MCP 서버

dora

io.tooloracle/dora
법률 및 컴플라이언스 보안 공개 · 연결 가능 MCP 2026-07-28

이 MCP로 할 수 있는 일

Supports DORA-oriented ICT risk and compliance work with vulnerability, breach, threat, cloud-provider, incident-timeline, third-party-risk, and TLPT information.

breach_check
HaveIBeenPwned breach database — check domain/company breach exposure. DORA Art. 18 incident assessment.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 20, 'maximum': 50, 'minimum': 1, 'description': 'Max results 1-50 (default: 20)'}, 'domain': {'type': 'string', 'description': "Company domain e.g. 'meinbank.de' (optional — omit for latest breaches)"}}, 'additionalProperties': False}
cert_advisories
CERT-Bund security advisories — authoritative DE source for ICT threats. DORA Art. 17 threat monitoring.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 15, 'maximum': 30, 'minimum': 1, 'description': 'Max results 1-30 (default: 15)'}, 'keyword': {'type': 'string', 'description': "Filter by keyword e.g. 'Windows', 'Apache', 'Cisco'"}}, 'additionalProperties': False}
cloud_status
Live status of AWS, GCP, Azure cloud providers. DORA Art. 28 third-party ICT risk monitoring.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 10, 'description': 'Max incidents per provider (default: 10)'}, 'provider': {'type': 'string', 'description': 'Provider: aws, gcp, azure, all (default: all)'}}, 'additionalProperties': False}
cve_latest
Latest critical CVEs — daily DORA ICT risk briefing. Filter by severity and banking relevance.
입력 스키마
{'type': 'object', 'properties': {'days': {'type': 'integer', 'default': 7, 'description': 'Last N days (default: 7)'}, 'limit': {'type': 'integer', 'default': 10, 'maximum': 20, 'minimum': 1, 'description': 'Max results 1-20 (default: 10)'}, 'severity': {'type': 'string', 'description': 'CRITICAL, HIGH, MEDIUM (default: CRITICAL)'}, 'banking_only': {'type': 'boolean', 'description': 'Filter to banking-relevant vendors only (default: false)'}}, 'additionalProperties': False}
cve_search
Search CVEs by keyword, vendor or product. Returns CVSS scores, attack vectors, DORA pillar mapping.
입력 스키마
{'type': 'object', 'properties': {'days': {'type': 'integer', 'default': 30, 'description': 'Published within last N days (default: 30)'}, 'limit': {'type': 'integer', 'default': 10, 'maximum': 20, 'minimum': 1, 'description': 'Max results 1-20 (default: 10)'}, 'vendor': {'type': 'string', 'description': "Vendor/product e.g. 'SAP', 'Cisco', 'Microsoft Exchange'"}, 'keyword': {'type': 'string', 'description': "Search keyword e.g. 'authentication bypass', 'remote code execution'"}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'CVSS severity: CRITICAL, HIGH, MEDIUM, LOW'}}, 'additionalProperties': False}
dora_calendar
DORA compliance milestones and upcoming deadlines for financial institutions. All Art. references included.
입력 스키마
{'type': 'object', 'properties': {}, 'additionalProperties': False}
dora_news
EBA/DORA regulatory news for banks. Topics: general, eba, incident, third_party, testing, guidelines, bafin, swift.
입력 스키마
{'type': 'object', 'properties': {'lang': {'type': 'string', 'description': 'Language: en or de (default: en)'}, 'limit': {'type': 'integer', 'default': 10, 'maximum': 20, 'minimum': 1, 'description': 'Max articles 1-20 (default: 10)'}, 'topic': {'type': 'string', 'description': 'Topic: general, eba, incident, third_party, testing, guidelines, bafin, swift, fintech'}}, 'additionalProperties': False}
health_check
DORAOracle server status and all backend connectivity checks.
입력 스키마
{'type': 'object', 'properties': {}, 'additionalProperties': False}
incident_timeline
Generate a DORA Art. 19-aligned ICT incident reporting timeline with the regulatory deadline structure. Supports - does not constitute - compliant reporting.
입력 스키마
{'type': 'object', 'properties': {'sector': {'type': 'string', 'description': 'Sector: banking, insurance, payment (default: banking)'}, 'incident_time': {'type': 'string', 'description': "ISO timestamp of incident e.g. '2026-03-19T14:00:00Z' (default: now)"}, 'classification': {'type': 'string', 'description': 'Incident class: major, significant, minor (default: major)'}}, 'additionalProperties': False}
kev_check
Check if a specific CVE is in CISA KEV (actively exploited in the wild). Returns DORA incident classification guidance.
입력 스키마
{'type': 'object', 'properties': {'cve_id': {'type': 'string', 'description': "CVE ID to check e.g. 'CVE-2021-44228' (Log4Shell)"}}, 'additionalProperties': False}
kev_list
CISA Known Exploited Vulnerabilities — actively exploited CVEs with patch deadlines. DORA Art. 9 patch compliance.
입력 스키마
{'type': 'object', 'properties': {'days': {'type': 'integer', 'default': 30, 'description': 'Added to KEV within last N days (default: 30)'}, 'limit': {'type': 'integer', 'default': 15, 'maximum': 50, 'minimum': 1, 'description': 'Max results 1-50 (default: 15)'}, 'vendor': {'type': 'string', 'description': "Filter by vendor e.g. 'Cisco', 'Microsoft', 'SAP'"}, 'overdue': {'type': 'boolean', 'description': 'Show only overdue patches (default: false)'}}, 'additionalProperties': False}
mitre_techniques
MITRE ATT&CK techniques for DORA TLPT / TIBER-EU penetration testing. Maps to DORA Art. 26.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 10, 'maximum': 20, 'minimum': 1, 'description': 'Max results 1-20 (default: 10)'}, 'tactic': {'type': 'string', 'description': 'Filter by tactic: Initial Access, Lateral Movement, Impact, Persistence, etc.'}, 'keyword': {'type': 'string', 'description': "Search keyword e.g. 'ransomware', 'phishing', 'credential'"}}, 'additionalProperties': False}
provider_risk
DORA Art. 28 ICT third-party risk assessment: CVE history, news, GLEIF registration, contractual checklist.
입력 스키마
{'type': 'object', 'properties': {'provider': {'type': 'string', 'description': "Provider name e.g. 'SAP', 'Salesforce', 'AWS', 'Temenos'"}}, 'additionalProperties': False}
threat_actors
Feodo Tracker: live C2 botnet servers (Emotet, QakBot, etc.). Actionable IP blocklist for DORA Art. 9.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 20, 'maximum': 100, 'minimum': 1, 'description': 'Max results 1-100 (default: 20)'}, 'status': {'type': 'string', 'description': 'Filter by status: online, offline'}, 'malware': {'type': 'string', 'description': 'Filter by malware family: Emotet, QakBot, Dridex, TrickBot'}}, 'additionalProperties': False}
tlpt_scenarios
TIBER-EU threat scenarios for DORA resilience testing planning. Banking-specific attack simulations.
입력 스키마
{'type': 'object', 'properties': {'focus': {'type': 'string', 'description': 'Focus area: swift, ransomware, insider, ddos, cloud (default: all)'}, 'sector': {'type': 'string', 'description': 'Sector: banking (default: banking)'}}, 'additionalProperties': False}
추가됨
health_check
2026년 9월 17일 12:53 PM
추가됨
dora_calendar
2026년 9월 17일 12:53 PM
추가됨
dora_news
2026년 9월 17일 12:53 PM
추가됨
provider_risk
2026년 9월 17일 12:53 PM
추가됨
cloud_status
2026년 9월 17일 12:53 PM
추가됨
tlpt_scenarios
2026년 9월 17일 12:53 PM
추가됨
mitre_techniques
2026년 9월 17일 12:53 PM
추가됨
incident_timeline
2026년 9월 17일 12:53 PM
추가됨
threat_actors
2026년 9월 17일 12:53 PM
추가됨
breach_check
2026년 9월 17일 12:53 PM
추가됨
cert_advisories
2026년 9월 17일 12:53 PM
추가됨
kev_check
2026년 9월 17일 12:53 PM
추가됨
kev_list
2026년 9월 17일 12:53 PM
추가됨
cve_latest
2026년 9월 17일 12:53 PM
추가됨
cve_search
2026년 9월 17일 12:53 PM