You ask
Give me a security posture briefing for this morning and flag anything critical.
The agent runs
security-posture-overviewalerts-listexposure-summary
Connect any MCP-compatible client to DarkStrata over Streamable HTTP. Agents don't just read: they configure webhooks, manage the team and run incident response end to end. DarkStrata is fully headless, and the console is optional.
Point your agent at DarkStrata and ask in plain language – it chooses the right tools and chains them automatically.
You ask
Give me a security posture briefing for this morning and flag anything critical.
The agent runs
security-posture-overviewalerts-listexposure-summaryYou ask
Triage the latest critical alert and draft a remediation plan.
The agent runs
alerts-listtriage-alertdata-intelligence-queryYou ask
Investigate example.co.uk – what's exposed and who's most at risk?
The agent runs
investigate-domaindata-intelligence-querydata-intelligence-generate-summaryYou ask
A staff credential just appeared in a stealer log – suspend the account, open an incident-response export, and push the alert to our ticketing queue.
The agent runs
users-suspendincident-response-requestwebhooks-createAdd DarkStrata to any MCP-compatible client over Streamable HTTP with a single configuration block.
Replace <YOUR_API_KEY> with your DarkStrata API key. Generate one from your account settings.
API keys are scoped. Issue a read-only key to give agents safe, least-privilege access – a key can only call the tools its scopes permit, so analysis and triage stay non-destructive. Add write scopes only for automation that needs to act.
https://mcp.darkstrata.io/mcp{
"mcpServers": {
"darkstrata": {
"type": "streamable-http",
"url": "https://mcp.darkstrata.io/mcp",
"headers": {
"x-api-key": "<YOUR_API_KEY>"
}
}
}
}87 tools and 10 live resources, grouped by domain. Every DarkStrata capability, accessible to your AI agents.
Query, triage, and manage security alerts. Filter by severity, status, and type.
alerts-listalerts-getalerts-get-statsalerts-update-statusalerts-deletealerts-listalerts-getalerts-get-statsalerts-update-statusalerts-deletedarkstrata://alerts/statsManage monitored domains and keywords. Add, remove, and verify assets.
assets-listassets-getassets-get-statsassets-registerassets-register-bulkassets-deleteassets-delete-bulkassets-resubmit-dnsassets-listassets-getassets-get-statsassets-registerassets-register-bulkassets-deleteassets-delete-bulkassets-resubmit-dnsdarkstrata://assets/statsSearch compromised credential databases with k-anonymity privacy.
credential-check-statscredential-check-statsdarkstrata://credential-check/statsQuery infostealer logs, third-party breaches, and credential-exposure events across monitored domains, with naming-rule views, AI exposure summaries, and malware-family threat profiles.
data-intelligence-querydata-intelligence-getdata-intelligence-get-statsdata-intelligence-hostnamesdata-intelligence-get-actionsdata-intelligence-update-actionsdata-intelligence-generate-summarydata-intelligence-breaches-querydata-intelligence-breaches-statsdata-intelligence-events-querydata-intelligence-events-statsdata-intelligence-naming-rulesdata-intelligence-breaches-update-statusdata-intelligence-breaches-bulk-statusdata-intelligence-malware-family-profiledata-intelligence-querydata-intelligence-getdata-intelligence-get-statsdata-intelligence-hostnamesdata-intelligence-get-actionsdata-intelligence-update-actionsdata-intelligence-generate-summarydata-intelligence-breaches-querydata-intelligence-breaches-statsdata-intelligence-events-querydata-intelligence-events-statsdata-intelligence-naming-rulesdata-intelligence-breaches-update-statusdata-intelligence-breaches-bulk-statusdata-intelligence-malware-family-profiledarkstrata://data-intelligence/statsOrganise and manage identity groups for monitoring.
groups-listgroups-getgroups-creategroups-updategroups-deletegroups-list-membersgroups-add-membersgroups-update-membergroups-remove-membergroups-move-membersgroups-listgroups-getgroups-creategroups-updategroups-deletegroups-list-membersgroups-add-membersgroups-update-membergroups-remove-membergroups-move-membersRequest, download, and manage encrypted credential data exports for incident investigation — end to end, no console required. Available to verified partners only; contact us to enable it for your organisation.
incident-response-requestincident-response-listincident-response-getincident-response-get-statsincident-response-downloadincident-response-get-passwordincident-response-list-pgp-keysincident-response-add-pgp-keyincident-response-remove-pgp-keyincident-response-requestincident-response-listincident-response-getincident-response-get-statsincident-response-downloadincident-response-get-passwordincident-response-list-pgp-keysincident-response-add-pgp-keyincident-response-remove-pgp-keydarkstrata://incident-response/statsManage private security awareness invites and review completion metrics.
lens-invite-sendlens-token-revokelens-invite-sendlens-token-revokeManage organisations, view statistics, and update organisation details.
organisations-listorganisations-getorganisations-get-statsorganisations-updateorganisations-list-tenant-plansorganisations-createorganisations-set-planorganisations-generate-api-keyorganisations-listorganisations-getorganisations-get-statsorganisations-updateorganisations-list-tenant-plansorganisations-createorganisations-set-planorganisations-generate-api-keydarkstrata://organisations/statsdarkstrata://organisations/alerts/statsExport alerts and indicators as STIX 2.1 bundles, and credential-exposure events in CEF or LEEF format for SIEM ingestion.
stix-export-alertsstix-export-alertstix-export-indicatorssiem-export-eventssiem-export-alert-eventsstix-export-alertsstix-export-alertstix-export-indicatorssiem-export-eventssiem-export-alert-eventsMonitor API usage, billing period summaries, and per-key breakdowns.
usage-getusage-get-summaryusage-get-by-keyusage-getusage-get-summaryusage-get-by-keydarkstrata://usage/summarydarkstrata://usage/by-keyManage the team headlessly: visibility, invitations, and automated suspend/unsuspend for compromised-account response. Admin role changes stay console-only.
users-listusers-list-rolesusers-inviteusers-list-invitationsusers-resend-invitationusers-revoke-invitationusers-suspendusers-unsuspendusers-listusers-list-rolesusers-inviteusers-list-invitationsusers-resend-invitationusers-revoke-invitationusers-suspendusers-unsuspendConfigure event-driven delivery of alerts and exposures to your own endpoints, Slack, or SIEM — no polling required.
webhooks-listwebhooks-getwebhooks-list-deliverieswebhooks-list-eventswebhooks-createwebhooks-updatewebhooks-deletewebhooks-testwebhooks-listwebhooks-getwebhooks-list-deliverieswebhooks-list-eventswebhooks-createwebhooks-updatewebhooks-deletewebhooks-testMulti-step investigation tools that combine data across domains into unified reports.
security-posture-overviewinvestigate-domaintriage-alertexposure-summarydashboard-exposure-summarysecurity-posture-overviewinvestigate-domaintriage-alertexposure-summarydashboard-exposure-summarydarkstrata://dashboardPre-built multi-step prompts that guide AI agents through common security tasks.
triage-alertFetch an alert, enrich it with threat context, suggest a severity rating, and draft a response plan.
analyse-exposurePull exposure data for a domain, cross-reference with credential databases, and assess organisational risk.
incident-response-workflowGather all relevant alerts, exposures, and threat data for a domain and produce an incident timeline.
onboard-assetsWalk through adding domains and keywords to monitoring with verification steps.
executive-summaryCompile dashboard statistics, recent alerts, and exposure trends into a board-ready briefing.
Issue a scoped API key and point any MCP-compatible client at DarkStrata.