Threatweaver

v1.0.0

A powerful MCP server built with NitroStack

Connection Setup

Add via Cursor Settings UI (Settings > Features > MCP > Add New MCP Server):

{
  "mcpServers": {
    // your other mcp servers
    "threatweaver": {
      "url": "https://threatweaver-the-unprompted-amrita-university-amritapuri-campus.app.nitrocloud.ai/mcp"
    }
  }
}

Connect remote tools directly via Claude's Web UI:

Add custom connector BETA
Connect Claude to your data and tools. Learn more about connectors or get started with pre-built ones.
Advanced settings
Only use connectors from developers you trust. Anthropic does not control which tools developers make available and cannot verify that they will work as intended or that they won't change.

Configure custom tools directly via ChatGPT's Web UI:

New App
PNG only. Best results at 256 x 256 px or larger. Max file size: 10 KB
Custom MCP servers introduce risk. Learn more
OpenAI hasn't reviewed this MCP server. Attackers may attempt to steal your data or trick the model into taking unintended actions, including destroying data.

Add the following configuration block under mcpServers in your Antigravity configuration file (~/.gemini/config/mcp_config.json):

{
  "mcpServers": {
    // your other mcp servers
    "threatweaver": {
      "serverUrl": "https://threatweaver-the-unprompted-amrita-university-amritapuri-campus.app.nitrocloud.ai/mcp"
    }
  }
}

Add the following configuration block to your Codex configuration file (~/.codex/config.toml):

[mcp_servers.threatweaver]
url = "https://threatweaver-the-unprompted-amrita-university-amritapuri-campus.app.nitrocloud.ai/mcp"

Connect directly using the Server-Sent Events endpoint:

https://threatweaver-the-unprompted-amrita-university-amritapuri-campus.app.nitrocloud.ai/mcp
Available Tools
investigate_indicator

Investigate an IOC (IP, domain, hash, or URL) across multiple threat intelligence sources (VirusTotal, AbuseIPDB, URLhaus, Shodan). Returns structured findings with reputation, abuse scores, geolocation, and ASN data.

suggest_next_steps

Analyze current investigation context and suggest related IOCs to investigate next. Identifies shared ASNs, malware families, hostnames, and other relationships.

correlate_investigations

Analyze all findings in the current investigation to detect threat patterns. Identifies IOCs sharing ASNs, malware families, registrants, and geographic proximity. This is the core correlation feature.

generate_report

Generate an investigation report in Markdown or STIX 2.1 format. Includes timeline, findings, threat classification, MITRE ATT&CK mappings, and correlation graph.

batch_investigate

Investigate multiple IOCs in bulk with progress streaming. Validates all IOCs first, then investigates each one, updating the investigation context. Returns correlated findings after all IOCs are processed.