Search threat actors by name prefix
- get_next_threat_actor_page: Get the next page of threat actor results
- search_iocs: PREFERRED for general IOC searches: Search Indicators of Compromise (IOCs) with optional filters. This API may have higher response times (~4 seconds) as it aggregates data from multiple sources.
- get_iocs_by_country: PREFERRED for country-specific IOC analysis: Get IOCs filtered by a specific country. This tool is optimized for analyzing threats targeting or originating from particular countries. Use FULL country names, not abbreviations.
- get_iocs_by_threat_type: Get IOCs filtered by a specific threat type. Use this tool to focus on particular types of threats from the available categories.
- get_iocs_page: Get a specific page of IOC results. Use this for pagination when dealing with large result sets. Each request returns up to 100 IOCs.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"falconfeeds mcp server": {
"falconfeeds": {
"command": "npx",
"args": [
"-y",
"@falconfeeds/mcp@latest"
],
"env": {
"FALCONFEEDS_API_KEY": "your_api_key_here",
"FALCONFEEDS_TIMEOUT": "30000"
}
}
}
}
}
McpServers
{
"falconfeeds": {
"command": "npx",
"args": [
"-y",
"@falconfeeds/mcp@latest"
],
"env": {
"FALCONFEEDS_API_KEY": "your_api_key_here",
"FALCONFEEDS_TIMEOUT": "30000"
}
}
}
<div align="center">
# FalconFeeds MCP Server
MCP server providing cybersecurity threat intelligence tools and resources
Documentation • API Reference • Dashboard • Support
</div>
---
Connect real-time cybersecurity threat intelligence to MCP clients through standardized tools and resources. Access comprehensive IOCs, CVEs, TTPs, and threat actor data from FalconFeeds.io with seamless integration across Claude Desktop, VS Code, and other MCP-enabled applications.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



