# misp-mcp

> Use this tool when you need to integrate Large Language Models (LLMs) with threat intelligence platforms for streamlined IOC lookups, event management, and intelligence sharing. It solves problems related to investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata. The misp-mcp tool accepts LLM queries as input and provides formatted intelligence outputs, ideal for use cases requiring automated threat analysis and knowledge sharing.

Canonical page: https://skillsregistry.net/skills/solomonneas-misp-mcp  
JSON: https://api.skillsregistry.net/v1/skills/solomonneas-misp-mcp

## Description

An MCP server that enables LLMs to interact with MISP for threat intelligence sharing, IOC lookups, and event management. It provides tools for investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata.

## Trust

- **Trust score (0–1):** 0.90
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-19

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/zdggx9war9)
- **Repository:** <https://github.com/lidless-labs/misp-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "solomonneas-misp-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/solomonneas-misp-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/solomonneas-misp-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
