# ThreatConnect v3 MCP Server

> Use this tool when you need to integrate case management and threat intelligence capabilities into your system, enabling seamless interaction with ThreatConnect v3 for creating, updating, and managing cases, indicators, and artifacts. It solves problems related to threat intelligence and case management by providing a streamlined interface for LLM clients, handling authentication and API complexities. Ideal for use cases requiring secure and efficient threat intelligence data exchange, it accepts API requests as input and returns relevant case management data as output.

Canonical page: https://skillsregistry.net/skills/delonius22-threat-connect-mcp  
JSON: https://api.skillsregistry.net/v1/skills/delonius22-threat-connect-mcp

## Description

Enables LLM clients to interact with ThreatConnect v3 for case management and threat intelligence, providing typed tools for creating/updating cases, indicators, and artifacts while handling HMAC authentication and API quirks.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-08-30

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-08-30

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/sch3al59jf)
- **Repository:** <https://github.com/delonius22/threat_connect_mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "delonius22-threat-connect-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/delonius22-threat-connect-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/delonius22-threat-connect-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
