🛠️ MISP Tool MCP Server: All 44 Operations

Zero-config MCP server exposing all 44 MISP Tool operations to AI agents. Pre-built with official n8n integration, error handling, and AI parameter population.

n8n
🛠️ MISP Tool MCP Server: All 44 Operations

This workflow creates a fully operational MCP (Model Context Protocol) server that exposes every single one of the 44 MISP Tool operations directly to AI agents. MISP (Malware Information Sharing Platform) is a powerful open-source threat intelligence platform, and this server allows seamless integration without any manual configuration. The MCP Trigger node acts as the endpoint, routing requests to pre-configured nodes for operations across Attributes (create/delete/get/update/filter), Events (create/delete/get/publish/unpublish/update/filter), Event tags, Feeds (create/disable/enable/get/update), Galaxies (delete/get/list), and more including Noticelists.

Key benefits include zero-setup deployment—just import, activate, and copy the webhook URL. AI expressions using $fromAI() placeholders automatically handle parameters, with built-in error handling ensuring robust performance. It leverages the official n8n MISP Tool node for reliability and supports high-volume threat intel tasks.

Ideal use cases: Automate threat hunting with AI agents querying/creating MISP events and attributes; integrate with LLMs for real-time IOC (Indicators of Compromise) enrichment; manage feeds and galaxies programmatically; enable security teams to publish/unpublish events via natural language AI prompts. Perfect for SOCs, cybersecurity firms, and red teams saving hours on API wrappers.

$27.99
Last updated October 3, 2026
30-day money-back guarantee
Instant download
Lifetime updates included

New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.

Secure checkout powered by Stripe

Support

How to import this workflow into n8n

  1. 1Purchase or download the workflow to get the n8n workflow JSON file.
  2. 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
  3. 3Open each node marked with a credential warning and connect your own accounts and API keys.
  4. 4Run the workflow once manually to verify the data flow, then toggle it to Active.

Related Other workflows

More from Quentin Andersen

Need this deployed? We'll set it up for you.

Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.