pentest-mcp-server
What this MCP does
Supports authorized penetration testing and security research with offline payload generation and encoding, HTTP response analysis, and MITRE ATT&CK methodology lookups.
Tools
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'context': {'type': 'string', 'maxLength': 2000, 'description': 'Freeform context about the authorized test target â\x80\x94 e.g., "login endpoint", "GraphQL API", "file upload handler". Narrows the pattern matching to relevant categories. Max 2,000 characters.'}, 'status_code': {'type': 'integer', 'maximum': 599, 'minimum': 100, 'description': 'HTTP status code (100â\x80\x93599). Helps classify the response type.'}, 'response_body': {'type': 'string', 'maxLength': 10000, 'description': 'Raw HTML, JSON, XML, or error response body text. Maximum 10,000 characters.'}, 'response_headers': {'type': 'string', 'maxLength': 20000, 'description': 'Raw HTTP response headers, optionally including the status line. Maximum 20,000 characters.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['authorized_use_reminder', 'findings', 'fingerprints', 'summary', 'nextToolSuggestions']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['no_input'], 'description': 'Machine-readable failure mode. Declared by this tool: `no_input`: Neither response_headers nor response_body was provided. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'summary': {'type': 'string', 'description': 'One-paragraph summary of findings and associated follow-up actions.'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'severity', 'finding', 'significance', 'detection', 'remediation'], 'properties': {'finding': {'type': 'string', 'description': 'What was detected and where â\x80\x94 header name, body excerpt, or field path with surrounding context.'}, 'category': {'enum': ['version_disclosure', 'stack_trace', 'internal_path', 'debug_header', 'technology_fingerprint', 'auth_pattern', 'cors_misconfiguration', 'security_header_missing', 'interesting_field', 'error_message'], 'type': 'string', 'description': 'Finding category. version_disclosure = server/app version exposed; stack_trace = exception stacktrace leaked; internal_path = filesystem/internal route visible; debug_header = diagnostic header present; technology_fingerprint = framework/language signal; auth_pattern = JWT/cookie/auth mechanism visible; cors_misconfiguration = permissive CORS policy; security_header_missing = CSP/X-Frame-Options absent; interesting_field = non-obvious field worth noting; error_message = application/database error text.'}, 'severity': {'enum': ['info', 'low', 'medium', 'high'], 'type': 'string', 'description': 'Relative impact in an authorized testing context. info = fingerprinting only; low = indirect exposure; medium = useful for chaining; high = directly exploitable.'}, 'detection': {'type': 'string', 'description': 'Observable signals associated with exploitation of this finding.'}, 'remediation': {'type': 'string', 'description': 'Recommended fix for the target application.'}, 'significance': {'type': 'string', 'description': 'Why this finding matters for an authorized penetration test.'}, 'suggested_vector': {'type': 'string', 'description': 'Pentest_guide vector name for follow-up when this finding maps to an attack vector. Absent when no direct vector mapping exists.'}}, 'description': 'A single leakage or fingerprinting finding.', 'additionalProperties': False}, 'description': 'Structured findings ordered by severity descending (high first).'}, 'fingerprints': {'type': 'object', 'required': ['other'], 'properties': {'other': {'type': 'array', 'items': {'type': 'string', 'description': 'A technology signal.'}, 'description': 'Other technology signals detected.'}, 'database': {'type': 'string', 'description': 'Detected database technology if disclosed.'}, 'language': {'type': 'string', 'description': 'Detected backend language (e.g., "PHP", "Python", "Java").'}, 'framework': {'type': 'string', 'description': 'Detected framework or runtime (e.g., "Express 4.x", "Spring Boot").'}, 'cloud_provider': {'type': 'string', 'description': 'Detected cloud provider or CDN.'}, 'server_software': {'type': 'string', 'description': 'Detected server software and version (e.g., "Apache/2.4.54", "nginx/1.25").'}}, 'description': 'Detected server, framework, language, database, cloud, and other technology signals.', 'additionalProperties': False}, 'nextToolSuggestions': {'type': 'array', 'items': {'type': 'object', 'required': ['toolName', 'reason', 'args'], 'properties': {'args': {'type': 'object', 'description': 'Arguments derived from detected fingerprints and findings.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'reason': {'type': 'string', 'description': 'Relationship between the analysis findings and the suggested tool.'}, 'toolName': {'type': 'string', 'description': 'Suggested tool name (e.g., "pentest_guide").'}}, 'description': 'A suggested tool with arguments derived from the analysis.', 'additionalProperties': False}, 'description': 'Suggested tools derived from detected fingerprints and findings.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that response analysis is for authorized testing only. Rendered first.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['payload', 'chain'], 'properties': {'chain': {'type': 'array', 'items': {'enum': ['url', 'double_url', 'html_entity', 'unicode', 'hex', 'base64', 'js_escape', 'null_byte', 'mixed_case', 'comment_break'], 'type': 'string', 'description': 'An encoding step.'}, 'maxItems': 6, 'minItems': 1, 'description': 'Ordered list of encodings to apply (1â\x80\x936 steps). Applied left to right. E.g., ["unicode", "url"] applies Unicode escape first, then URL-encodes the result.'}, 'explain': {'type': 'boolean', 'default': True, 'description': 'Whether to include the decode path and bypass rationale.'}, 'payload': {'type': 'string', 'maxLength': 10000, 'minLength': 1, 'description': 'Input payload string to encode. Max 10,000 characters.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['authorized_use_reminder', 'original', 'encoded', 'intermediate_steps', 'detection_note']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['encoding_error'], 'description': 'Machine-readable failure mode. Declared by this tool: `encoding_error`: An encoding step produced invalid output (e.g., base64 on invalid input). Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'encoded': {'type': 'string', 'description': 'Final encoded payload after all chain steps applied.'}, 'original': {'type': 'string', 'description': 'The input payload.'}, 'decode_path': {'type': 'string', 'description': 'Step-by-step explanation of how a decoder (WAF, server, browser) would reverse the encoding chain. Included when explain is true.'}, 'detection_note': {'type': 'string', 'description': 'Detection methods for encoded variants, including normalization and behavior signals.'}, 'bypass_rationale': {'type': 'string', 'description': 'Why this encoding combination might bypass common filter patterns. Included when explain is true.'}, 'intermediate_steps': {'type': 'array', 'items': {'type': 'object', 'required': ['encoding', 'result'], 'properties': {'result': {'type': 'string', 'description': 'Payload value after this encoding step.'}, 'encoding': {'type': 'string', 'description': 'Encoding name applied at this step.'}}, 'description': 'One encoding step in the chain with its output.', 'additionalProperties': False}, 'description': 'Intermediate values at each encoding step, for tracing the chain.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that encoding transforms are for authorized bypass research only.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['category', 'injection_context'], 'properties': {'count': {'type': 'integer', 'default': 5, 'maximum': 20, 'minimum': 1, 'description': 'Number of payload variants to return (1â\x80\x9320, default 5). More variants cover different bypass approaches for the same context.'}, 'category': {'enum': ['xss', 'sqli', 'ssrf', 'xxe', 'path_traversal', 'ssti', 'command_injection', 'open_redirect', 'csrf', 'deserialization', 'jwt', 'ldap_injection', 'nosql_injection', 'http_header'], 'type': 'string', 'description': 'Vulnerability category for payload generation.'}, 'encoding': {'type': 'array', 'items': {'enum': ['none', 'url', 'double_url', 'html_entity', 'unicode', 'hex', 'base64', 'js_escape'], 'type': 'string', 'description': 'An encoding step to apply.'}, 'description': 'Optional encoding chain applied left to right to each returned template.'}, 'waf_profile': {'enum': ['cloudflare', 'aws_waf', 'modsecurity_crs', 'imperva', 'akamai', 'f5_bigip_asm', 'nginx_modsecurity', 'fortinet_fortiwaf', 'none', 'unknown'], 'type': 'string', 'default': 'none', 'description': 'WAF or filter in front of the authorized test target. When a specific WAF is named, bypass variants referencing known public research are included.'}, 'injection_context': {'enum': ['html_attribute', 'html_body', 'js_string', 'js_template', 'js_script_block', 'url_parameter', 'url_path', 'sql_where', 'sql_integer', 'xml_element', 'xml_attribute', 'http_header', 'json_value', 'cookie_value', 'file_name', 'generic'], 'type': 'string', 'description': 'Precise injection context. Critical for XSS: an HTML attribute payload differs from a JS string payload. Provide the most specific context for the best results.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['category', 'injection_context', 'authorized_use_reminder', 'payloads']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'description': 'Machine-readable failure mode.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'category': {'type': 'string', 'description': 'Requested payload category.'}, 'payloads': {'type': 'array', 'items': {'type': 'object', 'required': ['template', 'description', 'detection_signature', 'mitigation'], 'properties': {'template': {'type': 'string', 'description': 'The payload template string. Adapt to the specific authorized target â\x80\x94 replace placeholder values as annotated.'}, 'mitigation': {'type': 'string', 'description': 'Input validation or encoding control that prevents this payload class.'}, 'description': {'type': 'string', 'description': 'What this payload tests and why it works in the specified injection context.'}, 'encoded_variant': {'type': 'string', 'description': 'Encoded form of the template per the requested encoding chain. Absent when no encoding was requested.'}, 'waf_bypass_note': {'type': 'string', 'description': 'WAF-specific bypass technique and public research reference. Present only when waf_profile is not "none".'}, 'detection_signature': {'type': 'string', 'description': 'Signature a WAF or IDS might match, such as keywords or patterns.'}}, 'description': 'A payload template annotated with offense context (what it tests, how it works) and defense context (detection signature, mitigation).', 'additionalProperties': False}, 'description': 'Payload templates ordered by coverage breadth, each annotated with offense and defense context.'}, 'injection_context': {'type': 'string', 'description': 'Requested injection context.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that these templates are for authorized testing only.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['vector'], 'properties': {'phase': {'enum': ['all', 'recon', 'enumeration', 'exploitation', 'post_exploitation'], 'type': 'string', 'default': 'all', 'description': 'Methodology phase selector. "all" returns the complete playbook; a named phase returns only that phase.'}, 'vector': {'enum': ['auth_bypass', 'idor', 'ssrf', 'xss', 'sqli', 'xxe', 'path_traversal', 'cors', 'csrf', 'open_redirect', 'deserialization', 'race_condition', 'ssti', 'command_injection', 'jwt_attack'], 'type': 'string', 'description': 'Attack vector to retrieve methodology for. Each vector has its own methodology branch covering recon through exploitation. Authorized testing only.'}, 'target_context': {'type': 'object', 'properties': {'waf': {'type': 'string', 'description': 'WAF or filter in use (e.g., "Cloudflare", "AWS WAF", "ModSecurity CRS", "custom regex"). Triggers bypass-aware variants in payload suggestions.'}, 'stack': {'type': 'string', 'description': 'Technology stack (e.g., "Node.js + Express + PostgreSQL", "PHP 7.4 + Apache", "Spring Boot"). Narrows methodology to stack-specific techniques.'}, 'recon_notes': {'type': 'string', 'description': 'Freeform recon findings to incorporate. E.g., "endpoint /api/users/{id} reflects user input in JSON response". Narrows which phases are most relevant.'}}, 'description': 'Optional target profile for authorized engagement. Providing this narrows the playbook to what is most relevant for the specific environment.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['vector', 'authorized_use_reminder', 'phases', 'owasp_references', 'attack_technique_ids', 'nextToolSuggestions']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'description': 'Machine-readable failure mode.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'phases': {'type': 'array', 'items': {'type': 'object', 'required': ['phase', 'objectives', 'techniques', 'tools_commonly_used', 'common_mistakes'], 'properties': {'phase': {'type': 'string', 'description': 'Phase name (e.g., "Reconnaissance", "Exploitation").'}, 'objectives': {'type': 'array', 'items': {'type': 'string', 'description': 'An objective for this phase.'}, 'description': 'Discovery or execution objectives for this phase.'}, 'techniques': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'description', 'detection', 'mitigation'], 'properties': {'name': {'type': 'string', 'description': 'Technique name.'}, 'detection': {'type': 'string', 'description': 'Observable logs, signatures, and anomalies for this technique.'}, 'mitigation': {'type': 'string', 'description': 'Configuration or control that prevents or reduces impact.'}, 'stack_note': {'type': 'string', 'description': 'Stack-specific variant or consideration. Present only when target_context.stack was provided and a relevant note exists.'}, 'description': {'type': 'string', 'description': 'How to perform the technique in authorized testing.'}}, 'description': 'A specific technique for this phase with detection and mitigation context.', 'additionalProperties': False}, 'description': 'Applicable techniques for this phase.'}, 'common_mistakes': {'type': 'array', 'items': {'type': 'string', 'description': 'A common mistake.'}, 'description': 'Pitfalls that lead to missed findings or noisy testing.'}, 'tools_commonly_used': {'type': 'array', 'items': {'type': 'string', 'description': 'A tool commonly used in this phase.'}, 'description': 'Named tools commonly associated with this phase.'}}, 'description': 'A methodology phase covering one stage of the authorized testing workflow.', 'additionalProperties': False}, 'description': 'Ordered methodology phases. Contains only the requested phase when phase input is not "all".'}, 'vector': {'type': 'string', 'description': 'The requested attack vector.'}, 'owasp_references': {'type': 'array', 'items': {'type': 'string', 'description': 'An OWASP test case ID.'}, 'description': 'Relevant OWASP Testing Guide test case IDs (e.g., "WSTG-INPV-01").'}, 'nextToolSuggestions': {'type': 'array', 'items': {'type': 'object', 'required': ['toolName', 'reason', 'args'], 'properties': {'args': {'type': 'object', 'description': 'Arguments derived from the methodology context.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'reason': {'type': 'string', 'description': 'Relationship between the playbook and the suggested tool.'}, 'toolName': {'type': 'string', 'description': 'Suggested tool name (e.g., "pentest_generate_payloads").'}}, 'description': 'A suggested tool with arguments derived from the playbook.', 'additionalProperties': False}, 'description': 'Suggested tools and arguments derived from the playbook.'}, 'attack_technique_ids': {'type': 'array', 'items': {'type': 'string', 'description': 'An ATT&CK technique ID.'}, 'description': 'Relevant ATT&CK technique IDs for cross-referencing with pentest_lookup_technique.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that this methodology applies to authorized testing only. Included in every response.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'ATT&CK threat group ID (e.g., "G0007"), software ID (e.g., "S0002"), or name/keyword (e.g., "APT28", "Mimikatz", "Lazarus Group"). ID lookup is exact and case-insensitive; name/keyword search returns the best match.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['authorized_use_reminder', 'id', 'name', 'aliases', 'type', 'description', 'techniques_used', 'attack_version']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'id': {'type': 'string', 'description': 'ATT&CK ID (e.g., "G0007" for a group, "S0002" for software).'}, 'name': {'type': 'string', 'description': 'Primary display name (e.g., "APT28", "Mimikatz").'}, 'type': {'enum': ['group', 'software'], 'type': 'string', 'description': '"group" for intrusion sets (threat actors), "software" for malware and tools.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['no_match'], 'description': 'Machine-readable failure mode. Declared by this tool: `no_match`: No group or software entry matched the query. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'aliases': {'type': 'array', 'items': {'type': 'string', 'description': 'An alternate name for this group or software.'}, 'description': 'Known alternate names from ATT&CK.'}, 'description': {'type': 'string', 'description': 'ATT&CK description (truncated to 800 characters).'}, 'attack_version': {'type': 'string', 'description': 'ATT&CK dataset version used (e.g., "Enterprise v19.1").'}, 'techniques_used': {'type': 'array', 'items': {'type': 'object', 'required': ['technique_id', 'technique_name', 'description'], 'properties': {'description': {'type': 'string', 'description': 'How this group or software used the technique, from public ATT&CK reporting.'}, 'technique_id': {'type': 'string', 'description': 'ATT&CK technique ID (e.g., "T1190").'}, 'technique_name': {'type': 'string', 'description': 'Technique name.'}}, 'description': 'A technique used by this group or software with procedure context.', 'additionalProperties': False}, 'description': 'Up to 20 techniques associated with the group or software, including procedure-level context and technique IDs.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that threat group data is for authorized testing and research only. Rendered first.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'ATT&CK technique ID (e.g., "T1190", "T1059.001") or keyword describing the technique (e.g., "sql injection", "pass the hash", "web shell upload"). ID lookup is exact; keyword lookup returns the best match plus related techniques.'}, 'include_subtechniques': {'type': 'boolean', 'default': True, 'description': 'Include sub-techniques in the result. Set to false when only the parent technique summary is needed.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['authorized_use_reminder', 'technique_id', 'name', 'tactics', 'description', 'platforms', 'detection', 'mitigations', 'procedure_examples', 'sub_techniques', 'attack_version']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'name': {'type': 'string', 'description': 'Technique name.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['no_match'], 'description': 'Machine-readable failure mode. Declared by this tool: `no_match`: No technique matched the query. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'tactics': {'type': 'array', 'items': {'type': 'string', 'description': 'A tactic name.'}, 'description': 'ATT&CK tactics this technique belongs to (e.g., "Initial Access", "Execution").'}, 'detection': {'type': 'object', 'required': ['summary', 'data_sources', 'indicators'], 'properties': {'summary': {'type': 'string', 'description': 'Overview of how defenders detect this technique.'}, 'indicators': {'type': 'array', 'items': {'type': 'string', 'description': 'A behavioral indicator or signature.'}, 'description': 'Concrete behavioral indicators and signatures.'}, 'data_sources': {'type': 'array', 'items': {'type': 'string', 'description': 'A relevant ATT&CK data source.'}, 'description': 'ATT&CK data sources relevant to detection.'}}, 'description': 'ATT&CK detection context for the technique.', 'additionalProperties': False}, 'platforms': {'type': 'array', 'items': {'type': 'string', 'description': 'A target platform.'}, 'description': 'Target platforms (e.g., "Windows", "Linux", "Web Application").'}, 'description': {'type': 'string', 'description': 'ATT&CK description of the technique.'}, 'mitigations': {'type': 'array', 'items': {'type': 'object', 'required': ['mitigation_id', 'name', 'description'], 'properties': {'name': {'type': 'string', 'description': 'Mitigation name.'}, 'description': {'type': 'string', 'description': "How this mitigation reduces the technique's effectiveness."}, 'mitigation_id': {'type': 'string', 'description': 'ATT&CK mitigation ID (e.g., "M1050").'}}, 'description': 'A recommended ATT&CK mitigation with its ID, name, and effect description.', 'additionalProperties': False}, 'description': 'Recommended mitigations from ATT&CK.'}, 'technique_id': {'type': 'string', 'description': 'ATT&CK technique ID (e.g., "T1190").'}, 'attack_version': {'type': 'string', 'description': 'ATT&CK dataset version used (e.g., "Enterprise v19.1").'}, 'sub_techniques': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name', 'description'], 'properties': {'id': {'type': 'string', 'description': 'Sub-technique ID (e.g., "T1059.001").'}, 'name': {'type': 'string', 'description': 'Sub-technique name.'}, 'description': {'type': 'string', 'description': 'Brief description of the sub-technique (first 200 chars).'}}, 'description': 'A sub-technique ID, name, and brief description.', 'additionalProperties': False}, 'description': 'Sub-techniques of this parent technique. Empty when querying a sub-technique itself, or when include_subtechniques is false.'}, 'procedure_examples': {'type': 'array', 'items': {'type': 'object', 'required': ['group_or_software', 'description'], 'properties': {'description': {'type': 'string', 'description': 'How the group or software used this technique, from public ATT&CK reporting.'}, 'group_or_software': {'type': 'string', 'description': 'Threat group name or malware name that used this technique.'}}, 'description': 'A real-world usage example from ATT&CK public reporting.', 'additionalProperties': False}, 'description': 'Real-world usage examples from ATT&CK public reporting.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that technique data is for authorized testing and research only. Rendered first.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'os': {'enum': ['linux', 'windows', 'macos', 'unknown'], 'type': 'string', 'description': 'Target operating system. Narrows to OS-specific techniques.'}, 'limit': {'type': 'integer', 'default': 15, 'maximum': 50, 'minimum': 1, 'description': 'Maximum number of techniques to return (1â\x80\x9350, default 15). Higher values give broader coverage; lower values focus on highest-relevance items.'}, 'stack': {'type': 'array', 'items': {'type': 'string', 'description': 'A technology stack component.'}, 'description': 'Technology stack components (e.g., ["Node.js", "Express", "PostgreSQL", "Redis"]). Each element matched against technique platform and procedure examples.'}, 'services': {'type': 'array', 'items': {'type': 'string', 'description': 'An exposed service or interface.'}, 'description': 'Exposed services and interfaces (e.g., ["REST API", "GraphQL", "file upload", "admin panel"]). Narrows technique relevance.'}, 'auth_type': {'enum': ['jwt', 'session_cookie', 'api_key', 'oauth2', 'basic_auth', 'ntlm', 'kerberos', 'none', 'unknown'], 'type': 'string', 'description': 'Authentication mechanism in use. Surfaces auth-specific attack techniques.'}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['authorized_use_reminder', 'ranked_techniques', 'owasp_test_cases', 'profile_summary', 'attack_version', 'truncated', 'shown', 'cap']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cap': {'type': 'number', 'description': 'The limit applied to ranked_techniques.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['no_profile'], 'description': 'Machine-readable failure mode. Declared by this tool: `no_profile`: No profile fields were provided. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'shown': {'type': 'number', 'description': 'Number of ranked techniques returned.'}, 'truncated': {'type': 'boolean', 'description': 'True when ranked_techniques was capped by limit.'}, 'attack_version': {'type': 'string', 'description': 'ATT&CK dataset version used for technique data.'}, 'profile_summary': {'type': 'string', 'description': 'One-sentence normalized summary of the supplied target profile.'}, 'owasp_test_cases': {'type': 'array', 'items': {'type': 'object', 'required': ['test_id', 'name', 'relevance'], 'properties': {'name': {'type': 'string', 'description': 'Test case name.'}, 'test_id': {'type': 'string', 'description': 'OWASP Testing Guide test case ID (e.g., "WSTG-INPV-01").'}, 'relevance': {'type': 'string', 'description': 'Why this test case applies to the provided target profile.'}}, 'description': 'An OWASP test case relevant to the target profile.', 'additionalProperties': False}, 'description': 'Relevant OWASP Testing Guide test cases for the profile (up to 10).'}, 'ranked_techniques': {'type': 'array', 'items': {'type': 'object', 'required': ['technique_id', 'name', 'tactic', 'relevance_score', 'relevance_rationale', 'detection_opportunity', 'mitigation_summary'], 'properties': {'name': {'type': 'string', 'description': 'Technique name.'}, 'tactic': {'type': 'string', 'description': 'Primary tactic (e.g., "Initial Access").'}, 'technique_id': {'type': 'string', 'description': 'ATT&CK technique ID (e.g., "T1190").'}, 'relevance_score': {'type': 'number', 'description': 'Relative relevance to the supplied target profile; higher scores indicate stronger matches.'}, 'mitigation_summary': {'type': 'string', 'description': 'Key mitigation recommendation for this technique.'}, 'relevance_rationale': {'type': 'string', 'description': 'Explanation of why this technique is relevant to the provided target profile.'}, 'pentest_guide_vector': {'type': 'string', 'description': 'Associated pentest_guide methodology vector. Absent when no direct mapping exists.'}, 'detection_opportunity': {'type': 'string', 'description': 'Primary observable detection opportunity (truncated to 200 characters).'}}, 'description': 'A ranked ATT&CK technique with relevance rationale and defense context.', 'additionalProperties': False}, 'description': 'Techniques ordered by relevance_score descending.'}, 'authorized_use_reminder': {'type': 'string', 'description': 'Reminder that technique mapping is for authorized testing engagements only. Rendered first.'}}, 'additionalProperties': False}
Recent tool changes
Similar MCP servers
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…