socradar.io 7 Sept 2026, 10:28 UTC

SOCRadar Connects ChatGPT to Threat Intelligence via MCP

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

SOCRADAR has released an integration that lets the SOCRadar Threat Intelligence MCP app connect ChatGPT to the SOCRadar MCP server via OAuth, exposing licensed intelligence modules as callable tools within a conversation. Analysts can enrich indicators, verify CVE exploitation, and query Dark Web exposure without leaving the chat, keeping all context in a single thread.

The MCP server powers a range of capabilities, including IoC enrichment for IPs, domains, URLs and hashes; vulnerability intelligence with CVE risk and exploitation data; threat actor, malware and ransomware intelligence; identity breach data; and Dark Web investigation tools.

The integration is accessed by linking ChatGPT to the SOCRadar MCP server (https://mcp.socradar[.]com/) and authorising with the user’s SOCRadar subscription and API keys. Module API keys are optional, meaning unavailable tools are hidden unless entitlements permit them.

A practical example in the article describes enriching an IP (e.g., 45.147.230[.]14) and assessing whether it should be blocked, then querying CVE-2024-3400 for risk and exploitation signals, and checking stealer-log exposure for a domain, all within the same ChatGPT conversation. The setup emphasises developer-mode addition of the custom MCP app and cautions that custom apps aren’t reviewed by OpenAI, so organisations should ensure appropriate trust and permissions before enabling access.

View full article

Article by CyberSIXT