Are you the author? Sign in to claim
Official MCP server for Threadlinqs Intelligence — 49 tools for threat intel, detections, IOCs, actors, C2, MITRE chains
MCP server for Threadlinqs Intelligence — 49 tools across threat intelligence, detections, IOCs, threat actors, MITRE attack-chains, C2 infrastructure, and Purple-tier composite intelligence. Drop-in for Claude Code, Claude Desktop, Cursor, and any MCP-compatible client.
# No install needed — npx will fetch it
npx -y intelthreadlinqs-mcp
claude mcp add threadlinqs-intel \
-e THREADLINQS_API_KEY=tl_your_key_here \
-- npx -y intelthreadlinqs-mcp
The -e THREADLINQS_API_KEY is required in practice. The Threadlinqs Intelligence MCP server is a Purple-tier feature — it checks your key's tier at startup and warns if it is missing, invalid, or below Purple. The server still starts and exposes its tool catalog so clients and registries can introspect it, but tool calls are gated server-side: without a Purple or Gold key (tier ≥ 3) they return an Access denied error instead of data. There is no free or anonymous access to gated intelligence.
~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"threadlinqs-intel": {
"command": "npx",
"args": ["-y", "intelthreadlinqs-mcp"],
"env": {
"THREADLINQS_API_KEY": "tl_your_key_here"
}
}
}
}
.cursor/mcp.json:
{
"mcpServers": {
"threadlinqs-intel": {
"command": "npx",
"args": ["-y", "intelthreadlinqs-mcp"],
"env": {
"THREADLINQS_API_KEY": "tl_your_key_here"
}
}
}
}
.vscode/mcp.json:
{
"servers": {
"threadlinqs-intel": {
"type": "stdio",
"command": "npx",
"args": ["-y", "intelthreadlinqs-mcp"],
"env": {
"THREADLINQS_API_KEY": "tl_your_key_here"
}
}
}
}
Sign up at intel.threadlinqs.com, verify your email, and head to Profile → API Key. New accounts get a 7-day Purple-tier free trial that unlocks all 49 tools.
The MCP server is a Purple-tier feature: all 49 tools require a Purple or Gold subscription (tier ≥ 3). The server checks your key's tier at startup and warns when it is missing, invalid, or below Purple — it still starts and lists its tools so clients can introspect the catalog, but the tier is enforced server-side on every call, so gated tools return Access denied rather than data. There is no free or anonymous access to gated intelligence.
| Tier | Price | MCP access |
|---|---|---|
| Purple | $11.99/mo | ✅ All 49 tools |
| Gold | Custom | ✅ All 49 tools (enterprise — contact sales) |
| Lower tiers | — | ❌ No MCP access (the public website + REST API keep their own free Blue tier) |
New accounts get a 7-day Purple-tier free trial that unlocks all 49 tools. Tool calls also enforce the tier server-side and return a structured 403 if your subscription lapses.
The composite tools are the reason most people upgrade to Purple — each one replaces 5–7 single-purpose MCP calls.
get_threat_hunting_bundle ⭐Input: threat_id (e.g. "TL-2026-0599")
Returns: complete hunt dossier in one shot — threat metadata, full IOC list, SPL/KQL/Sigma detection queries, similar threats, simulation commands, and cross-threat infrastructure pivots. The single most useful tool in the platform.
get_actor_intelligenceInput: actor name (e.g. "Lazarus Group", "APT29")
Returns: comprehensive adversary picture — actor profile, attributed threats, MITRE techniques, IOCs (200 cap), detection rules (100 cap), activity timeline, active C2 infrastructure correlated to the actor, and cross-actor shared entities.
get_ioc_intelligenceInput: ioc_value (IP, domain, hash, URL)
Returns: every threat that touches the IOC + actor attribution + DNS enrichment trail + cross-IOC infrastructure pivots + consensus confidence score across 7 external feeds (Pulsedive, GreyNoise, YARAify, MalwareBazaar, URLScan, VxVault, OpenPhish). The "I found this in a log — tell me everything" workflow.
get_cve_intelligenceInput: cve_id (e.g. "CVE-2024-3400")
Returns: CVE detail + linked threats + EPSS exploitation velocity + KEV status + detection coverage % + available attack simulations + first-weaponization timeline.
get_mitre_gap_analysisInput: optional tactic filter, limit
Returns: prioritized list of MITRE techniques without detection coverage, sorted by debt score (threat exposure + KEV count + EPSS). Each entry includes example threats and recommended detection types. Answers "what should I write detections for next?"
predict_attack_pathInput: technique_id (e.g. "T1566"), top_n, direction (forward | reverse)
Returns: ranked next-technique predictions with probability and observation count, plus example threats showing the chain. Built from 4,271 observed transitions across the corpus.
generate_c2_blocklistInput: optional framework, since_days (default 30, max 365), format (cidr | hosts | plain)
Returns: firewall-ready blocklist of active C2 IPs with country, ASN, version, watermark, and last-seen metadata. Currently tracking Cobalt Strike beacons; framework filter is forward-compatible.
search_actors — Find threat actors by name, alias, nation-state, or motivation.get_actor_profile — Full actor dossier in a single call.get_similar_threats — Precomputed-similarity matches by shared TTPs, IOC overlap, and same-actor attribution.For the complete list of 49 tools with parameters and example invocations, see the interactive MCP documentation page.
THREADLINQS_API_KEY environment variable (Bearer token to the worker API)@modelcontextprotocol/sdk@^1.26.0MIT © Threadlinqs
Run Claude Code as an MCP server so any agent can delegate coding tasks to it
Browser automation using accessibility snapshots instead of screenshots
Google's universal MCP server supporting PostgreSQL, MySQL, MongoDB, Redis, and 10+ databases
Official GitHub integration for repos, issues, PRs, and CI/CD workflows