ContrastAPI — Agent · Wellknown
Index / ai / contrastcyber-contrastapi
ContrastAPI Agent A2A Security + OSINT API with 55 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and 3 MCP Prompts for AI agents: CVE/KEV/CWE lookup, composite risk scoring (CVSS+EPSS+KEV+PoC fusion), CVSS v3.x vector parser, domain audit, SSL/header scan, IOC/phishing/IP/ASN/WHOIS/subdomain/wayback, p…
Unknownno checks yet
Not checked yet.
last ok — last check — 30d checks none Observed by Wellknown
Evidence Everything here was measured by our prober or read from a registry. Nothing is self-reported.
30-day availability no checks in window
30 days ago today
Endpoints
https://api.contrastcyber.com a2a · auth: apikey,http · checked on a schedule Registry facts
Not distributed through a package registry we index.
Declared by sources
What the publisher says Attributed to the source that supplied each field. Treated as claims, not facts.
Security + OSINT API with 55 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and 3 MCP Prompts for AI agents: CVE/KEV/CWE lookup, composite risk scoring (CVSS+EPSS+KEV+PoC fusion), CVSS v3.x vector parser, domain audit, SSL/header scan, IOC/phishing/IP/ASN/WHOIS/subdomain/wayback, password breach, username enumeration, threat intel, MITRE ATLAS (AI/ML attack catalog) with bulk technique drill, MITRE D3FEND (defense techniques mapped to ATT&CK), SigmaHQ detection rules (UUID lookup + bulk), email security posture (SPF/DMARC/DKIM), web intelligence (robots.txt parser, redirect-chain walker, email validation, brand-asset scraper, SEO audit, GEO / AI-visibility audit), full-site security scan (contrast_scan, A-F grade).
security cve vulnerability exploit kev cisa cwe weakness osint domain dns whois ssl headers fingerprint injection secrets dependencies threat-intel ioc ip asn hash phishing password email phone username wayback ai-ml atlas mitre bulk incident d3fend defense attack audit prompt triage
Declared skills
CVE Lookup — Look up CVE details with CVSS, EPSS, KEV, patch info CVE Search — Search CVEs by vendor, product, keyword Leading CVEs — Top trending/high-severity CVEs Bulk CVE Lookup — Batch CVE details Exploit Lookup — Public exploits for a CVE KEV Detail — CISA KEV record: federal patch deadline, required action, ransomware association, CWE list CWE Lookup — MITRE CWE catalog: description, mitigations, parent/child weakness chain, CVE count Domain Audit — Full-stack domain security audit Domain Report — Summary report for a domain Subdomain Enumeration — Enumerate subdomains via crt.sh DNS Lookup — DNS records (A, AAAA, MX, TXT, NS) WHOIS Lookup — Domain registration info SSL/TLS Check — Certificate validation + grading (A-F) Security Headers — HTTP security header validation with value checks Scan Headers — Bulk header scan Tech Fingerprint — Detect CMS, frameworks, servers, JS libraries Injection Check — Basic SQLi/XSS reflection test Secret Leakage Check — Scan for exposed secrets in responses Dependency Check — Vulnerable JS library detection IOC Lookup — Indicator of compromise check (IP, domain, hash) Bulk IOC Lookup — Batch IOC check IP Lookup — IP geolocation, ASN, reputation kind ← A2A Agent Card
name ← A2A Agent Card
summary ← A2A Agent Card
version ← A2A Agent Card
description ← A2A Agent Card
homepageUrl ← A2A Agent Card
publisherUrl ← A2A Agent Card
publisherName ← A2A Agent Card
Derived by Wellknown
Capabilities Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Provenance
Where this record came from Every source is kept verbatim. Field changes are logged as events.
A2A Agent Card https://api.contrastcyber.com/.well-known/agent-card.json
first seen 3 h ago · fetched 3 h ago
open ↗ Field history (7 recent events) 3 h ago · declared · summary → "Security + OSINT API with 55 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and 3 MCP Prompts for AI a3 h ago · declared · description → "Security + OSINT API with 55 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and 3 MCP Prompts for AI a3 h ago · declared · publisherName → "ContrastCyber"3 h ago · declared · publisherUrl → "https://contrastcyber.com"3 h ago · declared · homepageUrl → "https://api.contrastcyber.com/quickstart"3 h ago · declared · version → "1.36.2"3 h ago · declared · protocols → ["a2a"]Machine-readable
id ag_6qemzf46fbnj
handle contrastcyber-contrastapi
curl https://wellknown.network/api/v1/agents/contrastcyber-contrastapi Copy badge Task receipts
No signed task receipts yet. Receipts are counts of attested events, never ratings.
First seen 3 h ago · updated 3 h ago.
About records
ASN Lookup — Autonomous system info
Hash Lookup — File hash reputation (MD5/SHA1/SHA256)
Threat Intel — Multi-source threat lookup
Threat Report — Consolidated threat report
Phishing Check — Phishing URL detection
Password Breach — HIBP password breach check (k-anonymity)
Disposable Email — Detect disposable / temp email domains
Email MX — Email domain MX record validation
Phone Lookup — Phone carrier, region, country
Username Lookup — Cross-platform username enumeration
Wayback Lookup — Internet Archive snapshots for a URL
ATLAS Technique Lookup — MITRE ATLAS (AI/ML attack catalog) technique lookup by id (AML.T####). Returns tactics, maturity, ATT&CK bridge, pivot hints
ATLAS Technique Search — Search the MITRE ATLAS AI/ML attack catalog by keyword, tactic, or maturity
Bulk ATLAS Technique Lookup — Drill into up to 50 MITRE ATLAS technique ids in a single call — natural follow-up to atlas_case_study_lookup's techniques_used array
ATLAS Case Study Lookup — MITRE ATLAS real-world AI/ML attack incident case study (AML.CS####)
ATLAS Case Study Search — Search ATLAS case studies by keyword or by referenced ATLAS technique
D3FEND Defense Lookup — MITRE D3FEND defense technique lookup by slug (e.g. TokenBinding). Returns tactic, artifact, mapped ATT&CK T-codes
D3FEND Defense Search — Search D3FEND defenses by keyword, tactic (Harden/Detect/Isolate/...), or targeted artifact
D3FEND Reverse Lookup — Given an ATT&CK T-code, return all D3FEND defenses that mitigate it. Bridges offensive intel (CVE/ATLAS/ATT&CK) to defensive playbook
D3FEND Coverage Audit — Batch defense coverage breakdown across multiple ATT&CK T-codes — count defenses per tactic + identify undefended techniques
Contrast Triage (Prompt) — v1.23.0 conditional MCP Prompt: pick a tool chain by perspective ('red' = offensive recon, 'blue' = defensive triage) for an auto-detected target (CVE / ATLAS / ATT&CK / CWE / hash / IP / domain).
ATLAS Catalog (MCP Resources) — v1.23.0 MCP Resources: browse the full MITRE ATLAS catalog (167 techniques + 57 case studies) without spending a tool slot. URIs: atlas://catalog, atlas://technique/{id}, atlas://case-study/{id}.
D3FEND Catalog (MCP Resources) — v1.23.0 MCP Resources: browse the full MITRE D3FEND defense catalog (149 defenses). URIs: d3fend://catalog, d3fend://defense/{id}.
CWE Catalog (MCP Resources) — v1.23.0 MCP Resources: browse the full MITRE CWE catalog (944 weaknesses). URIs: cwe://catalog (slim), cwe://weakness/{id} (full record).
Robots.txt Parser — v1.25.0 Fetch + parse a target domain's robots.txt — sitemaps, per-User-agent allow/disallow, crawl-delay, Host directive (RFC 9309). Use BEFORE crawling/scraping a target site to honour its published rules.
Redirect Chain Walker — v1.25.0 Walk a URL's HTTP redirect chain hop-by-hop, returning per-hop status, Location, latency. SSRF-guarded at every hop. Use to deobfuscate URL shorteners, audit suspicious phishing links, trace marketing tracking redirects.
Email Verify (Combined) — v1.25.0 One-call email validation combining syntax + MX records + disposable check + role-address detection (admin@/info@/noreply@) + free-provider classification (gmail/outlook/yahoo). Replaces 2-3 tool calls. NO SMTP RCPT TO probing — ethical floor declared.
Brand Assets Scraper — v1.25.0 Scrape a domain's homepage <head> for public brand assets — favicon, og:image, theme-color, og:site_name, JSON-LD Organization.logo. Enriches CRM records / company-card UIs without manual screenshots. Honours robots.txt, Cache-Control, per-target throttle.