# Threat Research

> Use this tool when you need to automate defensive security analysis workflows and extract indicators of compromise from text. It solves problems related to threat detection and incident response by enriching indicators against multiple sources and generating detection rules in various formats. It takes in text data and outputs enriched indicators and detection rules, making it ideal for use cases involving security operations and threat hunting.

Canonical page: https://skillsregistry.net/skills/harshthakur6293-threat-research  
JSON: https://api.skillsregistry.net/v1/skills/harshthakur6293-threat-research

## Description

Threat Research MCP automates defensive security analysis workflows. It extracts indicators of compromise from text using regex patterns, enriches them against VirusTotal, AlienVault OTX, and other sources with confidence scoring, maps MITRE ATT&CK technique IDs, and generates detection rules in Sigma, Splunk SPL, Microsoft Sentinel KQL, and Elastic formats. Uses LangGraph for multi-agent orchestration across the analysis pipeline.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** devops-ci
- **Updated:** 2026-05-16

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/harshthakur6293-threat-research)
- **Repository:** <https://github.com/harshthakur6293/threat-research-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "harshthakur6293-threat-research"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/harshthakur6293-threat-research` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/harshthakur6293-threat-research/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
