PG1 Sovereign Threat Intelligence
此 MCP 可以做什么
Provides threat-intelligence lookups for indicators, CVEs, threat actors, STIX feeds, EPSS and CISA KEV enrichment, indicator submissions, and alert subscriptions.
工具
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': "Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically."}}}
输出模式
{'type': 'object', 'required': ['found', 'available', 'domain'], 'properties': {'note': {'type': ['string', 'null']}, 'found': {'type': 'boolean', 'description': 'Whether a registration record was found. Same meaning as the deprecated "available" field.'}, 'domain': {'type': 'string'}, 'reason': {'type': ['string', 'null']}, 'source': {'type': ['string', 'null']}, 'age_days': {'type': ['integer', 'null']}, 'available': {'type': 'boolean', 'description': 'Deprecated — use "found" instead. Kept for backward compatibility.'}, 'registrar': {'type': ['string', 'null']}, 'reason_code': {'enum': ['invalid_domain', 'bootstrap_unavailable', 'unsupported_tld', 'timeout', 'lookup_failed', None], 'type': ['string', 'null']}, 'expiration_date': {'type': ['string', 'null']}, 'newly_registered': {'type': ['boolean', 'null']}, 'registration_date': {'type': ['string', 'null']}}}
输入模式
{'type': 'object', 'required': ['hostname'], 'properties': {'hostname': {'type': 'string', 'description': "Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call."}}}
输出模式
{'type': 'object', 'required': ['hostname', 'verdict', 'sources', 'lookalike_of', 'list_synced_at', 'checked_at', 'attribution'], 'properties': {'sources': {'type': 'array', 'items': {'type': 'object', 'properties': {'url': {'type': ['string', 'null']}, 'name': {'type': 'string'}, 'match_type': {'enum': ['allowlist', 'exact', 'parent_domain', 'confusable', 'keyword'], 'type': 'string'}}}}, 'verdict': {'enum': ['allowlisted', 'listed', 'lookalike', 'not_listed'], 'type': 'string', 'description': 'Never "safe" or "clean".'}, 'hostname': {'type': 'string', 'description': 'The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode).'}, 'checked_at': {'type': 'string'}, 'attribution': {'type': 'string'}, 'lookalike_of': {'type': ['string', 'null'], 'description': 'The matched brand/fuzzylist domain for a "lookalike" verdict, otherwise null.'}, 'list_synced_at': {'type': ['string', 'null']}}}
输入模式
{'type': 'object', 'required': ['address'], 'properties': {'address': {'type': 'string', 'description': 'Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address.'}, 'currency': {'type': ['string', 'null'], 'description': "Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'."}}}
输出模式
{'type': 'object', 'required': ['address', 'address_normalized', 'listed', 'matches', 'source', 'list_last_synced'], 'properties': {'listed': {'type': 'boolean'}, 'source': {'type': 'string'}, 'address': {'type': 'string', 'description': 'The address exactly as submitted.'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'properties': {'sdn_uid': {'type': ['string', 'number', 'null']}, 'currency': {'type': ['string', 'null']}, 'programs': {'type': 'array', 'items': {'type': 'string'}}, 'sdn_name': {'type': ['string', 'null']}}}}, 'message': {'type': 'string'}, 'disclaimer': {'type': 'string'}, 'list_last_synced': {'type': 'string'}, 'address_normalized': {'type': 'string', 'description': 'The address after normalization, used to match against sanctioned_wallets.'}}}
输入模式
{'type': 'object', 'required': ['cve_ids'], 'properties': {'cve_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': "Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call."}}}
输入模式
{'type': 'object', 'required': ['vendor', 'product'], 'properties': {'vendor': {'type': 'string', 'description': "Vendor name, e.g. 'apache'."}, 'product': {'type': 'string', 'description': "Product name, e.g. 'log4j'."}, 'version': {'type': 'string', 'description': "Optional specific version, e.g. '2.14.1'."}, 'only_kev': {'type': 'boolean', 'description': 'If true, only return CVEs on the CISA KEV list.'}}}
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': "Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228')."}}}
输入模式
{'type': 'object', 'required': ['values'], 'properties': {'values': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call.'}}}
输入模式
{'type': 'object', 'required': ['value'], 'properties': {'value': {'type': 'string', 'description': 'Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string.'}}}
输入模式
{'type': 'object', 'required': ['actor_name'], 'properties': {'actor_name': {'type': 'string', 'description': "Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases."}}}
输入模式
{'type': 'object', 'properties': {'type': {'type': ['string', 'null'], 'description': "Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'."}, 'limit': {'type': ['integer', 'null'], 'default': 500, 'description': 'Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).'}, 'since': {'type': ['string', 'null'], 'description': 'ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp.'}, 'min_score': {'type': ['integer', 'null'], 'description': 'Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise.'}}}
输入模式
{'type': 'object', 'properties': {'identifier': {'type': 'string', 'description': 'Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted.'}, 'license_key': {'type': 'string', 'description': 'Optional — check Gumroad license status alongside free-tier usage.'}}}
输入模式
{'type': 'object', 'required': ['indicator', 'indicator_type'], 'properties': {'indicator': {'type': 'string'}, 'confidence': {'type': 'integer', 'description': "Submitter's own confidence, 0-100."}, 'source_note': {'type': 'string', 'description': 'Optional free-text on how this was observed.'}, 'indicator_type': {'type': 'string'}, 'malware_family': {'type': 'string', 'description': 'Optional.'}}}
输入模式
{'type': 'object', 'required': ['webhook_url'], 'properties': {'filter': {'type': 'object', 'properties': {'kev_only': {'type': 'boolean'}, 'min_epss': {'type': 'number'}, 'indicator_type': {'type': 'string'}}, 'description': 'Optional filter object: { indicator_type, min_epss, kev_only }'}, 'webhook_url': {'type': 'string', 'description': 'HTTPS URL to receive POSTed alert payloads.'}}}
近期工具变更
类似的 MCP 服务器
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…