Tools

All Tools

The Precursor Intelligence MCP server exposes 71 tools. All cost 1 credit per successful call except account_status, which is free. Click any tool for full parameter, response, and example detail.

The Your Data tools (the *_my_*, get_open_ports, assess_cve_exposure, map_assets_to_actor, and appliances_exploited_by_actor tools) return your own organisation's data — assets, alerts, watchlist, supply-chain, and more — and cross-reference it with the threat intel. They require the mcp:org scope on your key; the organisation is resolved from the key and never read from the request. See Authentication.

Every tool's name is the exact string you pass to tools/call:

{ "jsonrpc": "2.0", "id": 1, "method": "tools/call",
  "params": { "name": "<tool>", "arguments": { } } }

CVE, EPSS & KEV

ToolWhat it does
get_cveFull intelligence on a single CVE: NVD record, CVSS, EPSS, CISA KEV status, Shadowserver honeypot activity, notable events, and attributed threat actors with citations.
search_cves_by_vendorHighest-EPSS CVEs for a vendor, sorted by EPSS descending.
list_kev_recentCISA KEV entries added within the last N days.
list_high_epss_cvesCVEs at or above an EPSS threshold, sorted descending.
list_recent_notable_eventsCVE events such as new NVD entries, high EPSS deltas, and CISA KEV additions.

CPE & Vendors

ToolWhat it does
get_vendorVendor summary: total CVE count, product count, and product-to-CVE map.
get_vendor_productProduct summary: CVE count, version count, and version-to-CVE map.
get_vendor_product_versionUp to 200 CVEs affecting a specific vendor/product/version triple, with a truncation flag.
search_productsFull-text search across CPE product names.
list_top_vendors_by_cve_countTop CPE vendors by total tracked CVE count.

CWE

ToolWhat it does
get_cweSingle CWE record: description, abstraction, related weaknesses, consequences, and mitigations.
list_cwesSearch or page the CWE catalog (approximately 964 records).
list_top_cwesMost-referenced CWEs across scored CVEs.

MITRE ATT&CK

ToolWhat it does
get_mitre_techniqueSingle ATT&CK technique or sub-technique: description, platforms, detection, and kill-chain phases.
list_mitre_tacticsAll 14 ATT&CK Enterprise tactics with per-tactic statistics.
list_mitre_techniquesTechniques list, optionally filtered by tactic shortname.
list_top_mitre_techniquesMost-referenced ATT&CK techniques across intelligence reporting.

Atomic Red Team

ToolWhat it does
list_art_techniquesAtomic Red Team technique index (324 techniques), with optional substring filter.
list_art_atomic_testsPaged atomic test list, filterable by ATT&CK technique ID and platform.
get_art_atomic_testFull atomic test detail: executors, dependencies, and input arguments.

Threat Actors

ToolWhat it does
list_threat_actorsTracked actors ranked by corroborated evidence volume. Filterable by type (ransomware / apt / cybercrime / hacktivist).
get_threat_actorFull dossier: aliases, ATT&CK techniques, campaigns, related groups, ransomware tradecraft, and linked CVEs / industries / malware — each with an evidence quote and source URL.
list_threat_actor_cvesCVEs an actor is reported to exploit, with evidence quotes plus CVSS, EPSS, KEV status and action priority. KEV-first ordering.
get_cve_threat_actorsThreat actors reported to have exploited a given CVE, each with the quote and source URL attributing it.
list_threat_actors_by_industryThreat actors reported to target a given industry, with citations. Matches industry names, slugs and aliases.
get_threat_actor_techniquesFull technique set for an actor: MITRE ATT&CK where it is a named intrusion set, in-house data for the ~800 actors ATT&CK does not name.

IOCs

ToolWhat it does
search_iocsSubstring search across 1M+ IOCs from our IOC intelligence, with filters by type, threat type, and malware family.
lookup_iocExact-match IOC lookup across the IOC feed and blog-derived IOCs, with enrichment.
list_recent_iocsIOCs first seen within the last N days.

Malware Samples

ToolWhat it does
search_malware_samplesSearch the malware sample corpus by substring, file type, or signature.
get_malware_sampleSingle sample by SHA-256 hash, with key metadata and signature.
list_recent_malware_samplesRecently observed samples from our malware dataset, optionally filtered by file type.
list_top_malwareMost-referenced malware families across intelligence reporting.

Blacklists

ToolWhat it does
lookup_ssl_blacklistCheck whether a SHA-1 certificate fingerprint appears on the SSL blacklist as associated with botnet C2 or malware.
lookup_ja3_blacklistCheck whether a JA3 MD5 fingerprint appears on the JA3 blacklist as associated with malware or C2.

Shadowserver Honeypot

ToolWhat it does
get_shadowserver_cve_activityDaily Shadowserver honeypot observations for a single CVE over N days.
list_shadowserver_top_cvesTop CVEs by Shadowserver honeypot connections over a configurable window.
list_shadowserver_top_vendorsTop vendors by Shadowserver honeypot connections.
get_shadowserver_daily_statsAggregate Shadowserver daily statistics: unique IPs, connections, and active CVEs.

Remediation

ToolWhat it does
get_top_affected_systemsMost-referenced affected systems across intelligence reporting.
list_remediation_summaryLatest AI-generated remediation summaries for a CVE.
list_recent_remediation_queueCVEs recently added to the remediation queue.

Account & Meta

ToolWhat it does
account_statusFree. Caller's current credit balance and API key metadata.

Your Data (scope mcp:org)

These tools return your own organisation's data and require the mcp:org scope. The organisation is resolved from your API key and injected server-side — it is never read from the request, so a key can only ever read its own org.

Your Data · Cross-Reference

Join your own assets and findings with Precursor's threat intel.

ToolWhat it does
assess_cve_exposureYour exposure to a specific CVE: your findings + affected assets, watchlist/alert membership, inferred CPE matches, public intel, and recent exploitation.
map_assets_to_actorMap your assets to a threat actor's ATT&CK TTPs and linked CVEs, optionally filtered by vendor.
appliances_exploited_by_actorYour edge appliances tied to CVEs exploited in the wild in the last N days, optionally attributed to a named actor.

Your Data · Attack Surface

Your EdgeProtect attack-surface inventory — assets, ports, services, certs, and more.

ToolWhat it does
list_my_assetsYour EdgeProtect scans with target and roll-up counts.
list_my_softwareDiscovered software: CPE products + detected website technologies.
list_my_vulnerabilitiesYour vulnerability findings with instance counts; filter by severity/CVSS/KEV/has-CVE.
list_my_hostsDiscovered hosts (hostname/FQDN/OS) with IP and open-port counts.
get_open_portsWhich ports are open on a specific asset (hostname/FQDN/IP), with the service on each.
list_my_portsPorts across your assets with host/IP/service; filter by state, port, protocol, or host.
list_my_servicesDetected services (product/version, HTTP server/title, TLS); filter by product/port/SSL.
list_my_ip_addressesIP addresses with geo/ASN/ISP enrichment.
list_my_network_rangesNetwork CIDR ranges attributed to your organisation.
list_my_ssl_certificatesTLS certificates on your services, ordered by expiry.
list_my_dns_recordsDNS records for your domains; filter by record type.
list_my_discovered_domainsDomains found by EdgeProtect discovery (registrar/expiry/nameservers).
list_my_exposed_credentialsBreached credentials for your domains (email/username/source). Passwords are never returned.

Your Data · Watchlist

ToolWhat it does
list_my_relevant_cvesCVEs flagged relevant to your stack, sorted by EPSS.
list_my_favorite_threat_groupsThreat groups your organisation follows.
get_my_industryThe industry group(s) configured for your organisation.

Your Data · Alerts

ToolWhat it does
list_my_alertsYour CVE alert/notification feed; unseen_only available.
get_my_alert_configYour alert watchlist entries and notification recipients.
list_my_domain_alertsBrand/domain intelligence alerts; unread_only available.

Your Data · Supply Chain

ToolWhat it does
list_my_lockfilesDependency lockfiles (SBOM) you've uploaded, with package/findings counts.
check_my_supply_chain_exposureYour dependencies matched against known software-supply-chain incidents.

Your Data · Posture

ToolWhat it does
list_my_triage_findingsYour triaged vulnerabilities (scored, with actor/malware enrichment and action priority).
list_my_domainsDomains your organisation monitors.
list_my_action_plansAI-generated remediation to-do lists.
list_my_reportsThreat-report analyses you've run.