The Google Threat Intelligence (GTI) MCP Server (Standalone) acts as a bridge, enabling AI assistants like Claude, Cline, and Cursor, as well as custom frontend applications, to access comprehensive threat intelligence from Google and VirusTotal. It's built on the Model Context Protocol (MCP) and offers flexible deployment options, supporting both local development for individual analysts and scalable production cloud deployments via Google Cloud Run. This tool empowers users with capabilities like deep threat intelligence search, file analysis, reputation checking for domains, IPs, and URLs, IOC searching, and managing threat profiles and hunting rulesets, making it a critical asset for enhancing security operations and threat analysis workflows.
Key Features
01File analysis and sandbox behavior reporting
02Domain, IP, and URL reputation checking
030 GitHub stars
04Management of threat profiles and hunting rulesets
05Indicator of Compromise (IOC) search capabilities
06Comprehensive threat intelligence search (campaigns, threat actors, malware)