Cortex Threat Intelligence
MCP Server Cortex is a bridge implementation that exposes Cortex threat intelligence analyzer functionalities as tools for AI models and automation scripts. Developed by Gianluca Brigandi under MIT license, it provides tools for analyzing IP addresses, domains, URLs, and email addresses using popular security services like AbuseIPDB, AbuseFinder, and VirusTotal through a Cortex instance. The server handles the complete workflow of submitting analysis jobs to Cortex, polling for completion, and returning structured reports, making it particularly valuable for security analysts who need to integrate threat intelligence capabilities into AI assistants for automated security assessments and investigations.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- communication
- Source
- PulseMCP
- Repository
- github.com/gbrigandi/mcp-server-cortex
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve Cortex Threat Intelligence from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.