OpenPorts
-822109421 | 2026-10-06T09:02:17
MCP Server1.27.1
HTTP/1.1 406 Not Acceptable
content-type: application/json
mcp-session-id: a50513ef92f047c8aea977fc9139b07c
x-cloud-trace-context: 0aa8b9bc2bb7f03b7fca29509f5db584;o=1
date: Tue, 06 Oct 2026 09:02:17 GMT
server: Google Frontend
Content-Length: 126
Via: 1.1 google
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
MCP Server:
Server Name: mitre-attack
Server Version: 1.27.1
Protocol Version: 2025-06-18
Transport: streamable-http
Tools #1:
Name: get_object_by_attack_id
Description: Get object by ATT&CK ID (case-sensitive)
Args:
attack_id: ATT&CK ID to find associated object for
stix_type: TheSTIX object type (must be 'attack-pattern', 'malware', 'tool', 'intrusion-set',
'campaign', 'course-of-action', 'x-mitre-matrix', 'x-mitre-tactic',
'x-mitre-data-source', 'x-mitre-data-component', or 'x-mitre-asset')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #2:
Name: get_object_by_stix_id
Description: Get object by STIX ID (case-sensitive)
Args:
stix_id: ATT&CK ID to find associated object for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #3:
Name: get_objects_by_name
Description: Get objects by name (case-sensitive)
Args:
name: Name of the object to search for
stix_type: TheSTIX object type (must be 'attack-pattern', 'malware', 'tool', 'intrusion-set',
'campaign', 'course-of-action', 'x-mitre-matrix', 'x-mitre-tactic',
'x-mitre-data-source', 'x-mitre-data-component', or 'x-mitre-asset')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #4:
Name: get_objects_by_content
Description: Get objects by the content of their description
Args:
name: Name of the object to search for
object_type: The STIX object type (must be 'attack-pattern', 'malware', 'tool', 'intrusion-set',
'campaign', 'course-of-action', 'x-mitre-matrix', 'x-mitre-tactic',
'x-mitre-data-source', 'x-mitre-data-component', or 'x-mitre-asset')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #5:
Name: get_stix_type
Description: Get object type by stix ID
Args:
stix_id: ATT&CK ID to find associated object type for
domain: Domain name ('enterprise', 'mobile', or 'ics')
Tools #6:
Name: get_attack_id
Description: Get attack ID for given stix ID
Args:
stix_id: STIX ID to find associated ATT&CK ID for
domain: Domain name ('enterprise', 'mobile', or 'ics')
Tools #7:
Name: get_name
Description: Get name for given stix ID
Args:
stix_id: STIX ID to find associated name for
domain: Domain name ('enterprise', 'mobile', or 'ics')
Tools #8:
Name: get_groups_by_alias
Description: Get MITRE ATT&CK group ID and description by their alias
Args:
alias: alias of a MITRE ATT&CK group
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #9:
Name: get_techniques_used_by_group
Description: Get all MITRE ATT&CK techniques used by group by group STIX ID
Args:
group_stix_id: Group STIX ID belonging to requested MITRE ATT&CK group
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #10:
Name: get_software_used_by_group
Description: Get software used by MITRE ATT&CK group STIX id
Args:
group_stix_id: Group STIX ID belonging to requested MITRE ATT&CK group
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #11:
Name: get_campaigns_attributed_to_group
Description: Get all campaigns attributed to group by group STIX ID
Args:
group_stix_id: Group STIX ID belonging to requested MITRE ATT&CK group
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #12:
Name: get_techniques_used_by_group_software
Description: Get techniques used by group's software
Args:
group_stix_id: Group STIX ID to check what software they use, and what techniques that software uses
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #13:
Name: get_groups_using_technique
Description: Get groups using a technique by its STIX ID
Args:
technique_stix_id: Technique STIX ID to check what groups are associated with it.
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #14:
Name: get_groups_using_software
Description: Get groups using software by software name
Args:
software_stix_id: Software STIX ID to check which groups use the given software
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #15:
Name: get_groups_attributing_to_campaign
Description: Get groups attributing to campaign
Args:
campaign_stix_id: Campaign STIX ID to look up what groups have been attributed to it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #16:
Name: get_software_by_alias
Description: Get software by it's alias
Args:
alias: Software name alias to find in MITRE ATT&CK
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #17:
Name: get_software_using_technique
Description: Get software using technique
Args:
technique_stix_id: Technique STIX ID to search software that uses it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #18:
Name: get_techniques_used_by_software
Description: Get techniques used by software
Args:
software_stix_id: Software STIX ID to check what techniques are associated with it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #19:
Name: get_all_techniques
Description: Get all techniques in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #20:
Name: get_all_subtechniques
Description: Get all subtechniques in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #21:
Name: get_all_parent_techniques
Description: Get all parent techniques in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #22:
Name: get_all_groups
Description: Get all threat actor groups in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #23:
Name: get_all_software
Description: Get all software in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #24:
Name: get_all_mitigations
Description: Get all mitigations in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #25:
Name: get_all_tactics
Description: Get all tactics in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #26:
Name: get_all_matrices
Description: Get all matrices in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #27:
Name: get_all_campaigns
Description: Get all campaigns in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #28:
Name: get_all_datasources
Description: Get all data sources in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #29:
Name: get_all_datacomponents
Description: Get all data components in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #30:
Name: get_all_assets
Description: Get all assets in the MITRE ATT&CK framework (ICS domain only)
Args:
domain: Domain name ('ics')
include_description: Whether to include description in the output (default is False)
Tools #31:
Name: get_campaigns_using_technique
Description: Get all campaigns in which a technique is used by its STIX ID
Args:
technique_stix_id: Technique STIX ID to look up campaigns in which it is used
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #32:
Name: get_techniques_used_by_campaign
Description: Get techniques used by campaign
Args:
campaign_stix_id: Campaign STIX ID to check what techniques are used in it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #33:
Name: get_campaigns_using_software
Description: Get all campaigns that use software
Args:
software_stix_id: Software STIX ID to look up campaigns in which it is used
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #34:
Name: get_software_used_by_campaign
Description: Get software used by campaign
Args:
campaign_stix_id: Campaign STIX ID to look up what software has been used in it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #35:
Name: get_techniques_by_platform
Description: Get techniques by the platform provided (Windows, Linux etc.)
Args:
platform: Platform (Windows, Linux etc.) to find associated techniques for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #36:
Name: get_parent_technique_of_subtechnique
Description: Get parent technique of subtechnique
Args:
technique_stix_id: Subtechnique STIX ID to check what its parent technique is
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #37:
Name: get_subtechniques_of_technique
Description: Get subtechniques of technique
Args:
technique_stix_id: Technique STIX ID to check what its subtechniques are
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #38:
Name: get_techniques_by_tactic
Description: Get all techniques of the given tactic
Args:
tactic: Tactic name to lookup techniques for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #39:
Name: get_techniques_mitigated_by_mitigation
Description: Get techniques mitigated by mitigation
Args:
mitigation_stix_id: Mitigation STIX ID to check what techniques are mitigated by it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #40:
Name: get_mitigations_mitigating_technique
Description: Get mitigations mitigating technique
Args:
technique_stix_id: Technique STIX ID to what mitigations are mitigating this technique
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #41:
Name: get_datacomponents_detecting_technique
Description: Get datacomponents that detect the given technique
Args:
technique_stix_id: Technique STIX ID to check what datacomponents detect it
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #42:
Name: get_techniques_detected_by_datacomponent
Description: Get techniques detected by a datacomponent
Args:
datacomponent_stix_id: Datacomponent STIX ID to check what techniques it detects
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #43:
Name: get_procedure_examples_by_technique
Description: Get procedure examples by technique STIX ID (shows how groups use a technique)
Args:
technique_stix_id: Technique STIX ID to check how they are used and in what procedure
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #44:
Name: get_assets_targeted_by_technique
Description: Get assets targeted by technique STIX ID (shows how assets are targeted by technique), only pertains to ICS domain
Args:
technique_stix_id: Technique STIX ID to check what assets are targeted by it
domain: Domain name ('ics')
include_description: Whether to include description in the output (default is False)
Tools #45:
Name: get_campaigns_by_alias
Description: Get campaigns by their alias
Args:
alias: Alias to find associated campaigns for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #46:
Name: get_objects_by_type
Description: Get objects by STIX type
Args:
stix_type: TheSTIX object type (must be 'attack-pattern', 'malware', 'tool', 'intrusion-set',
'campaign', 'course-of-action', 'x-mitre-matrix', 'x-mitre-tactic',
'x-mitre-data-source', 'x-mitre-data-component', or 'x-mitre-asset')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #47:
Name: get_tactics_by_matrix
Description: Get tactics by matrix
Args:
matrix_stix_id: Matrix STIX ID to find associated tactics for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #48:
Name: get_tactics_by_technique
Description: Get tactics associated with a technique
Args:
technique_stix_id: Technique STIX ID to find associated tactics for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #49:
Name: get_procedure_examples_by_tactic
Description: Get procedure examples by tactic (shows how groups use techniques in this tactic)
Args:
tactic: Tactic name to check procedure examples for
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #50:
Name: get_techniques_targeting_asset
Description: Get techniques targeting a specific asset (ICS domain only)
Args:
asset_stix_id: Asset STIX ID to find techniques targeting it
domain: Domain name ('ics')
include_description: Whether to include description in the output (default is False)
Tools #51:
Name: get_objects_created_after
Description: Get objects created after a specific timestamp
Args:
timestamp: ISO format timestamp string (e.g., '2020-01-01T00:00:00Z')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #52:
Name: get_objects_modified_after
Description: Get objects modified after a specific timestamp
Args:
timestamp: ISO format timestamp string (e.g., '2020-01-01T00:00:00Z')
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #53:
Name: get_revoked_techniques
Description: Get all revoked techniques in the MITRE ATT&CK framework
Args:
domain: Domain name ('enterprise', 'mobile', or 'ics')
include_description: Whether to include description in the output (default is False)
Tools #54:
Name: generate_layer
Description: Generate an ATT&CK navigator layer in JSON format based on a matching ATT&CK ID value
Args:
attack_id: ATT&CK ID to generate ATT&CK navigator layer for. Valid match values are single ATT&CK ID's for group (GXXX), mitigation (MXXX), software (SXXX), and data component objects (DXXX) within the selected ATT&CK data. NEVER directly input a technique (TXXX). If an invalid match happens, or if multiple ATT&CK ID's are provided, present the user with an error message.
score: Score to assign to each technique in the layer
domain: Domain name ('enterprise', 'mobile', or 'ics')
Tools #55:
Name: get_layer_metadata
Description:
Always call this tool whenever a prompt requires the generation of a MITRE ATT&CK Navigator Layer,
such as the generate_layer tool. Always insert this metadata in the generated layer.
Args:
domain (str, optional): The ATT&CK domain ('enterprise', 'mobile', or 'ics'). Defaults to 'enterprise'.
Returns:
str: JSON string containing the appropriate layer metadata
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
5a:bd:22:d8:5e:81:9c:b9:0a:8e:b3:41:78:5c:80:85
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Google Trust Services, CN=WR3
Validity
Not Before: Sep 9 09:57:36 2026 GMT
Not After : Dec 8 10:51:50 2026 GMT
Subject: CN=dlab-mcp.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
d8:66:d0:2b:d4:19:78:33:fd:85:0b:7e:b0:12:aa:17:
14:40:26:6d:67:c6:94:93:d3:c4:1e:34:7b:ad:68:64:
ef:16:f2:bf:ce:ff:c0:b2:71:6b:d4:06:53:fd:12:d8:
69:eb:d1:e9:f2:50:99:b1:39:13:94:5c:99:06:be:a1:
dc:6c:90:fb:9d:85:3b:1a:f5:5f:cf:b1:32:0e:f4:6d:
fc:60:60:d7:37:ae:c6:b4:bc:16:5b:89:9c:05:36:92:
df:f0:41:40:12:ce:12:73:5d:28:af:8a:7e:ba:1f:7d:
59:6b:4f:71:ee:4f:58:ec:e8:bd:10:bb:5f:42:54:7d:
30:cf:59:82:af:89:fe:d8:68:bc:61:5a:94:d0:63:86:
49:6d:32:51:a9:b8:0b:82:5f:09:db:47:e7:a3:dc:5e:
6e:b9:16:81:fd:e2:d6:41:68:0f:67:92:71:01:10:44:
5a:54:de:86:b3:84:a9:5e:5f:a1:0e:1a:6f:42:b6:4f:
9d:68:3f:9b:79:1e:66:46:55:85:01:68:e6:25:75:ef:
28:63:86:47:4a:6d:48:7f:35:7f:8b:8c:8a:2d:00:df:
6d:59:63:f7:3c:d2:37:1f:6a:99:00:c5:97:89:3b:d4:
ce:e2:7a:07:7a:33:2a:ee:e7:8c:8b:dc:c9:d0:8a:83
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
88:16:FB:DD:BC:A2:CA:77:B4:E2:49:2A:DC:24:4E:78:CF:64:4C:3F
X509v3 Authority Key Identifier:
C7:81:F5:FD:8E:88:D9:00:3C:4D:63:A2:50:31:24:A0:CE:23:FE:23
Authority Information Access:
CA Issuers - URI:http://i.pki.goog/wr3.crt
X509v3 Subject Alternative Name:
DNS:dlab-mcp.com
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
X509v3 CRL Distribution Points:
Full Name:
URI:http://c.pki.goog/wr3/6ePRCsEQW_0.crl
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
Timestamp : Sep 9 10:57:39.521 2026 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:CF:D2:85:8C:B0:09:9E:E2:13:3A:2D:
3F:B8:82:B3:48:8A:A7:06:98:2A:A4:D1:BA:B2:94:E5:
45:FA:BC:52:9D:02:20:72:0E:CD:78:9D:C7:AB:AD:77:
69:C7:91:DD:E1:8A:A1:50:66:7D:56:BA:86:C5:33:E8:
70:AC:B8:AE:BE:AE:4E
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
Timestamp : Sep 9 10:57:37.491 2026 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:E0:60:23:27:B1:8B:F3:A8:63:51:36:
85:35:28:7A:1C:85:F8:12:B6:19:A9:24:28:74:85:D2:
DE:C5:8F:F3:E1:02:21:00:D2:01:84:87:25:A7:C3:15:
86:40:2B:11:6C:3E:E5:90:2E:44:B8:DD:05:3A:A2:34:
0F:3B:24:0F:88:9F:81:B6
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
16:66:b1:11:9f:08:0d:7c:88:b9:41:e0:bc:e4:7f:d4:97:62:9f:aa:36:42:45:b8:
5d:71:f4:08:d0:ff:10:eb:c5:c1:79:14:aa:f6:29:41:b7:39:1c:9f:19:2c:d8:e8:
46:6c:d4:aa:96:3b:53:78:61:51:97:85:bd:d1:89:64:c6:7a:35:6a:22:5c:64:a2:
b9:3c:04:ca:28:d3:d8:0b:62:0a:14:5a:58:00:46:58:f5:50:66:64:95:c4:ad:0b:
8d:9e:c3:d8:a6:15:6c:85:28:ce:d1:54:29:e0:92:19:92:7d:0c:18:ad:fb:46:e3:
da:bc:91:c3:19:d2:0e:0c:66:b7:d7:2e:50:fa:38:a0:e6:5f:f9:71:ef:4a:38:5b:
b8:35:f9:be:05:81:18:7f:4c:51:d0:5e:42:98:5e:fb:ec:72:08:e8:aa:56:71:3c:
aa:95:41:b4:80:a5:3e:1b:2e:82:26:24:1b:09:8c:88:64:6f:01:e8:8a:0b:82:4d:
a1:4e:a1:7d:60:5c:d3:e5:88:bc:df:af:10:3e:db:93:83:ca:a1:e2:e9:9e:73:99:
b9:e9:6e:07:53:a7:fe:07:6c:30:13:68:9e:76:52:9a:02:12:b7:7b:0c:c5:4f:5d:
42:df:01:60:5b:55:3f:3a:e4:91:4b:1a:5f:45:ef:0e