OpenCTI
Provides programmatic access to OpenCTI threat intelligence platforms through specialized tools for querying malware, threat actors, attack patterns, vulnerabilities, and campaigns. Enables sector-based threat analysis, relationship traversal between STIX entities, temporal report queries, and comprehensive threat actor profiling. Features both forward and reverse relationship mapping, fuzzy search capabilities, and configurable result limits. Designed for cybersecurity analysts conducting threat research, incident response teams building threat profiles, and security operations centers performing sector-specific threat assessments.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- security
- Source
- PulseMCP
- Repository
- github.com/jhuntinfosec/mcp-opencti
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve OpenCTI from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.