Agentโ™ฅ๏ธŽAge
Catalog

io.github.cyanheads/attack-surface-mcp-server

Official

by cyanheads ยท TypeScript

Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.

This MCP server provides passive external attack-surface mapping. It covers certificate transparency (CT) subdomains, DNS, TLS, and HTTP posture, and includes RDAP/WHOIS and Shodan. Access is via MCP over STDIO or Streamable HTTP, with a TypeScript implementation.

๐Ÿ› ๏ธ Key Features

  • Passive external attack-surface mapping
  • CT subdomain coverage
  • DNS and TLS posture collection
  • HTTP posture assessment
  • RDAP/WHOIS enrichment
  • Shodan integration
  • 8 tools
  • 1 resource

๐Ÿš€ Use Cases

  • Subdomain enumeration
  • External reconnaissance workflows
  • Security and OSINT data collection
  • AI-agent driven mapping using MCP

โšก Developer Benefits

  • MCP compatibility (tooling for model-context-protocol agents)
  • Streamable HTTP or STDIO transport options
  • Repository topics include attack-surface, recon, and security

โš ๏ธ Limitations

  • Described as passive external mapping; it does not claim active probing or exploitation in the provided data.

Topics

attack-surfacebuncertificate-transparencydnseasmmcpmcp-servermodel-context-protocolrdapreconnaissancesecurityshodansubdomain-enumerationtlstypescriptwhoisai-agentscyanheadsosint

Related servers

More in Security