Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. Mitre Attack MCP Server
Mitre Attack MCP Server logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 8:35:51 PM

Mitre Attack MCP Server

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository5 GitHub StarsTotal stargazers on GitHub for the source repository (5 stars).Visit Website

MCP server providing 50+ tools for MITRE ATT&CK techniques, groups, and mitigations

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "mitre-attack-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@imouiche/mitre-attack-mcp-server"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

πŸ›‘οΈ MITRE ATT&CK MCP Server

AI-Native Access to the World's Leading Threat Intelligence Framework

npm npm downloads License MCP Registry GitHub release

Features β€’ Installation β€’ Quick Start β€’ Tools β€’ Examples β€’ Roadmap


🎯 Overview

The MITRE ATT&CK MCP Server transforms the world's leading adversary knowledge base into an AI-native interface. Built for the Model Context Protocol, it enables LLMs and agentic systems to:

  • πŸ” Query 200+ techniques, 140+ groups, 700+ software entries
  • 🧠 Reason over complex threat relationships and TTPs
  • πŸ“Š Visualize coverage gaps with ATT&CK Navigator layers
  • ⚑ Scale threat intelligence workflows with structured tools

Perfect for: Security teams, threat hunters, detection engineers, AI researchers, and anyone building intelligent security systems.

What is this?

mitre-attack-mcp-server is a self-contained MCP server that provides machine-callable access to the MITRE ATT&CK framework using official STIX data with LLMs friendly structured outputs.

It enables:

  • πŸ€– LLMs to reason about ATT&CK techniques, groups, software, and mitigations
  • 🧠 Agentic workflows to generate threat explanations and coverage maps
  • πŸ” Security teams to query ATT&CK relationships programmatically
  • πŸ“Š Visualization via ATT&CK Navigator layers

No scraping.
No fragile APIs.
Just official MITRE data, structured and reliable.


πŸ“‘ Table of Contents

  • Overview
  • Key Features
  • Installation
  • Quick Start
  • MCP Registry
  • Available Tools
  • Example Queries
  • ATT&CK Navigator
  • Technical Details
  • Roadmap & Vision
  • Contributing
  • License
  • About the Author
  • Acknowledgments

✨ Key Features

  • βœ… 65+ MCP tools across ATT&CK domains (Enterprise, Mobile, ICS)
  • βœ… Automatic STIX download & caching on first run
  • βœ… Native ATT&CK Navigator layer generation
  • βœ… Designed for LLMs & MCP-compatible clients
  • βœ… In-memory caching for instant query responses
  • βœ… Type-safe with Pydantic models
  • βœ… Clean, production-ready, self-contained server
  • βœ… Comprehensive test coverage

πŸ“¦ Installation

Via PyPI (recommended) - Python Users

Terminal
pip install mitre-mcp-server

npm

Terminal
npm install -g @imouiche/mitre-attack-mcp-server

npx (no installation required)

Terminal
npx @imouiche/mitre-attack-mcp-server

Via uv (Modern Python)

bash
uv pip install mitre-mcp-server

Local Development

bash
git clone https://github.com/imouiche/complete-mitre-attack-mcp-server.git
cd complete-mitre-attack-mcp-server
npm install

Using uv (Python package manager)

bash
git clone https://github.com/imouiche/complete-mitre-attack-mcp-server.git
cd complete-mitre-attack-mcp-server
uv sync

⚑ Quick Start

1. Install

Terminal
pip install mitre-mcp-server

2. Configure Claude Desktop

Add to your claude_desktop_config.json:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json

config.json
{
  "mcpServers": {
    "mitre-attack": {
      "command": "npx",
      "args": ["-y", "@imouiche/mitre-attack-mcp-server"]
    }
  }
}

3. Restart Claude Desktop

Quit Claude Desktop completely (Cmd+Q on macOS) and reopen it.

4. Start Querying!

Ask Claude:

"What techniques does APT29 use for initial access?"
"Generate an ATT&CK Navigator layer for ransomware groups"
"Show me all Windows persistence techniques"

Data downloads automatically on first run (~59MB, cached at ~/.mitre-mcp-server/data/).


πŸ“¦ MCP Registry

This server is officially registered in the Model Context Protocol (MCP) Registry.

Registry ID: io.github.imouiche/mitre-attack-mcp-server

View in Official Registry: https://registry.modelcontextprotocol.io/?q=mitre-attack-mcp-server

Installation Options

Option 1: Direct NPM

Terminal
npm install -g @imouiche/mitre-attack-mcp-server

Option 2: NPX (no installation)

Terminal
npx @imouiche/mitre-attack-mcp-server

Option 3: Discover via Registry

  1. Visit MCP Registry
  2. Search for "mitre-attack"
  3. Click the server card for installation instructions

πŸ› οΈ Available Tools

The server exposes 50+ MCP tools covering all major MITRE ATT&CK entities and relationships.


πŸ“Š Infrastructure & Metadata

ToolDescription
get_data_statsShow download status, file paths, sizes, and ATT&CK release version
generate_layerGenerate an ATT&CK Navigator layer (JSON output)
get_layer_metadataReturn Navigator layer metadata template

🎯 Techniques

ToolDescription
get_technique_by_idGet a technique by ATT&CK ID (e.g., T1055)
search_techniquesSearch techniques by name or description
get_all_techniquesRetrieve all techniques
get_all_parent_techniquesParent techniques only
get_all_subtechniquesAll subtechniques
get_subtechniques_of_techniqueSubtechniques of a parent
get_parent_technique_of_subtechniqueParent of a subtechnique
get_technique_tacticsTactics associated with a technique
get_techniques_by_tacticTechniques under a tactic
get_techniques_by_platformTechniques for a platform
get_revoked_techniquesRevoked techniques

πŸ§‘β€πŸ’» Groups (Threat Actors)

ToolDescription
get_group_by_nameFind group by name or alias
search_groupsSearch groups
get_all_groupsAll ATT&CK groups
get_groups_by_aliasLookup groups by alias
get_groups_using_techniqueGroups using a technique
get_groups_using_softwareGroups using software
get_groups_attributing_to_campaignGroups attributed to a campaign

πŸ§ͺ Software (Malware & Tools)

ToolDescription
get_softwareGet all software
search_softwareSearch software
get_software_by_aliasLookup software by alias
get_software_used_by_groupSoftware used by a group
get_software_used_by_campaignSoftware used in campaigns
get_software_using_techniqueSoftware using a technique

πŸ“Œ Campaigns

ToolDescription
get_all_campaignsGet all campaigns
get_campaigns_by_aliasLookup campaigns by alias
get_campaigns_using_techniqueCampaigns using a technique
get_campaigns_using_softwareCampaigns using software
get_campaigns_attributed_to_groupCampaign attribution

πŸ›‘οΈ Mitigations

ToolDescription
get_all_mitigationsGet all mitigations
get_mitigations_mitigating_techniqueMitigations for a technique
get_techniques_mitigated_by_mitigationTechniques mitigated by a mitigation

🧭 Tactics, Data Sources & ICS

ToolDescription
get_all_tacticsGet all tactics
get_all_datasourcesGet all data sources
get_all_datacomponentsGet all data components
get_datacomponents_detecting_techniqueData components detecting a technique
get_all_assetsGet ICS assets
get_assets_targeted_by_techniqueAssets targeted by a technique

πŸ’‘ Example Queries

Threat Intelligence

Code
"What techniques does APT29 use for initial access?"
"Which groups target financial institutions?"
"Show me all ransomware-related software"
"What are the aliases for the Lazarus Group?"

Detection Engineering

Code
"What data sources detect credential dumping?"
"Generate a coverage map for EDR capabilities"
"List all techniques for Windows privilege escalation"
"What can detect T1055 (Process Injection)?"

Threat Hunting

Code
"What techniques use PowerShell?"
"Show me lateral movement techniques for Linux"
"Which groups use Cobalt Strike?"
"What persistence techniques target macOS?"

Mitigation & Defense

Code
"What mitigations exist for phishing attacks?"
"Show me all mitigations for privilege escalation"
"What techniques does MFA mitigate?"

Compliance & Gap Analysis

Code
"Generate a layer for all techniques our EDR covers"
"Compare APT29 TTPs against our detection capabilities"
"Show unmitigated techniques in our environment"

πŸ“Š ATT&CK Navigator Visualization

The generate_layer tool produces ATT&CK Navigator–compatible JSON.

Usage:

  1. Ask Claude to generate a layer:

    "Generate an ATT&CK Navigator layer for all techniques used by APT29"

  2. Save the JSON output to a file (e.g., apt29_layer.json)

  3. Upload to ATT&CK Navigator

  4. Visualize technique coverage, threat actor usage, or mitigation mapping

Real-World Example Using LangGraph

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • MITRE ATT&CK logoMITRE ATT&CK

    MCP server exposing the MITRE ATT&CK framework via the official MCP Python SDK.

    πŸ’» Developer Tools0 views
    Compare vs MITRE ATT&CK β†’
  • PraisonAI logoPraisonAI

    AI Agents Framework with Self Reflection and MCP support

    πŸ’» Developer Tools1 views
    Compare vs PraisonAI β†’
  • AccuWeather MCP logoAccuWeather MCP

    MCP server providing weather tools with data sourced from AccuWeather.

    πŸ’» Developer Tools1 views
    Compare vs AccuWeather MCP β†’
  • Labelhead Artist Momentum logoLabelhead Artist Momentum

    Trending hip-hop artist momentum scores across four cultural dimensions.

    πŸ’» Developer Tools0 views
    Compare vs Labelhead Artist Momentum β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Mitre Attack MCP Server

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "mitre-attack-mcp-server": { "command": "npx", "args": ["-y", "mitre-attack-mcp-server"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMitre Attack MCP Server AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/mitre-attack-mcp-server?style=directory)](https://allmcps.com/mcp/mitre-attack-mcp-server)
HTML Embed
<a href="https://allmcps.com/mcp/mitre-attack-mcp-server"><img src="https://allmcps.com/api/badge/mitre-attack-mcp-server?style=directory" alt="Mitre Attack MCP Server on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 7, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars5
GitHub Star CountTotal stargazers on GitHub representing community popularity (5 stars).
37Quality signal: Fair Β· 37/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to Mitre Attack MCP Server β†’Install in Claude DesktopInstall in CursorInstall in VS Code