Model Context Protocol (MCP) server for Threat.Zone API
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-threat-zone-threatzonemcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
``` ████████╗██╗ ██╗██████╗ ███████╗ █████╗ ████████╗ ███████╗ ██████╗ ███╗ ██╗███████╗███╗ ███╗ ██████╗██████╗ ╚══██╔══╝██║ ██║██╔══██╗██╔════╝██╔══██╗╚══██╔══╝ ╚══███╔╝██╔═══██╗████╗ ██║██╔════╝████╗ ████║██╔════╝██╔══██╗ ██║ ███████║██████╔╝█████╗ ███████║ ██║ ███╔╝ ██║ ██║██╔██╗ ██║█████╗ ██╔████╔██║██║ ██████╔╝ ██║ ██╔══██║██╔══██╗██╔══╝ ██╔══██║ ██║ ███╔╝ ██║ ██║██║╚██╗██║██╔══╝ ██║╚██╔╝██║██║ ██╔═══╝ ██║ ██║ ██║██║ ██║███████╗██║ ██║ ██║ ██╗███████╗╚██████╔╝██║ ╚████║███████╗██║ ╚═╝ ██║╚██████╗██║ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═════╝╚═╝ ``` # Threat.Zone MCP Server A Model Context Protocol (MCP) server for the Threat.Zone API, built with FastMCP. This server provides LLMs with access to Threat.Zone's malware analysis capabilities through standardized MCP tools. ## Features - **File Analysis**: Submit files for malware analysis including sandbox execution, static analysis, and CDR (Content Disarm and Reconstruction) - **URL Analysis**: Analyze URLs for threats and malicious content - **Submission Management**: Retrieve detailed analysis results, indicators, IoCs, and YARA rules - **Network Analysis**: Access DNS queries, HTTP/TCP/UDP requests, and network threats - **Report Generation**: Download sanitized files and HTML reports - **User Management**: Get user information and submission limits ## Installation ### Using pip ```bash pip install threatzone-mcp ``` ### Using uv (recommended) ```bash uv add threatzone-mcp ``` ### Development Installation ```bash git clone https://github.com/threat-zone/threatzonemcp.git cd threatzonemcp uv sync --dev ``` ## Configuration Set your Threat.Zone API credentials as environment variables: ```bash export THREATZONE_API_KEY="your_api_key_here" # Optional: For private tenants or on-premise deployments export THREATZONE_API_URL="https://your-tenant.threat.zone" `…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.