MISP Tool MCP Server: All 44 Operations for AI Agents

Complete zero-config MCP server exposing every MISP Tool operation (44 total) to AI agents via n8n webhook. Pre-built with error handling for seamless threat intel automation.

n8n
MISP Tool MCP Server: All 44 Operations for AI Agents

This workflow transforms n8n into a fully functional MCP (Model Context Protocol) server for the MISP Tool, providing instant access to all 44 operations including attribute management (create/delete/get/update/filter), event handling (create/delete/publish/unpublish/update/filter), event tags, feeds (create/disable/enable/update), galaxies, notice lists, and more. The MCP Trigger node acts as the endpoint for AI agents, automatically populating parameters with $fromAI() expressions and leveraging the official n8n MISP Tool integration with robust error handling.

Benefits include zero setup time—no custom nodes or configurations needed. Simply import, activate, copy the webhook URL, and connect your AI agents (e.g., Claude, GPT) for real-time MISP interactions. It saves hours of development by pre-building every operation, enabling scalable threat intelligence automation without coding.

Use cases: Automate cybersecurity workflows like ingesting IOCs into MISP events, querying attributes for malware analysis, managing feeds for OSINT, or tagging galaxies for cluster analysis—all via natural language AI prompts. Ideal for SOC teams, threat hunters, and red teams integrating MISP with AI for faster incident response and intel sharing.

$27.99
Last updated October 3, 2026
30-day money-back guarantee
Instant download
Lifetime updates included

New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.

Secure checkout powered by Stripe

Support

How to import this workflow into n8n

  1. 1Purchase or download the workflow to get the n8n workflow JSON file.
  2. 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
  3. 3Open each node marked with a credential warning and connect your own accounts and API keys.
  4. 4Run the workflow once manually to verify the data flow, then toggle it to Active.

Related HR & Operations workflows

More from Bruno Lindberg

Need this deployed? We'll set it up for you.

Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.