A threat intelligence MCP server for Claude Code that enables lookup of IOCs, threat feeds, breached credentials, CVEs, and dark web data.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.FASTMCP_PORTMCP_PORTDB_PATHABUSECH_API_KEY— [abuse.ch](https://abuse.ch/) (URLhaus, MalwareBazaar, ThreatFox, Feodo) Malware URLs, hashes, C2s, botnet IPs FreeOTX_API_KEY— [AlienVault OTX](https://otx.alienvault.com/) Community threat pulses, IOC enrichment FreeHIBP_API_KEY— [HIBP Email](https://haveibeenpwned.com/API/Key) Email breach lookup $4.50/moLEAKCHECK_API_KEY— [LeakCheck](https://leakcheck.io/) Dark web breach data (7B+ records) $10/moMCP_THREATINTEL_AUTH_TOKEN— Optional bearer-token auth: set (generate with openssl rand -hex 32) and every HTTP client must send Authorization: Bearer <token>. Unset = no auth (single-host trusted-boundary default).FASTMCP_HOSTMCP_HOST[](https://m8ven.ai/mcp/pete-builds-mcp-threatintel-1db1or)