Phishunt
Was dieses MCP kann
Checks URLs, domains, brands, certificates, and related infrastructure against phishing detections and performs passive or active phishing analysis.
Tools
Eingabeschema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Full URL or bare domain to analyze; prefer the bare domain if the URL carries tokens'}}}
Eingabeschema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Full URL or bare domain to actively analyze. This URL WILL be contacted, unlike analyze_url; prefer the bare domain if the URL carries tokens.'}}}
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'fuzzy': {'type': 'boolean', 'description': 'Legacy mode: case-insensitive substring match against the full URL instead of exact host match. Default false.'}, 'domain': {'type': ['string', 'array'], 'items': {'type': 'string'}, 'maxItems': 20, 'description': "A hostname (e.g. 'fake-bank.com') or full URL (the host is extracted), or a list of up to 20. Exact host match plus the 'www.' variant."}}}
Eingabeschema
{'type': 'object', 'required': ['brand'], 'properties': {'brand': {'type': 'string', 'description': "Brand slug (lowercase). Examples: 'amazon', 'binance', 'paypal', 'microsoft'. See https://phishunt.io/api/ for the full list."}}}
Eingabeschema
{'type': 'object', 'required': ['campaign_id'], 'properties': {'campaign_id': {'type': 'string', 'description': "Stable campaign key from get_campaigns (preferred, e.g. '0c1b79ab9b24'), or a legacy numeric campaign id."}}}
Ausgabeschema
{'type': 'object', 'oneOf': [{'type': 'object', 'title': 'LiveCampaign', 'required': ['state', 'key', 'size', 'members'], 'properties': {'key': {'type': 'string', 'description': 'Stable campaign identifier.'}, 'size': {'type': 'integer', 'description': 'Number of distinct registrable domains (PSL, private section included). Sibling subdomains of one domain count once.'}, 'state': {'const': 'live'}, 'brands': {'type': 'array', 'items': {'type': 'string'}}, 'domains': {'type': 'array', 'items': {'type': 'object', 'properties': {'hosts': {'type': 'array', 'items': {'type': 'string'}}, 'uuids': {'type': 'array', 'items': {'type': 'string'}}, 'domain': {'type': 'string'}, 'host_count': {'type': 'integer'}, 'active_count': {'type': 'integer'}}}, 'description': 'Members grouped by registrable domain; size == domains.length.'}, 'members': {'type': 'array'}, 'confidence': {'enum': ['possible campaign', 'suspected cluster'], 'type': 'string'}, 'first_seen': {'type': ['string', 'null']}, 'host_count': {'type': 'integer', 'description': 'Number of hostnames in the campaign (members.length).'}, 'data_status': {'enum': ['ok', 'stale', 'missing'], 'type': 'string'}, 'active_count': {'type': 'integer'}, 'generated_at': {'type': ['string', 'null']}, 'last_activity': {'type': ['string', 'null']}, 'relationships': {'type': 'array', 'description': 'Per-pair evidence drill-down: which member pairs actually formed this cluster and by what evidence, sorted strongest first, capped at 50.'}, 'evidence_summary': {'type': 'array'}, 'algorithm_version': {'type': ['string', 'null']}, 'relationships_truncated': {'type': 'boolean'}}}, {'type': 'object', 'title': 'ArchivedCampaign', 'required': ['state', 'key', 'members', 'url'], 'properties': {'key': {'type': 'string'}, 'url': {'type': 'string'}, 'size': {'type': ['integer', 'null']}, 'label': {'type': ['string', 'null']}, 'state': {'const': 'archived'}, 'members': {'type': 'array'}, 'end_state': {'enum': ['dissolved', 'merged', 'split', 'unknown', None], 'type': ['string', 'null']}, 'last_seen': {'type': ['string', 'null']}, 'host_count': {'type': ['integer', 'null']}, 'successors': {'type': 'array', 'items': {'type': 'string'}}, 'data_status': {'enum': ['ok', 'stale', 'missing'], 'type': 'string'}, 'first_tracked': {'type': ['string', 'null']}, 'confidence_score': {'type': 'number'}}}], 'required': ['state'], 'properties': {'state': {'enum': ['live', 'archived'], 'type': 'string'}}, 'description': "A possible campaign / suspected cluster - the live shape (state: 'live') or, for a key whose history is retained but is no longer live, the thinner archived shape (state: 'archived'). Shared-infrastructure grouping of public detections, not an attribution claim."}
Eingabeschema
{'type': 'object', 'required': [], 'properties': {'brand': {'type': 'string', 'description': "Filter to campaigns with at least one member targeting this brand slug (e.g. 'coinbase')."}, 'limit': {'type': 'number', 'default': 10, 'description': 'Max campaigns to return (1-50). Default 10.'}, 'active_only': {'type': 'boolean', 'default': False, 'description': 'If true, only return campaigns with at least one currently-active member. Default false (all).'}}}
Eingabeschema
{'type': 'object', 'required': ['cert'], 'properties': {'cert': {'type': 'string', 'description': "Intermediate CA common name as stored by phishunt (e.g. 'WE1', 'R10', 'GTS CA 1C3'). Case-sensitive exact match. See https://phishunt.io/cert/ for the list."}}}
Eingabeschema
{'type': 'object', 'required': ['since'], 'properties': {'ip': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact IPv4 address.'}, 'asn': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact ASN number as returned by the API, e.g. 15169 or AS15169.'}, 'org': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact hosting organisation string as returned by the API.'}, 'cert': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact TLS certificate issuer string as returned by the API.'}, 'brand': {'type': 'string', 'description': "Optional brand slug filter (e.g. 'amazon')."}, 'limit': {'type': 'number', 'default': 20, 'description': 'Max results (1-300). Default 20. Keep it small: each row is ~1.3 KB of JSON.'}, 'since': {'type': 'string', 'description': "ISO date (YYYY-MM-DD) for the lower bound. Example: '2026-04-15'."}, 'country': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact country name as returned by the API, e.g. United States (not the ISO code).'}, 'registrar': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact registrar string as stored by phishunt (not returned in rows).'}}}
Eingabeschema
{'type': 'object', 'required': ['domain'], 'properties': {'limit': {'type': 'number', 'default': 10, 'description': 'Max related indicators to return (1-50). Default 10.'}, 'domain': {'type': 'string', 'description': "A domain or URL that appears in the phishunt feed (e.g. 'secure-login-example.com'). Resolved to its most recent detection, then correlated."}}}
Eingabeschema
{'type': 'object', 'required': ['brand'], 'properties': {'ip': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact IPv4 address.'}, 'asn': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact ASN number as returned by the API, e.g. 15169 or AS15169.'}, 'org': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact hosting organisation string as returned by the API.'}, 'cert': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact TLS certificate issuer string as returned by the API.'}, 'brand': {'type': 'string', 'description': "Brand slug (lowercase). Examples: 'microsoft', 'binance', 'spotify', 'paypal'. See https://phishunt.io/api/ for the full list."}, 'limit': {'type': 'number', 'default': 20, 'description': 'Max results (1-300). Default 20. Keep it small: each row is ~1.3 KB of JSON.'}, 'country': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact country name as returned by the API, e.g. United States (not the ISO code).'}, 'registrar': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Exact registrar string as stored by phishunt (not returned in rows).'}}}
Eingabeschema
{'type': 'object', 'required': ['query'], 'properties': {'limit': {'type': 'number', 'default': 20, 'description': 'Max results (1-200). Default 20. Keep it small: each row is ~1.3 KB of JSON.'}, 'query': {'type': 'string', 'description': 'Search string (min 3 chars). Case-insensitive substring match against URL, domain, or IP.'}}}
Letzte Tool-Änderungen
Ähnliche MCP-Server
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…