Threat Hunting

v1.0.0Securitystable

A minimal, modular MCP server that equips your AI with practical capabilities for real-world threat hunting workflows.

cybersecuritydefensive-securitymcp-servermitre-attackpython
Share:
16
Stars
0
Downloads
0
Weekly
0/5

What is Threat Hunting?

Threat Hunting is a Model Context Protocol (MCP) server that allows AI assistants like Claude, Cursor, and VS Code to minimal, modular mcp server that equips your ai with practical capabilities for real-world threat hunting workflows.

A minimal, modular MCP server that equips your AI with practical capabilities for real-world threat hunting workflows.

This server falls under the Security category on MCPgee, the world's largest MCP server directory with 33,000+ servers.

Features

  • A minimal, modular MCP server that equips your AI with pract

Use Cases

Conduct threat hunting workflows with AI assistance.
Use MITRE ATT&CK frameworks for defensive security analysis.
Analyze cybersecurity threats with practical AI tools.
THORCollective

Maintainer

LicenseNOASSERTION
Languagepython
Versionv1.0.0
UpdatedMay 16, 2026
Statushealthy
Maintenanceactive

Works with

ClaudeOpenAIwindowsmacoslinux

Installation

Manual Installation

npx threat-hunting

Configuration

Configuration Details

Config File

claude_desktop_config.json

Performance

Response Metrics

Response Time< 200ms
ThroughputMedium

Resource Usage

Memory UsageLow
CPU UsageLow

How to Set Up and Use Threat Hunting

The Threat Hunting MCP Server equips AI assistants with a modular, practical toolkit for real-world security threat hunting workflows, integrating MITRE ATT&CK techniques, the PEAK threat hunting framework, and the community HEARTH hunt hypothesis library. It exposes over 20 tools for generating behavioral hunt reports, converting IOCs to TTP-focused detections, querying community hunts, analyzing adversary behavior, and integrating with Splunk for live query execution. Security analysts and blue team practitioners use it to accelerate hypothesis generation, standardize hunt documentation, and leverage community knowledge directly from their AI assistant.

Prerequisites

  • Python 3.11–3.13 installed
  • Git to clone the repository and optionally the HEARTH community hunts repository
  • Optional: Splunk SDK (pip install splunk-sdk) for Splunk integration
  • Optional: Atlassian account and API token for Jira/Confluence integration
  • An MCP-compatible client (Claude Desktop, Claude Code)
1

Clone the repository

Clone the threat-hunting-mcp-server repository and optionally the HEARTH community hunt library as a sibling directory.

git clone https://github.com/THORCollective/threat-hunting-mcp-server
cd threat-hunting-mcp-server
# Optional: clone HEARTH community hunts
git clone https://github.com/THORCollective/HEARTH ../HEARTH
2

Install dependencies

Install the base Python requirements. Optional packages for Splunk, ML analysis, and NLP can be added as needed.

pip install -r requirements.txt
# Optional extras:
pip install splunk-sdk
pip install numpy pandas scikit-learn
pip install spacy && python -m spacy download en_core_web_lg
3

Configure environment variables

Copy .env.example to .env and fill in the credentials for any integrations you want enabled. All integrations are optional and degrade gracefully if not configured.

cp .env.example .env
# Edit .env and set as needed:
# HEARTH_PATH=/path/to/HEARTH
# SPLUNK_HOST=your-splunk-host
# SPLUNK_PORT=8089
# SPLUNK_TOKEN=your-token
# ATLASSIAN_URL=https://your-org.atlassian.net
# [email protected]
# ATLASSIAN_API_TOKEN=your-api-token
4

Start the MCP server

Run the server module directly with Python. It will start in stdio mode ready for MCP client connections.

python -m src.server
5

Configure your MCP client

Add the threat hunting server to your Claude Desktop or Claude Code configuration.

Threat Hunting Examples

Client configuration

Claude Desktop configuration for the Threat Hunting MCP server. Replace /path/to/threat-hunting-mcp-server with your actual clone path.

{
  "mcpServers": {
    "threat-hunting": {
      "command": "python3",
      "args": ["-u", "/path/to/threat-hunting-mcp-server/src/server.py"]
    }
  }
}

Prompts to try

Example prompts using MITRE ATT&CK technique IDs, PEAK framework hunts, and HEARTH community hunts.

- "Hunt for any process accessing LSASS memory (T1003.001)"
- "Create a behavioral hunt report for lateral movement via remote execution T1021"
- "Show me HEARTH community hunts for credential access techniques"
- "Convert this IOC to a TTP-focused detection: malicious PowerShell downloading from pastebin"
- "Analyze the adversary behavior pattern in this incident and suggest hunt hypotheses"
- "Recommend threat hunts suitable for a Windows Active Directory environment"

Troubleshooting Threat Hunting

Community hunt tools return no results or HEARTH tools are unavailable

Ensure the HEARTH_PATH environment variable in your .env file points to the correct absolute path of the HEARTH repository clone. Run 'get_server_health' tool to check which features are enabled.

Splunk integration tools fail with connection errors

Verify SPLUNK_HOST, SPLUNK_PORT, and SPLUNK_TOKEN are set correctly in .env. Confirm the Splunk REST API port (default 8089) is reachable from your machine. Install splunk-sdk with 'pip install splunk-sdk' if not already installed.

The server fails to start with ModuleNotFoundError

Make sure you installed requirements from the correct directory ('pip install -r requirements.txt' inside the threat-hunting-mcp-server folder). Use a virtual environment to avoid package conflicts with other Python projects.

Frequently Asked Questions about Threat Hunting

What is Threat Hunting?

Threat Hunting is a Model Context Protocol (MCP) server that minimal, modular mcp server that equips your ai with practical capabilities for real-world threat hunting workflows. It connects AI assistants to external tools and data sources through a standardized interface.

How do I install Threat Hunting?

Follow the installation instructions on the Threat Hunting GitHub repository. Clone the repo, install dependencies, and add the server config to your AI client.

Which AI clients work with Threat Hunting?

Threat Hunting works with all major MCP-compatible AI clients including Claude Desktop, Claude Code, Cursor, VS Code (GitHub Copilot), Windsurf, and Cline.

Is Threat Hunting free to use?

Yes, Threat Hunting is open source and available under the NOASSERTION license. You can use it freely in both personal and commercial projects.

Threat Hunting Alternatives — Similar Security Servers

Looking for alternatives to Threat Hunting? Here are other popular security servers you can use with Claude, Cursor, and VS Code.

Casdoor

13.6k

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, Google Workspace, Azure AD

ghidraMCP

9.0k

An Model Context Protocol server that enables LLMs to autonomously reverse engineer applications by exposing Ghidra's decompilation and analysis tools. It allows AI agents to list code structures, rename methods, and analyze binaries directly through

HexStrike AI

8.9k

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly b

IDA Pro MCP

8.7k

Enables AI-assisted reverse engineering in IDA Pro by providing tools to analyze binaries, decompile functions, manage comments, search patterns, and interact with the IDA database through natural language.

Anthropic Cybersecurity Skills

6.6k

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platform

Hooker

5.1k

🔥🔥 hooker is a Frida-based reverse engineering toolkit for Android. It offers a user-friendly CLI, universal scripts, auto hook generation, memory roaming to detect activities/services, one-click SOCKS5 proxy setup, Frida JustTrustMe, and BoringSSL u

Browse More Security MCP Servers

Explore all security servers available in the MCPgee directory. Each server includes setup guides for Claude, Cursor, and VS Code.

Quick Config Preview

{ "mcpServers": { "threat-hunting": { "command": "npx", "args": ["-y", "threat-hunting"] } } }

Add this to your claude_desktop_config.json or .cursor/mcp.json

Read the full setup guide →

Ready to use Threat Hunting?

Browse our complete directory of 33,000+ MCP servers, read setup guides for your editor, and start building with the Model Context Protocol.

33,000+ ServersFree & Open SourceStep-by-Step Guides