Production-ready MCP server for threat hunting providing access to HEARTH community hunts, PEAK Framework for threat hunting reports, threat intelligence enrichment, and advanced analysis capabilities including graph-based correlation, cognitive pattern analysis, and adversary profiling.
This threat hunting server provides 13 tools with mixed definition quality. Naming is verb-forward and generally clear (search_*, get_*, create_*, list_), and all tools have descriptions. However, parameter descriptions are often sparse or generic, many tools lack output schema documentation, and error handling lacks recovery guidance. The server shows promise in domain-specific functionality (MITRE ATT&CK integration, HEARTH/PEAK frameworks) but falls short of production-grade clarity for LLM reasoning. Most tools cluster in the C-grade range (60-69) with only a few reaching B grade.
Analyze MITRE ATT&CK tactic coverage in community hunts. See which tactics have the most community-contributed hunt ideas.
Creates a behavioral PEAK hunt focused on a MITRE ATT&CK technique. This tool emphasizes hunting for behaviors (TTPs) at the top of the Pyramid of Pain, not atomic indicators.
Creates a custom PEAK hunt report with full control over all fields.
Retrieve a specific community hunt by ID. Get detailed information about a specific hunt from the HEARTH database.
Get community hunts for a MITRE ATT&CK tactic. Retrieve hunt hypotheses from the community for a specific tactic.
Get community hunts for a MITRE ATT&CK technique. Find hunts that reference a specific ATT&CK technique ID.
Output schemas undocumented for 10 of 13 tools. Tools return Dict with 'success', 'count', 'hunts', etc., but LLMs cannot plan downstream calls without knowing the structure. This forces agents to probe results via trial and error.
Enum values stated in descriptions instead of JSON Schema enums. Examples: hunt_type in search_community_hunts ('flame', 'ember', 'alchemy') and hunt_type in create_custom_peak_hunt ('H', 'B', 'M') are documented as examples rather than formal enum constraints. This allows LLMs to hallucinate invalid values.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | D | 55 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 19 | - | v1 |
Returns the PEAK template content for reference.
Get recently added community hunts. Discover the latest threat hunting ideas from the community.
Check server health and feature availability. Returns comprehensive diagnostic information about the server, including which features are enabled, configuration status, and resource counts.
Lists all PEAK hunts in the hunts directory.
Get personalized hunt recommendations from community knowledge. AI-powered recommendations based on your environment and threat landscape.
Search HEARTH community hunt database. Search through hundreds of community-curated threat hunting hypotheses from security professionals worldwide.
Suggests behavioral hunt alternatives when given an IOC. This is a KEY function that pivots from bottom-of-pyramid IOCs to top-of-pyramid behavioral hunts.
No error recovery guidance. When a hunt is not found (get_hunt_by_id), technique_id is invalid (get_hunts_for_technique), or ioc_type is unrecognized (suggest_behavioral_hunt_from_ioc), tools return error dicts but offer no actionable next step. Example: 'Hunt H999 not found' should suggest 'Try search_community_hunts() with keywords or tactics.'
No pagination support for tools that may return large result sets. list_hunts and get_recent_community_hunts lack offset/limit documentation and no max result constraints are stated. If the hunts directory has 1000+ items, an uncapped response blows the context window.
WRITE operations lack confirmation or dry-run support. create_behavioral_hunt and create_custom_peak_hunt both modify state but offer no dry-run mode or explicit confirmation. Agents can accidentally create duplicate hunts or malformed records.
Nested object schemas not documented. data_sources in create_behavioral_hunt and create_custom_peak_hunt are described as 'array of objects' with inline property hints (source, key_fields, example) but no formal JSON schema for the nested structure. LLMs cannot construct valid payloads.
Parameter constraints missing. Examples: limit params in search_community_hunts and get_recent_community_hunts lack min/max bounds; tactic, technique_id, and ioc_type lack format constraints. Without validation, LLMs may pass invalid values (negative limits, made-up tactic names).
Response field naming consistency at risk. Tools return 'hunts', 'hunt', or structured nested responses inconsistently. If a downstream tool chain expects hunt.id but create_behavioral_hunt returns a different field name, the agent must infer mapping.