The pairing that matters is CVE detail with EPSS exploit probability and KEV status: severity alone does not tell you what to fix first, and this returns the numbers that do. The rest of the surface follows the same shape — a domain investigation composes DNS, certificates, subdomains and headers into one report, and a dependency list can be checked in bulk instead of one CVE at a time.
A hosted security-intelligence server built on public authorities: NVD, CISA KEV, FIRST EPSS, MITRE ATLAS and D3FEND, plus live domain, email and web checks.
- Vulnerability lookup that answers the question you actually have: a CVE's details and CVSS, whether it is on the Known Exploited list, exploit references, and a composite risk score
- CVE search and leading-vulnerability views, with bulk lookup for a whole dependency list
- The adversarial catalogues navigable — MITRE ATLAS techniques and case studies looked up or searched, D3FEND defences resolved for a given attack technique, coverage assessed, and CWE entries and Sigma detection rules retrieved
- Attack-surface investigation on a domain: DNS and WHOIS, SSL, subdomain enumeration, technology fingerprinting, security headers, robots.txt, redirect chains and Wayback history, rolled into a domain report or a full audit
- A technology-stack CVE audit that turns a fingerprint into the vulnerabilities that apply to it
- Email checks — MX records, security posture, disposable-address detection and verification without SMTP probing
- Threat intelligence on indicators: IOC and hash lookup singly or in bulk, phishing checks, breached-password checks and username lookup
- Network context: IP and ASN lookup, phone lookup, and brand, SEO and geo audits
- Code-security checks for exposed secrets, injection patterns and vulnerable dependencies
- Resources for browsing the ATLAS, D3FEND and CWE catalogues, and a triage prompt
No signup and no API key. It is a hosted endpoint at https://api.contrastcyber.com/mcp/ — connect any client to it, or install the packaged extension for Claude Desktop. The web-intelligence tools operate under a stated ethical floor: per-target throttling, robots.txt respected, and no SMTP probing.
One command — npx -y mcp-remote https://api.contrastcyber.com/mcp/
