{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_83vr25ngwtun","handle":"iflow-mcp-stoyky-mitre-attack-mcp","url":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp","links":{"self":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp/record.json","html":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp","markdown":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp/record.md","api":"https://wellknown.network/api/v1/agents/iflow-mcp-stoyky-mitre-attack-mcp","status":"https://wellknown.network/api/v1/agents/iflow-mcp-stoyky-mitre-attack-mcp/status","claim":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp/claim.json","badge":"https://wellknown.network/agents/iflow-mcp-stoyky-mitre-attack-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/iflow-mcp-stoyky-mitre-attack-mcp/history","tools":"https://wellknown.network/api/v1/agents/iflow-mcp-stoyky-mitre-attack-mcp/tools"},"ard":{"identifier":"urn:air::server:iflow-mcp-stoyky-mitre-attack-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"iflow-mcp_stoyky-mitre-attack-mcp","summary":"A Model-Context Protocol server for the MITRE ATT&CK knowledge base","description":"<h1 align=\"center\">\n  <br>\n  MITRE ATT&CK MCP Server\n  <br>\n</h1>\n\n<h4 align=\"center\">A Model-Context Protocol server for the MITRE ATT&CK knowledge base</h4>\n\n<p align=\"center\">\n  <a href=\"#key-features\">Key Features</a> •\n  <a href=\"#installation\">Installation</a> •\n  <a href=\"#how-to-use\">How To Use</a> •\n  <a href=\"#use-cases\">Use Cases</a> •\n  <a href=\"#credits\">Credits</a>\n</p>\n\n## Key Features\n\n* 50+ Tools for MITRE ATT&CK Querying\n  * Comprehensive access to the MITRE ATT&CK knowledge base through structured API tools\n* Automatic ATT&CK Navigator Layer Generation\n  * Generate visual representations of techniques used by threat actors\n* Threat Actor and Malware Attribution\n  * Query relationships between malware, threat actors, and techniques\n* Technique Overlap Analysis\n  * Compare techniques used by different threat actors or malware families\n\n## Installation\n\nTo clone and run this server, you'll need [Git](https://git-scm.com), [Python](https://www.python.org/), and [PipX](https://github.com/pypa/pipx) installed on your computer.\n\n1. Ensure Git, Python, and PipX have been installed using their official respective installation instructions for Windows/Mac/Linux\n2. Install the MCP Server using PipX\n   \n```bash\npipx install git+https://github.com/stoyky/mitre-attack-mcp\n```\n\n## How To Use\n\n### Configure with Claude AI Desktop\n\n1. Open Claude's MCP server configuration file.\n\n#### Windows\n\n```\nC:\\Users\\[YourUsername]\\AppData\\Roaming\\Claude\\claude_desktop_config.json\n# or\nC:\\Users\\[YourUsername]\\AppData\\Local\\AnthropicClaude\\claude_desktop_config.json\n```\n\n#### Linux / Mac\n\n```bash\n~/.config/Claude/claude_desktop_config.json\n```\n\n2. Add the following to that file if it doesn't already exist. If it already exists, merge the two JSON structures accordingly.\n\n```json\n{\n  \"mcpServers\": {\n    \"mitre-attack\": {\n      \"command\": \"mitre-attack-mcp\",\n      \"args\": [\n      ]\n    }\n  }\n}\n```\n\n**Note**: By default the MCP server stores the mitre-related data in the curren…","publisher":{"name":"stoyky","url":null},"homepage":null,"repository":null,"version":"1.0.2","license":null,"protocols":["mcp"],"tags":["mcp"],"pricing":null,"endpoints":[{"url":"pypi:iflow-mcp_stoyky-mitre-attack-mcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","summary":"pypi","version":"pypi","description":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"dev.version-control","name":"Version Control","confidence":0.745,"provenance":"derived"}],"categories":["dev"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"iflow-mcp_stoyky-mitre-attack-mcp","registry":"pypi","observedAt":"2026-09-15T20:21:25.339Z","publishedAt":"2026-02-09T19:00:20.059839Z","latestVersion":"1.0.2"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"iflow-mcp_stoyky-mitre-attack-mcp","url":"https://pypi.org/project/iflow-mcp_stoyky-mitre-attack-mcp/","firstSeenAt":"2026-09-09T21:24:08.739Z","fetchedAt":"2026-09-15T20:19:51.622Z","normalizedAt":"2026-09-15T20:19:51.622Z"}]},"firstSeenAt":"2026-09-09T21:24:08.739Z","updatedAt":"2026-09-15T20:21:25.339Z"}