MITRE ATT&CK MCP SERVER TOOLS

55 tools from the MITRE ATT&CK MCP Server MCP Server, categorised by risk level.

READ 54 tools
Read get_all_assets Get all assets in the MITRE ATT&CK framework (ICS domain only) Read get_all_campaigns Get all campaigns in the MITRE ATT&CK framework Read get_all_datacomponents Get all data components in the MITRE ATT&CK framework Read get_all_datasources Get all data sources in the MITRE ATT&CK framework Read get_all_groups Get all threat actor groups in the MITRE ATT&CK framework Read get_all_matrices Get all matrices in the MITRE ATT&CK framework Read get_all_mitigations Get all mitigations in the MITRE ATT&CK framework Read get_all_parent_techniques Get all parent techniques in the MITRE ATT&CK framework Read get_all_software Get all software in the MITRE ATT&CK framework Read get_all_subtechniques Get all subtechniques in the MITRE ATT&CK framework Read get_all_tactics Get all tactics in the MITRE ATT&CK framework Read get_all_techniques Get all techniques in the MITRE ATT&CK framework Read get_assets_targeted_by_technique get_assets_targeted_by_technique Read get_attack_id Get attack ID for given stix ID Read get_campaigns_attributed_to_group get_campaigns_attributed_to_group Read get_campaigns_by_alias Get campaigns by their alias Read get_campaigns_using_software Get all campaigns that use software Read get_campaigns_using_technique get_campaigns_using_technique Read get_datacomponents_detecting_technique get_datacomponents_detecting_technique Read get_groups_attributing_to_campaign Get groups attributing to campaign Read get_groups_by_alias Get MITRE ATT&CK group ID and description by their alias Read get_groups_using_software get_groups_using_software Read get_groups_using_technique get_groups_using_technique Read get_layer_metadata get_layer_metadata Read get_mitigations_mitigating_technique get_mitigations_mitigating_technique Read get_name Get name for given stix ID Read get_object_by_attack_id get_object_by_attack_id Read get_object_by_stix_id Get object by STIX ID (case-sensitive) Read get_objects_by_content get_objects_by_content Read get_objects_by_name get_objects_by_name Read get_objects_by_type get_objects_by_type Read get_objects_created_after Get objects created after a specific timestamp Read get_objects_modified_after Get objects modified after a specific timestamp Read get_parent_technique_of_subtechnique Get parent technique of subtechnique Read get_procedure_examples_by_tactic get_procedure_examples_by_tactic Read get_procedure_examples_by_technique get_procedure_examples_by_technique Read get_revoked_techniques Get all revoked techniques in the MITRE ATT&CK framework Read get_software_by_alias Get software by it's alias Read get_software_used_by_campaign Get software used by campaign Read get_software_used_by_group Get software used by MITRE ATT&CK group STIX id Read get_software_using_technique Get software using technique Read get_stix_type Get object type by stix ID Read get_subtechniques_of_technique Get subtechniques of technique Read get_tactics_by_matrix Get tactics by matrix Read get_tactics_by_technique Get tactics associated with a technique Read get_techniques_by_platform get_techniques_by_platform Read get_techniques_by_tactic Get all techniques of the given tactic Read get_techniques_detected_by_datacomponent get_techniques_detected_by_datacomponent Read get_techniques_mitigated_by_mitigation get_techniques_mitigated_by_mitigation Read get_techniques_targeting_asset Get techniques targeting a specific asset (ICS domain only) Read get_techniques_used_by_campaign Get techniques used by campaign Read get_techniques_used_by_group get_techniques_used_by_group Read get_techniques_used_by_group_software get_techniques_used_by_group_software Read get_techniques_used_by_software Get techniques used by software

Route MITRE ATT&CK MCP Server through PolicyLayer and every one of its 55 tools is checked against your policy before it runs.

GOVERN MITRE ATT&CK →

Enforced before the call runs. Nothing to install.

How many tools does the MITRE ATT&CK MCP Server MCP server have? +

The MITRE ATT&CK MCP Server MCP server exposes 55 tools across 2 categories: Read, Write.

How do I enforce policies on MITRE ATT&CK MCP Server tools? +

Route the MITRE ATT&CK MCP Server server through the PolicyLayer gateway. Define allow, deny, or approval rules per tool in the dashboard; they are enforced on every call before it reaches the server.

What risk categories do MITRE ATT&CK MCP Server tools fall into? +

MITRE ATT&CK MCP Server tools are categorised as Read (54), Write (1). Each category has a recommended default policy.

Enforce policy on every MITRE ATT&CK MCP Server tool call.

Deterministic rules across all 55 MITRE ATT&CK MCP Server tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

42,500+ MCP servers and 110,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.