Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. MCP Server Cortex
MCP Server Cortex logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 6:02:13 PM

MCP Server Cortex

User RatingsBe the first to rate and review this MCP server!
View Repository16 GitHub StarsTotal stargazers on GitHub for the source repository (16 stars).Visit Website
securitythreat-intelligencecortexobservable-analysisrust

Rust MCP server exposing Cortex analyzers for observable threat intelligence and automated security responses.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for gbrigandi/mcp-server-cortex, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Tool Schemas (1) Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

This MCP server acts as a bridge to a Cortex instance, exposing its analyzers as tools accessible by MCP clients. It enables automated analysis of observables like IPs, URLs, and domains using configured Cortex analyzers. Use this server when you want to integrate Cortex's threat intelligence and active response capabilities with AI agents or other MCP-compatible clients.

Use cases

β€’Analyze IP addresses for reputation and abuse reports
β€’Scan URLs using VirusTotal or urlscan.io analyzers
β€’Automate threat intelligence enrichment workflows
β€’Integrate Cortex analysis results into AI-driven security platforms
β€’Trigger automated security responses based on analysis

Key features

β€’Exposes Cortex analyzers as MCP tools
β€’Supports multiple analyzers including AbuseIPDB, AbuseFinder, VirusTotal, urlscan.io
β€’API key authentication for Cortex instance access
β€’Configurable via environment variables
β€’Rust-based implementation for performance and safety

Capabilities & Tool Schemas (1) ~41 tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server β€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Server Cortex.

Description

Analyzes an IP address using an AbuseIPDB analyzer (or a similarly configured IP reputation analyzer) via Cortex. Returns the job report if successful.

Documentation Overview

MCP Server for Cortex

Claude Cortex Session

This server acts as a bridge, exposing the powerful analysis capabilities of a Cortex instance as tools consumable by Model Context Protocol (MCP) clients, such as large language models like Claude. It allows these clients to leverage Cortex analyzers for threat intelligence tasks.

What is Cortex?

Cortex is a powerful, free, and open-source observable analysis and active response engine. It allows you to analyze observables (like IPs, URLs, domains, files, etc.) using a variety of "analyzers" – modular pieces of code that connect to external services or perform local analysis.

Benefits of using Cortex (and this MCP server):

  • Centralized Analysis: Run various analyses from a single point.
  • Extensibility: Easily add new analyzers for different threat intelligence feeds and tools.
  • Automation: Automate the process of enriching observables.
  • Integration: Designed to work closely with TheHive, a Security Incident Response Platform (SIRP), but can also be used standalone.
  • Security: API-key based access to protect your Cortex instance.

This MCP server makes these benefits accessible to MCP-compatible clients, enabling them to request analyses and receive structured results.

Prerequisites

  1. Rust Toolchain: Ensure you have Rust installed (visit rustup.rs).
  2. Cortex Instance: A running Cortex instance is required.
    • The server needs network access to this Cortex instance.
    • An API key for Cortex with permissions to list analyzers and run jobs.
  3. Configured Analyzers: The specific analyzers you intend to use (e.g., AbuseIPDB_1_0, Abuse_Finder_3_0, VirusTotal_Scan_3_1, Urlscan_io_Scan_0_1_0) must be enabled and correctly configured within your Cortex instance.

Installation

The recommended way to install the MCP Server for Cortex is to download a pre-compiled binary for your operating system.

  1. Go to the Releases Page: Navigate to the GitHub Releases page.

  2. Download the Binary: Find the latest release and download the appropriate binary for your operating system (e.g., mcp-server-cortex-linux-amd64, mcp-server-cortex-macos-amd64, mcp-server-cortex-windows-amd64.exe).

  3. Place and Prepare the Binary:

    • Move the downloaded binary to a suitable location on your system (e.g., /usr/local/bin on Linux/macOS, or a dedicated folder like C:\Program Files\MCP Servers\ on Windows).
    • For Linux/macOS: Make the binary executable:
      bash
      chmod +x /path/to/your/mcp-server-cortex
      
    • Ensure the directory containing the binary is in your system's PATH if you want to run it without specifying the full path.

Alternatively, you can build the server from source (see the Building section below).

Configuration

The server is configured using the following environment variables:

  • CORTEX_ENDPOINT: The full URL to your Cortex API.
    • Example: http://localhost:9000/api
  • CORTEX_API_KEY: Your API key for authenticating with the Cortex instance.
  • RUST_LOG (Optional): Controls the logging level for the server.
    • Example: info (for general information)
    • Example: mcp_server_cortex=debug,cortex_client=info (for detailed server logs and info from the cortex client library)

Cortex Analyzer Configuration

For the tools provided by this MCP server to function correctly, the corresponding analyzers must be enabled and properly configured within your Cortex instance. The server relies on these Cortex analyzers to perform the actual analysis tasks.

The tools currently use the following analyzers by default (though these can often be overridden via tool parameters):

  • analyze_ip_with_abuseipdb: Uses an analyzer like AbuseIPDB_1_0.
    • This analyzer typically requires an API key from AbuseIPDB. Ensure this is configured in Cortex.
  • analyze_with_abusefinder: Uses an analyzer like Abuse_Finder_3_0.
    • AbuseFinder might have its own configuration requirements or dependencies within Cortex.
  • scan_url_with_virustotal: Uses an analyzer like VirusTotal_Scan_3_1.
    • This analyzer requires a VirusTotal API key. Ensure this is configured in Cortex.
  • analyze_url_with_urlscan_io: Uses an analyzer like Urlscan_io_Scan_0_1_0.
    • This analyzer requires an API key for urlscan.io. Ensure this is configured in Cortex.

Key Points:

  • Enable Analyzers: Make sure the analyzers you intend to use are enabled in your Cortex instance's "Organization" -> "Analyzers" section.
  • Configure Analyzers: Each analyzer will have its own configuration page within Cortex where you'll need to input API keys, set thresholds, or define other operational parameters. Refer to the documentation for each specific Cortex analyzer.
  • Test in Cortex: It's a good practice to test the analyzers directly within the Cortex UI first to ensure they are working as expected before trying to use them via this MCP server.

If an analyzer is not configured, not enabled, or misconfigured (e.g., invalid API key), the corresponding tool call from the MCP client will likely fail or return an error from Cortex.

Example: Claude Desktop Configuration

For MCP clients like Claude Desktop, you typically configure them by specifying the command to launch the MCP server and any necessary environment variables for that server.

  1. Build or Download the Server Binary: Ensure you have the mcp-server-cortex executable. If you've built it from source, it will be in target/debug/mcp_server_cortex or target/release/mcp_server_cortex.

  2. Configure Your LLM Client (e.g., Claude Desktop):

    • The method for configuring your LLM client will vary depending on the client itself.

    • For clients that support MCP, you will typically need to point the client to the path of the mcp-server-cortex executable.

    • Example for Claude Desktop claude_desktop_config.json: You would modify your Claude Desktop configuration file (usually claude_desktop_config.json) to include an entry for this server.

      For instance, if your mcp-server-cortex binary is located at /opt/mcp-servers/mcp-server-cortex, your configuration might look like this:

      config.json
      {
        "mcpServers": {
          // ... other server configurations ...
          "cortex": {
            "command": "/opt/mcp-servers/mcp-server-cortex",
            "args": [],
            "env": {
              "CORTEX_ENDPOINT": "http://your-cortex-instance:9000/api",
              "CORTEX_API_KEY": "your_cortex_api_key_here",
            }
          }
          // ... other server configurations ...
        }
      }
      
      

Available Tools

The server provides the following tools, which can be called by an MCP client:

  1. analyze_ip_with_abuseipdb

    • Description: Analyzes an IP address using an AbuseIPDB analyzer (or a similarly configured IP reputation analyzer) via Cortex. Returns the job report if successful.
    • Parameters:
      • ip (string, required): The IP address to analyze.
      • analyzer_name (string, optional): The specific name of the AbuseIPDB analyzer instance in Cortex. Defaults to AbuseIPDB_1_0.
      • max_retries (integer, optional): Maximum number of times to poll for the analyzer job to complete. Defaults to 5.
  2. analyze_with_abusefinder

    • Description: Analyzes various types of data (IP, domain, FQDN, URL, or email) using an AbuseFinder analyzer via Cortex. Returns the job report if successful.
    • Parameters:
      • data (string, required): The data to analyze (e.g., "1.1.1.1", "example.com", "http://evil.com/malware", "test@example.com").
      • data_type (string, required): The type of the data. Must be one of: ip, domain, fqdn, url, mail.
      • analyzer_name (string, optional): The specific name of the AbuseFinder analyzer instance in Cortex. Defaults to Abuse_Finder_3_0.
      • max_retries (integer, optional): Maximum number of times to poll for the analyzer job to complete. Defaults to 5.
  3. scan_url_with_virustotal

    • Description: Scans a URL using a VirusTotal_Scan analyzer (e.g., VirusTotal_Scan_3_1) via Cortex. Returns the job report if successful.
    • Parameters:
      • url (string, required): The URL to scan.
      • analyzer_name (string, optional): The specific name of the VirusTotal_Scan analyzer instance in Cortex. Defaults to VirusTotal_Scan_3_1.
      • max_retries (integer, optional): Maximum number of times to poll for the analyzer job to complete. Defaults to 5.
  4. analyze_url_with_urlscan_io

    • Description: Analyzes a URL using a Urlscan.io analyzer (e.g., Urlscan_io_Scan_0_1_0) via Cortex. Returns the job report if successful.
    • Parameters:
      • url (string, required): The URL to analyze.
      • analyzer_name (string, optional): The specific name of the Urlscan.io analyzer instance in Cortex. Defaults to Urlscan_io_Scan_0_1_0.
      • max_retries (integer, optional): Maximum number of times to poll for the analyzer job to complete. Defaults to 5.

Building

To build the server from source, ensure you have the Rust toolchain installed (as mentioned in the "Prerequisites" section).

  1. Clone the repository (if you haven't already):
    bash
    git clone https://github.com/gbrigandi/mcp-server-cortex.git
    cd mcp-server-cortex
    
    If you are already working within a cloned repository and are in its root directory, you can skip this step.
Code

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • MCP Virustotal logoMCP Virustotal

    MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.

    πŸ”’ Security2 views
    Compare vs MCP Virustotal β†’
  • MCP Security logoMCP Security

    MCP server for querying the ORKL API. This server provides tools for fetching threat reports, analyzing threat actors, and retrieving intelligence sources.

    πŸ”’ Security3 views
    Compare vs MCP Security β†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    πŸ”’ Security3 views
    Compare vs Apktool MCP Server β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
16
Stargazers on the source repository.
Last commit
9mo ago
Most recent push to the default branch.
Tools exposed
1
Callable tools this server registers over MCP.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Server Cortex

It supports analyzers like AbuseIPDB_1_0, Abuse_Finder_3_0, VirusTotal_Scan_3_1, and Urlscan_io_Scan_0_1_0, which must be enabled and configured in your Cortex instance.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Server Cortex AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/gbrigandi-mcp-server-cortex?style=directory)](https://allmcps.com/mcp/gbrigandi-mcp-server-cortex)
HTML Embed
<a href="https://allmcps.com/mcp/gbrigandi-mcp-server-cortex"><img src="https://allmcps.com/api/badge/gbrigandi-mcp-server-cortex?style=directory" alt="MCP Server Cortex on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
AuthAPI key
ClientsClaude Desktop
Last updatedAug 9, 2026
11/11 checks healthy over the last 33d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars16
GitHub Star CountTotal stargazers on GitHub representing community popularity (16 stars).
Last commit9mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Dec 6, 2025
44Quality signal: Fair Β· 44/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools21/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to MCP Server Cortex β†’Install in Claude DesktopInstall in CursorInstall in VS Code