@pipeworx/mitre-attck
Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/mitre-attck’s. Install: one-click buttons
Connect to just the @pipeworx/mitre-attck pack
https://gateway.pipeworx.io/mitre-attck/mcp — only @pipeworx/mitre-attck’s own tools, nothing else in the catalog.
No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.
Tools: 7
MITRE ATT&CK MCP — adversary tactics, techniques, and procedures (TTPs). Sources the official STIX 2.1 bundles from MITRE’s GitHub. Cached 1h in-pack.
Tools
technique(id)— technique by ATT&CK id (e.g.T1190,T1059.001)tactic(id_or_short_name)— tactic recordgroup(id)— threat group (e.g.G0007APT28)software(id)— software/malware (e.g.S0002Mimikatz)mitigation(id)— mitigationsearch(query, type?)— substring search across the bundledomains()— list loaded STIX bundles (enterprise, mobile, ics)
Data source
https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json (and mobile + ics).
Tools
- technique — Technique by ATT&CK id.
- tactic — Tactic by id or short name.
- group — Threat group (e.g. G0007).
- software — Software/malware (e.g. S0002).
- mitigation — Mitigation.
- search — Substring search across the bundle.
- domains — List loaded STIX bundles.