Skip to main content

MCP server for Umbrix CTI platform - AI-powered threat intelligence

Project description

Umbrix MCP Server

Connect your AI assistant directly to live threat intelligence with smart MCP tools optimized for both large and small AI models.

🚀 Quick Start

1. Get Your API Key

Visit umbrix.dev, sign in, and generate an API key from Account Settings.

2. Install & Configure

Option A: Docker (Recommended)

git clone https://github.com/trvon/umbrix-mcp.git
cd umbrix-mcp
docker build -t umbrix-mcp:latest .

Option B: Python Package

pip install git+https://github.com/trvon/umbrix-mcp.git

3. Configure Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "umbrix": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "UMBRIX_API_KEY",
        "-e", "UMBRIX_API_BASE_URL", 
        "umbrix-mcp:latest"
      ],
      "env": {
        "UMBRIX_API_KEY": "your-api-key-here",
        "UMBRIX_API_BASE_URL": "https://umbrix.dev/api"
      }
    }
  }
}

Config file locations:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
  • Linux: ~/.config/Claude/claude_desktop_config.json

4. Alternative: Python Installation

If using pip install instead of Docker:

{
  "mcpServers": {
    "umbrix": {
      "command": "python",
      "args": ["-m", "umbrix_mcp"],
      "env": {
        "UMBRIX_API_KEY": "your-api-key-here",
        "UMBRIX_API_BASE_URL": "https://umbrix.dev/api"
      }
    }
  }
}

🤖 Smart MCP Tools

Optimized for all AI model sizes - from GPT-4 to smaller local models.

🎯 Tool Selection Assistant (Perfect for Smaller Models)

  • get_tool_recommendation - 🆕 Describe what you want to research → Get personalized tool suggestions
    • Example: get_tool_recommendation("I want to research APT29") → Suggests best tools for that task

🔍 Discovery & Exploration (Great Starting Points)

  • discover_recent_threats - Start here! Shows latest activity and data overview
  • threat_correlation - Search for any threat entities with simple terms
  • analyze_indicator - Deep analysis of specific IOCs (IPs, domains, hashes)

💬 Natural Language Queries (Enhanced for Small Models)

  • execute_graph_query - 🚀 ENHANCED Smart tool that converts simple patterns to database queries
    • New patterns: "recent threats", "APT29", "192.168.1.1", "ransomware campaigns"
    • Still supports: Advanced Cypher queries for expert users
  • threat_intel_chat - Natural language Q&A about threats with graph context

🎯 Specific Entity Lookups

  • get_threat_actor - Detailed threat actor profiles and attribution
  • get_malware_details - Comprehensive malware analysis from graph database
  • get_campaign_details - In-depth campaign intelligence from verified data
  • get_cve_details - Comprehensive CVE analysis with severity and exploitation status

📊 Advanced Analysis

  • timeline_analysis - Temporal patterns and activity analysis
  • indicator_reputation - Reputation scoring for IOCs
  • network_analysis - Analyze IP ranges and networks
  • threat_actor_attribution - Attribute indicators to actors
  • ioc_validation - Validate and enrich indicators

🛠️ System & Management

  • system_health_check - Verify platform status when other tools fail
  • feed_status - Check threat intelligence feed health
  • user_quota - Monitor usage limits and access controls

🧠 Model Size Optimization

For Smaller Models (Claude 3 Haiku, Local LLMs):

  1. Start with get_tool_recommendation("describe your task")
  2. Use discover_recent_threats for exploration
  3. Try execute_graph_query with simple patterns like "recent threats" or "APT29"

For Larger Models (GPT-4, Claude 3.5 Sonnet):

  • Full access to advanced Cypher queries in execute_graph_query
  • Complex natural language processing in threat_intel_chat
  • Multi-step analysis workflows

Development

# Clone repository
git clone https://github.com/umbrix/umbrix-mcp.git
cd umbrix-mcp

# Install dependencies  
uv install

# Run tests
uv run pytest

# Build Docker image
docker build -t umbrix-mcp:latest .

# Test the server
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | \
  docker run --rm -i -e UMBRIX_API_KEY=test umbrix-mcp:latest

📄 License

MIT License - see LICENSE file for details.


umbrix.devDocumentation

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

umbrix_mcp-0.2.0.tar.gz (33.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

umbrix_mcp-0.2.0-py3-none-any.whl (23.0 kB view details)

Uploaded Python 3

File details

Details for the file umbrix_mcp-0.2.0.tar.gz.

File metadata

  • Download URL: umbrix_mcp-0.2.0.tar.gz
  • Upload date:
  • Size: 33.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for umbrix_mcp-0.2.0.tar.gz
Algorithm Hash digest
SHA256 c9b9fff0155e5b15533a186e1e8a66d9e260c205d822576a352af155df2b4b5b
MD5 90c3ab7502466a891649a9ee66f2b518
BLAKE2b-256 b2d001e5d4959183c449cccb3afc33a312e095c9279532a8ad42b3ae36c43876

See more details on using hashes here.

File details

Details for the file umbrix_mcp-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: umbrix_mcp-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 23.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for umbrix_mcp-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 464fb9ec0054155b0d4081b98232360957d0e78b3b42f5681462e0abf9757b2b
MD5 e7f3fb2561e1f4b1941b46934e5340e6
BLAKE2b-256 80c86a43ccf461fbbfa0425890d59371a78b6d130dff2ffa98014b92f99967f0

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page