Skip to content

Latest commit

Β 

History

40 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Cyware MCP Server

A powerful Model Context Protocol (MCP) server for seamless AI integration with Cyware Products

Go Version


πŸš€ Overview

Cyware MCP Server is a high-performance Model Context Protocol (MCP) server built in Go, designed to provide AI agents and large language models with secure, standardized access to Cyware's cybersecurity products. This server enables seamless integration between AI systems and various Cyware applications through the standardized MCP protocol.

✨ Features

  • πŸ”— MCP Protocol Compliance: Full implementation based on the Model Context Protocol specification
  • 🎯 Multi-Application Support: Integrated access to Cyware Intel Exchange (CTIX) and Cyware Orchestrate (CO)
  • πŸ”’ Secure AI Integration: Robust authentication and authorization using config.yaml file
  • πŸ› οΈ Tool Definitions: Structured tools for AI agents to interact with Cyware services
  • βš™οΈ Configurable: Easy configuration via YAML files
  • πŸš€ High Performance: Built with Go for optimal speed and reliability

πŸ“ Directory Structure

cyware-mcpserver/
β”œβ”€β”€ πŸ“ applications/
β”‚   β”œβ”€β”€ πŸ“ ctix/                # Cyware Intel Exchange (CTIX) MCP resources and tools
β”‚   β”œβ”€β”€ πŸ“ co/                  # Cyware Orchestrate (CO) MCP resources and tools
β”‚   └── πŸ“ general/             # General MCP capabilities
β”œβ”€β”€ πŸ“ cmd/
β”‚   β”œβ”€β”€ πŸ“„ main.go              # MCP server entry point
β”‚   └── πŸ“„ config.yaml          # MCP server and application configuration
β”œβ”€β”€ πŸ“ common/                  # Shared MCP utilities (client, config, response)
β”œβ”€β”€ πŸ“„ go.mod                   # Go module definition
β”œβ”€β”€ πŸ“„ go.sum                   # Go module dependencies
β”œβ”€β”€ πŸ“„ LICENSE                  # License file
└── πŸ“„ README.md                # Project documentation

πŸƒ Getting Started

πŸ“‹ Prerequisites

Ensure you have the following installed:

  • Go 1.24.2 or higher (To install Go, see https://go.dev/doc/install)
  • Access to Cyware applications (CTIX and CO)
  • MCP-compatible AI client (for example, Claude, Cursor, or more) or language model integration

πŸ“¦ Installation

  1. Clone the repository:

    git clone https://github.com/cyware-labs/cyware-mcpserver.git
    cd cyware-mcpserver
  2. Install dependencies:

    go mod tidy

βš™οΈ Configuration

In cmd/config.yaml, update the following details::

  • Cyware application credentials
  • MCP server transport settings β€” Choose either stdio or sse (with specified port)

πŸš€ Running the MCP Server

  1. Build the server:

    cd cmd
    go build .
  2. Configure Claude Desktop:

  • Quick Guide for setting up MCP on Claude: modelcontextprotocol.io/quickstart/user
  • After building the server, configure the binary path and config path in the claude_desktop_config.json file of Claude Desktop:
{
  "mcpServers": {
    "cywaremcp": {
      "command": "path/to/your/binary/cmd",
      "args": [
        "-config_path",
        "path/to/your/config.yaml"
      ]
    }
  }
}
  1. Restart Claude Desktop to complete the setup and view the available Cyware MCP server tools.

πŸ› οΈ Available MCP Tools

Cyware Intel Exchange (CTIX)

Authentication & User Management

  • login-to-ctix - Login to CTIX and generate authentication token
  • logged-in-user-details - Get details of currently logged in user

CQL Query & Search

  • cql-ctix-grammar-rules - Get CTIX CQL grammar rules
  • get-cql-query-search-result - Run CQL query and return results

Threat Data Management

  • get-threat-data-object-details - Get Threat Data Object details
  • get-threat-data-object-relations - Get Threat Data Object relations
  • get-available-relation-type - Get available relation types

Threat Data Bulk Actions

  • threat-data-list-bulk-action-add-tag - Bulk add tags to threat data objects
  • threat-data-list-bulk-mark-indicator-allowed - Bulk mark indicators as indicator allowed
  • threat-data-list-bulk-unmark-indicator-allowed - Bulk remove indicators from indicator allowed list
  • threat-data-list-bulk-manual-review - Bulk add threat data objects for manual review
  • threat-data-list-bulk-mark-false-positive - Bulk mark indicators as false positive
  • threat-data-list-bulk-unmark-false-positive - Bulk unmark indicators marked as false positives
  • threat-data-list-bulk-update-analyst-tlp - Bulk update analyst TLP of threat data objects
  • threat-data-list-bulk-update-analyst-score - Bulk update analyst scores of threat data objects
  • threat-data-list-bulk-deprecate - Bulk deprecate indicators
  • threat-data-list-bulk-undeprecate - Bulk undeprecate indicators
  • threat-data-list-bulk-add-watchlist - Bulk add threat data objects to watchlist
  • threat-data-list-bulk-remove-watchlist - Bulk remove threat data objects from watchlist
  • threat-data-list-bulk-add-relation - Bulk add relation to threat data objects

Tag Management

  • create-tag-in-ctix - Create new tags in CTIX
  • get-ctix-tags-list - Get list of available tags

Enrichment Tools and Actions

  • get-enrichment-tools-list - Get list of all enrichment tools
  • get-enrichment-tool-details - Get details of an enrichment tool
  • get-enrichment-tool-action-configs - Get action configuration details of enrichment tool
  • enrichment-tool-supported-for-threat-data-object - Get supported enrichment tools for specific threat data types
  • enrich-threat-data-object - Enrich threat data objects using configured tools

Intel Creation

  • quick-add-intel-create - Create intel in CTIX using Quick Add Intel

Cyware Orchestrate (CO)

Authentication & User Management

  • login-to-co - Login to CO and generate the authentication token

Playbooks Details & Execution

  • get-co-playbooks-list - Get the list of playbooks created in CO
  • get-co-playbook-details - Get details of a playbook
  • execute-playbook-in-co - Run CO playbook

CO Apps & Actions

  • get-co-apps-list - Get the list of apps present in CO
  • get-co-app-details _ Get the details of a specific app
  • get-co-actions-of-app - Get list of actions supported by the app
  • get-co-app-action-details - Get the details of an action
  • get-instances-of-co-app - Get the instances configured in the app
  • execute-action-of-co-app - Run action of an app

πŸ“„ License

This project is licensed under the terms specified in the LICENSE file.


About

No description, website, or topics provided.

Resources

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages