Skip to main content

Live threat intelligence MCP server — IP lookup, CVE intel, KEV Oracle predictions, malware hashes, pre-attack staging detection. Free, no API key required.

Project description

KeyboardCrumbs MCP Server

Live threat intelligence tools for Claude Desktop. Free, no API key required.

Tools

Tool Description
check_ip Threat intel for any IP — risk score, geo, ASN, C2 associations, staging clusters
check_cve CVE lookup — CVSS, EPSS, KEV status, exploit availability, patch urgency
check_domain Domain intel — DNS records, WHOIS, malware associations, subdomains
check_hash Malware hash lookup via VirusTotal (68+ engines) + CIRCL (6.3B files)
active_threats Live snapshot — KEV count, active C2s, ransomware victims, data freshness
predict_kev KEV Oracle — top CVEs predicted to be added to CISA KEV before it happens
check_staging GhostWatch — detect pre-attack infrastructure staging for an IP or domain
check_ransomware Ransomware group lookup and victim tracking

Install

Option 1 — uvx (no install needed)

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "keyboardcrumbs": {
      "command": "uvx",
      "args": ["--from", "git+https://github.com/keyboardcrumbs/mcp", "keyboardcrumbs-mcp"]
    }
  }
}

Option 2 — Clone and run locally

git clone https://github.com/keyboardcrumbs/mcp
cd mcp
uv venv && source .venv/bin/activate
uv add "mcp[cli]" httpx

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "keyboardcrumbs": {
      "command": "uv",
      "args": ["--directory", "/path/to/mcp", "run", "server.py"]
    }
  }
}

Restart Claude Desktop.

Example Usage

Once installed, just ask Claude:

  • "Is 45.141.26.73 malicious?"
  • "Should I patch CVE-2024-3400 immediately?"
  • "What CVEs are about to be added to CISA KEV?"
  • "Is this domain staging for an attack?"
  • "What's the current threat landscape?"

Claude will call the live KeyboardCrumbs API and return real-time threat intelligence.

Data Sources

URLhaus · Feodo Tracker · AlienVault OTX · CISA KEV · NVD · EPSS · ExploitDB · VirusTotal · CIRCL · SANS ISC DShield · Shodan · RIPE · crt.sh · Ransomware.live

Data updates every 15 minutes. No API key. No signup. No rate limits for normal use.

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

keyboardcrumbs_mcp-1.0.0.tar.gz (6.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

keyboardcrumbs_mcp-1.0.0-py3-none-any.whl (7.5 kB view details)

Uploaded Python 3

File details

Details for the file keyboardcrumbs_mcp-1.0.0.tar.gz.

File metadata

  • Download URL: keyboardcrumbs_mcp-1.0.0.tar.gz
  • Upload date:
  • Size: 6.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for keyboardcrumbs_mcp-1.0.0.tar.gz
Algorithm Hash digest
SHA256 bf43a3af2288890ccfac695e876232952a82ae5464a31b01cbfab66fc50d9ab4
MD5 a79c0d01dd0963cdd02abdbada118a50
BLAKE2b-256 16b790269dfb619cd39d996d9d8e9758bcbcaa7c99e8b3ff11ab359c94301059

See more details on using hashes here.

File details

Details for the file keyboardcrumbs_mcp-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for keyboardcrumbs_mcp-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ffd715393fcdc620bf43648ef156bee319691fc47c713a9b4981316524c01a6c
MD5 9700cda454b4a83af2c34570f0fa9246
BLAKE2b-256 671159e7e92c02cd32181150a54dfb4111b0003e77d4b0ffa25bce363aa9ba0d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page