Threadlinqs threat-intelligence MCP β 49 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Unified Detection Engineering Platform
7,283+ detections across Sigma, Splunk ESCU, Elastic & KQL β powered by MCP
Quick Start β’ Workbench β’ 106 Tools β’ 22 Workflows β’ Agents β’ Config
Built on Security Detections MCP by MHaggis Β β’Β Threat Intelligence by Threadlinqs

Security Detections MCP is an open-source platform that unifies 7,283+ detection rules from four major sources into a single queryable interface using the Model Context Protocol (MCP). It combines:
| Source | Rules | Format | Description |
|---|---|---|---|
| Sigma | 3,200+ | YAML | Community-driven, platform-agnostic detection rules |
| Splunk ESCU | 1,800+ | YAML/SPL | Splunk's Enterprise Security Content Update detections |
| Elastic | 1,400+ | TOML/EQL | Elastic Security detection rules |
| KQL | 880+ | KQL | Microsoft Sentinel / Defender analytics rules |
Open http://localhost:3000 in your browser.
Navigate to Settings in the workbench sidebar and configure:
Without an LLM API key, ad-hoc queries and
llm_promptworkflow steps won't function. Without a Threadlinqs key, threat intelligence workflows will skip intel steps but detection tools will work normally.
The workbench is a full-featured web dashboard built with Next.js 15, React 19, and Tailwind CSS v4. It features a terminal-inspired hacker aesthetic with JetBrains Mono font, colored status indicators, and // section headers.
The command center with real-time stats, quick-launch workflows, recent activity, and server status at a glance.

| Metric | Value |
|---|---|
| Total Tools | 106 |
| Indexed Detections | 7,283+ |
| Pre-built Workflows | 22 |
| MCP Servers | 2 |
Browse, search, and execute all 106 tools across both MCP servers. Blue indicators for security-detections, purple for threadlinqs-intel.

Click any tool to inspect its schema, parameters, and test it directly from the browser.

Filter by server to see the 32 Threadlinqs Intel tools β threat feeds, C2 tracking, simulations, and more.

22 pre-built detection engineering workflows spanning threat hunting, coverage analysis, CVE assessment, and intelligence operations.

Drag-and-drop canvas for designing custom detection pipelines. Connect tool calls, transforms, LLM analysis steps, conditionals, loops, and parallel branches.

Execute workflows against live MCP servers with real-time step-by-step progress tracking. Each step shows its type (tool_call, transform, llm_prompt), target server, and execution status.

Results include LLM-generated analysis with executive summaries, threat inventories, MITRE coverage matrices, and prioritized recommendations.

Natural language interface powered by your configured LLM. Ask questions about your detections, threats, and coverage β the system automatically selects and calls the right MCP tools, then synthesizes the results.

Example queries:

| Page | Path | Description |
|---|---|---|
| Dashboard | / | Stats, quick-launch, recent activity, server status |
| Ad-Hoc Terminal | /adhoc | Natural language queries with automatic tool orchestration |
| Tool Explorer | /tools | Browse and execute all 106 MCP tools |
| Workflow Library | /workflows | View and run 22 pre-built workflows |
| Workflow Builder | /workflows/builder | Visual drag-and-drop pipeline designer |
| Threats | /threats | Real-time threat intelligence feed |
| Coverage | /coverage | MITRE ATT&CK coverage analysis |
| History | /history | Execution history and past results |
| Settings | /config | LLM provider, API keys, MCP server status |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/intelthreadlinqs-mcp-2)<a href="https://allmcps.com/mcp/intelthreadlinqs-mcp-2"><img src="https://allmcps.com/api/badge/intelthreadlinqs-mcp-2?style=directory" alt="Intelthreadlinqs MCP on AllMCPs" /></a>