SOCRADAR has released an integration that lets the SOCRadar Threat Intelligence MCP app connect ChatGPT to the SOCRadar MCP server via OAuth, exposing licensed intelligence modules as callable tools within a conversation. Analysts can enrich indicators, verify CVE exploitation, and query Dark Web exposure without leaving the chat, keeping all context in a single thread.
The MCP server powers a range of capabilities, including IoC enrichment for IPs, domains, URLs and hashes; vulnerability intelligence with CVE risk and exploitation data; threat actor, malware and ransomware intelligence; identity breach data; and Dark Web investigation tools.
The integration is accessed by linking ChatGPT to the SOCRadar MCP server (https://mcp.socradar[.]com/) and authorising with the user’s SOCRadar subscription and API keys. Module API keys are optional, meaning unavailable tools are hidden unless entitlements permit them.
A practical example in the article describes enriching an IP (e.g., 45.147.230[.]14) and assessing whether it should be blocked, then querying CVE-2024-3400 for risk and exploitation signals, and checking stealer-log exposure for a domain, all within the same ChatGPT conversation. The setup emphasises developer-mode addition of the custom MCP app and cautions that custom apps aren’t reviewed by OpenAI, so organisations should ensure appropriate trust and permissions before enabling access.