MCP Server Let AI agents query alerts, investigate domains and triage incidents.

Connect any MCP-compatible client to DarkStrata over Streamable HTTP. Agents don't just read: they configure webhooks, manage the team and run incident response end to end. DarkStrata is fully headless, and the console is optional.

Scenario 1 of 3: Security posture check
An AI agent session against the DarkStrata MCP serverDemo with sample data

Use it like this

Point your agent at DarkStrata and ask in plain language – it chooses the right tools and chains them automatically.

  • You ask

    Give me a security posture briefing for this morning and flag anything critical.

    The agent runs

    1. security-posture-overview
    2. alerts-list
    3. exposure-summary
  • You ask

    Triage the latest critical alert and draft a remediation plan.

    The agent runs

    1. alerts-list
    2. triage-alert
    3. data-intelligence-query
  • You ask

    Investigate example.co.uk – what's exposed and who's most at risk?

    The agent runs

    1. investigate-domain
    2. data-intelligence-query
    3. data-intelligence-generate-summary
  • You ask

    A staff credential just appeared in a stealer log – suspend the account, open an incident-response export, and push the alert to our ticketing queue.

    The agent runs

    1. users-suspend
    2. incident-response-request
    3. webhooks-create

Connect in minutes

Add DarkStrata to any MCP-compatible client over Streamable HTTP with a single configuration block.

Replace <YOUR_API_KEY> with your DarkStrata API key. Generate one from your account settings.

API keys are scoped. Issue a read-only key to give agents safe, least-privilege access – a key can only call the tools its scopes permit, so analysis and triage stay non-destructive. Add write scopes only for automation that needs to act.

Streamable HTTP endpoint
https://mcp.darkstrata.io/mcp
Claude Desktop, Claude Code and Cursor
{
  "mcpServers": {
    "darkstrata": {
      "type": "streamable-http",
      "url": "https://mcp.darkstrata.io/mcp",
      "headers": {
        "x-api-key": "<YOUR_API_KEY>"
      }
    }
  }
}

What your agent can call

87 tools and 10 live resources, grouped by domain. Every DarkStrata capability, accessible to your AI agents.

Alerts

Query, triage, and manage security alerts. Filter by severity, status, and type.

  • alerts-list
  • alerts-get
  • alerts-get-stats
  • alerts-update-status
  • alerts-delete
  • What each tool does
    alerts-list
    List alerts with filtering and pagination
    alerts-get
    Get detailed information about a specific alert
    alerts-get-stats
    Get aggregate alert statistics and severity breakdown
    alerts-update-status
    Update the status of an alert
    alerts-delete
    Permanently delete an alert
    darkstrata://alerts/stats
    Alert counts by status and severity breakdown

Assets

Manage monitored domains and keywords. Add, remove, and verify assets.

  • assets-list
  • assets-get
  • assets-get-stats
  • assets-register
  • assets-register-bulk
  • assets-delete
  • assets-delete-bulk
  • assets-resubmit-dns
  • What each tool does
    assets-list
    List monitored domain assets with filtering
    assets-get
    Get detailed information about a specific asset
    assets-get-stats
    Get aggregate asset statistics
    assets-register
    Register a new domain asset for monitoring
    assets-register-bulk
    Register multiple domain assets in a single operation
    assets-delete
    Remove a domain asset from monitoring
    assets-delete-bulk
    Remove multiple domain assets from monitoring
    assets-resubmit-dns
    Re-trigger DNS verification for an asset
    darkstrata://assets/stats
    Asset verification statistics

Credential Check

Search compromised credential databases with k-anonymity privacy.

  • credential-check-stats
  • What each tool does
    credential-check-stats
    Get credential check database statistics
    darkstrata://credential-check/stats
    Credential database size and freshness

Data Intelligence

Query infostealer logs, third-party breaches, and credential-exposure events across monitored domains, with naming-rule views, AI exposure summaries, and malware-family threat profiles.

  • data-intelligence-query
  • data-intelligence-get
  • data-intelligence-get-stats
  • data-intelligence-hostnames
  • data-intelligence-get-actions
  • data-intelligence-update-actions
  • data-intelligence-generate-summary
  • data-intelligence-breaches-query
  • data-intelligence-breaches-stats
  • data-intelligence-events-query
  • data-intelligence-events-stats
  • data-intelligence-naming-rules
  • data-intelligence-breaches-update-status
  • data-intelligence-breaches-bulk-status
  • data-intelligence-malware-family-profile
  • What each tool does
    data-intelligence-query
    Query credential exposure data with comprehensive filtering
    data-intelligence-get
    Get details about a specific credential exposure
    data-intelligence-get-stats
    Get data intelligence statistics and threat score distribution
    data-intelligence-hostnames
    List unique hostnames found in credential exposure data
    data-intelligence-get-actions
    Get configured actions for a credential exposure
    data-intelligence-update-actions
    Update actions for a credential exposure
    data-intelligence-generate-summary
    Generate an AI executive summary of an identifier's exposure risk profile
    data-intelligence-breaches-query
    List third-party breach exposures with filtering and pagination
    data-intelligence-breaches-stats
    Aggregate statistics over third-party breach exposures
    data-intelligence-events-query
    List outbound credential-exposure events (one row per identifier-service match)
    data-intelligence-events-stats
    Distribution statistics for outbound credential-exposure events
    data-intelligence-naming-rules
    List the organisation's active asset naming rules
    data-intelligence-breaches-update-status
    Update the status of a single breach exposure
    data-intelligence-breaches-bulk-status
    Bulk-update the status across multiple breach exposures
    data-intelligence-malware-family-profile
    Get an AI threat-intelligence profile for a stealer malware family
    darkstrata://data-intelligence/stats
    Data intelligence metrics and monthly trends

Groups

Organise and manage identity groups for monitoring.

  • groups-list
  • groups-get
  • groups-create
  • groups-update
  • groups-delete
  • groups-list-members
  • groups-add-members
  • groups-update-member
  • groups-remove-member
  • groups-move-members
  • What each tool does
    groups-list
    List identity groups with filtering and pagination
    groups-get
    Get detailed information about a specific group
    groups-create
    Create a new identity group
    groups-update
    Update a group's name, description, or configuration
    groups-delete
    Delete a group
    groups-list-members
    List the members of a group
    groups-add-members
    Add or replace group members in bulk
    groups-update-member
    Update a group member's details or status
    groups-remove-member
    Remove a member from a group
    groups-move-members
    Move members between groups

Incident Response

Request, download, and manage encrypted credential data exports for incident investigation — end to end, no console required. Available to verified partners only; contact us to enable it for your organisation.

  • incident-response-request
  • incident-response-list
  • incident-response-get
  • incident-response-get-stats
  • incident-response-download
  • incident-response-get-password
  • incident-response-list-pgp-keys
  • incident-response-add-pgp-key
  • incident-response-remove-pgp-key
  • What each tool does
    incident-response-request
    Request a new credential data export
    incident-response-list
    List credential data export requests
    incident-response-get
    Get details about a specific export request
    incident-response-get-stats
    Get incident response export statistics
    incident-response-download
    Get a presigned download link for a completed export
    incident-response-get-password
    Retrieve the archive password for a password-encrypted export
    incident-response-list-pgp-keys
    List the organisation's PGP export keys
    incident-response-add-pgp-key
    Add a PGP export key to the organisation
    incident-response-remove-pgp-key
    Remove one of the organisation's PGP export keys
    darkstrata://incident-response/stats
    Incident response export statistics

Lens

Manage private security awareness invites and review completion metrics.

  • lens-invite-send
  • lens-token-revoke
  • What each tool does
    lens-invite-send
    Send Lens credential review invitations
    lens-token-revoke
    Revoke a Lens review token

Organisations

Manage organisations, view statistics, and update organisation details.

  • organisations-list
  • organisations-get
  • organisations-get-stats
  • organisations-update
  • organisations-list-tenant-plans
  • organisations-create
  • organisations-set-plan
  • organisations-generate-api-key
  • What each tool does
    organisations-list
    List organisations accessible to the current API key
    organisations-get
    Get detailed information about an organisation
    organisations-get-stats
    Get organisation-level statistics
    organisations-update
    Update organisation details
    organisations-list-tenant-plans
    List the plans you can give customer organisations
    organisations-create
    Create a customer organisation on a plan
    organisations-set-plan
    Change a customer organisation's plan
    organisations-generate-api-key
    Generate an API key for a customer organisation
    darkstrata://organisations/stats
    Organisation-level statistics
    darkstrata://organisations/alerts/stats
    Organisation-level alert statistics

SIEM & STIX Export

Export alerts and indicators as STIX 2.1 bundles, and credential-exposure events in CEF or LEEF format for SIEM ingestion.

  • stix-export-alerts
  • stix-export-alert
  • stix-export-indicators
  • siem-export-events
  • siem-export-alert-events
  • What each tool does
    stix-export-alerts
    Export alerts as STIX 2.1 bundles for SIEM integration
    stix-export-alert
    Export a specific alert as a STIX 2.1 bundle
    stix-export-indicators
    Export STIX 2.1 indicators for SIEM ingestion
    siem-export-events
    Export credential-exposure events in CEF or LEEF format for SIEM ingestion
    siem-export-alert-events
    Export the credential-exposure events for a specific alert in CEF or LEEF format

Usage

Monitor API usage, billing period summaries, and per-key breakdowns.

  • usage-get
  • usage-get-summary
  • usage-get-by-key
  • What each tool does
    usage-get
    Get API usage data with optional filtering
    usage-get-summary
    Get API usage summary for the current billing period
    usage-get-by-key
    Get API usage breakdown by individual API key
    darkstrata://usage/summary
    API usage summary for current billing period
    darkstrata://usage/by-key
    API usage breakdown per API key

Team

Manage the team headlessly: visibility, invitations, and automated suspend/unsuspend for compromised-account response. Admin role changes stay console-only.

  • users-list
  • users-list-roles
  • users-invite
  • users-list-invitations
  • users-resend-invitation
  • users-revoke-invitation
  • users-suspend
  • users-unsuspend
  • What each tool does
    users-list
    List team members with role, status, and activity
    users-list-roles
    List assignable user roles
    users-invite
    Invite a team member (non-admin roles, verified domains only)
    users-list-invitations
    List team invitations and their status
    users-resend-invitation
    Resend a pending invitation with a fresh link
    users-revoke-invitation
    Revoke a pending invitation
    users-suspend
    Suspend a team member's account immediately
    users-unsuspend
    Restore a suspended team member's account

Webhooks

Configure event-driven delivery of alerts and exposures to your own endpoints, Slack, or SIEM — no polling required.

  • webhooks-list
  • webhooks-get
  • webhooks-list-deliveries
  • webhooks-list-events
  • webhooks-create
  • webhooks-update
  • webhooks-delete
  • webhooks-test
  • What each tool does
    webhooks-list
    List configured webhooks with status and last delivery result
    webhooks-get
    Get a webhook's full configuration and subscribed events
    webhooks-list-deliveries
    See each delivery to a webhook and why any failed
    webhooks-list-events
    Browse the catalogue of subscribable webhook events
    webhooks-create
    Create a webhook to push alerts and exposures to your endpoint
    webhooks-update
    Update a webhook's configuration or event subscriptions
    webhooks-delete
    Permanently delete a webhook
    webhooks-test
    Send a test event to verify a webhook endpoint

Composite Workflows

Multi-step investigation tools that combine data across domains into unified reports.

  • security-posture-overview
  • investigate-domain
  • triage-alert
  • exposure-summary
  • dashboard-exposure-summary
  • What each tool does
    security-posture-overview
    Comprehensive security posture overview combining multiple stats
    investigate-domain
    Full investigation context for a domain
    triage-alert
    Gather all context needed to triage a specific alert
    exposure-summary
    Credential exposure summary across all monitored domains
    dashboard-exposure-summary
    Headline credential-exposure metrics across all verified domains
    darkstrata://dashboard
    Dashboard widget data including recent activity

Built-in investigation workflows

Pre-built multi-step prompts that guide AI agents through common security tasks.

Triage Alert

triage-alert

Fetch an alert, enrich it with threat context, suggest a severity rating, and draft a response plan.

Analyse Exposure

analyse-exposure

Pull exposure data for a domain, cross-reference with credential databases, and assess organisational risk.

Incident Response

incident-response-workflow

Gather all relevant alerts, exposures, and threat data for a domain and produce an incident timeline.

Onboard Assets

onboard-assets

Walk through adding domains and keywords to monitoring with verification steps.

Executive Summary

executive-summary

Compile dashboard statistics, recent alerts, and exposure trends into a board-ready briefing.

Connect your AI to real threat intelligence

Issue a scoped API key and point any MCP-compatible client at DarkStrata.