threat_actor — osint terminal MCP Tool
threat_actor
(threat actor) is one of 457 tools on the
osint terminal
MCP server. Connect the server and your client discovers it on the handshake.
by client
How to call threat_actor from your client
- Claude Code osint terminal threat_actor run in your project directory
- Claude Desktop osint terminal threat_actor ~/Library/Application Support/Claude/claude_desktop_config.json
- Cursor osint terminal threat_actor ~/.cursor/mcp.json
- VS Code osint terminal threat_actor .vscode/mcp.json
- Zed osint terminal threat_actor ~/.config/zed/settings.json
- Windsurf osint terminal threat_actor ~/.codeium/windsurf/mcp_config.json
- Cline osint terminal threat_actor ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
- Gemini CLI osint terminal threat_actor ~/.gemini/settings.json
- Grok osint terminal threat_actor .mcp.json (in your project root)
- ChatGPT osint terminal threat_actor Settings → Connectors → Advanced → Developer mode
- Claude.ai osint terminal threat_actor Settings → Connectors → Add custom connector
- LangChain osint terminal threat_actor pip install langchain-mcp-adapters
Fastest route
claude mcp add --transport http osint-terminal https://osint-mcp.thetempleofdoom.com/mcp
Other tools on this server
- dns
- whois
- subdomains
- tls
- headers
- wayback
- ipgeo
- reversedns
- username
- github
- internetdb
- portscan
- camera
- ipwhois
- asn
- reverseip
- dnsbl
- tor
- cloud
- emailsec
- robots
- tech
- favicon
- redirects
- certhistory
- social
- mac
- crypto
- dorks
- urlscan
- greynoise
- typosquat
- securitytxt
- keybase
- phone
- decode
- jwt
- hashid
- cidr
- gitexposed
- cors
- cookies
- dnssec
- pgp
- hackernews
- gitlab
- dnsprop
- takeover
- sitemap
- waf
- cve
- npm
- peers
- urlparse
- epoch
- tlsscan
- revgeo
- suntimes
- iban
- bin
- uuid
- isbn
- txhash
- bluesky
- chesscom
- wikipedia
- httping
- links
- pwstrength
- entropy
- lobsters
- caa
- mtasts
- bimi
- domainage
- luhn
- pypi
- crates
- rubygems
- packagist
- npmpkg
- btcaddr
- ethaddr
- ghrepo
- ghgists
- ghorg
- mastodon
- geohash
- ipv6
- transform
- cpfcnpj
- color
- doh
- tlsa
- dnsverify
- subbrute
- hstspreload
- wpscan
- wellknown
- graphql
- swagger
- s3buckets
- httpmethods
- dirlisting
- adstxt
- feeds
- manifest
- wpplugin
- abusecontact
- asrank
- peeringdb
- rpki
- ens
- ethcontract
- osv
- depsdev
- gomod
- nuget
- maven
- hexpm
- cdnjs
- npmdl
- brew
- pypistats
- devto
- medium
- orcid
- codeberg
- wikidata
- musicbrainz
- stackoverflow
- hashnode
- gravatarfull
- osmuser
- feodo
- openphish
- kev
- epss
- circlhash
- weather
- elevation
- vin
- lei
- orgname
- cpe
- cvedetail
- port
- ssh
- hostsearch
- peeringnet
- nearbywiki
- doi
- crossrefauthor
- orcidworks
- isbnmeta
- sopostuser
- breachsearch
- feodoips
- urlscansearch
- commoncrawl
- ipfull
- geocode
- revgeocode
- macvendorlookup
- dnsmx
- fxrate
- country
- wikidatasearch
- spdxlicense
- gitignore
- ghcommits
- ghpubkeys
- ghkeysgpg
- npmdownloads
- pypiproject
- dockerhub
- httpstatus
- useragent
- asnprefixes
- ripewhois
- rdapip
- isotime
- nvdcve
- ghadvisory
- otxdomain
- otxip
- hosthunt
- ghlanguages
- githubsearch
- githubgists
- golangpkg
- rubygemrev
- cratedownloads
- openalexwork
- openalexauthor
- semanticscholar
- datacite
- restcountry
- wikisummary
- archiveorg
- hnsearch
- hnuser
- wikipv
- musicbrainzartist
- openfoodfacts
- cidrinfo
- passwordcheck
- base64
- hashtext
- qrcode
- dnsptrrange
- jwtdecode
- reddit_user
- reddit_sub
- huggingface
- steam_user
- codeforces
- leetcode_user
- npmorg
- emailrep
- arxiv
- pubmed
- zenodo
- dblp
- unpaywall
- ltcaddr
- dogeaddr
- xrpaddr
- soladdr
- opencorp
- gleif_name
- fccid
- smtpbanner
- disposable
- zonetransfer
- ctlogsearch
- webfinger
- srvlookup
- nstrace
- rdap_domain
- csp_parse
- sri_check
- clickjacking
- referrer_pol
- permissions_pol
- ipv4classify
- dnsrecon
- portlookup
- mimetype
- httpcode
- unixperm
- unicode_lookup
- timezone_info
- base_convert
- ip_math
- latlonformat
- regdomain
- tldinfo
- emailformat
- teamcymru
- whoisserver
- robotsmeta
- numlookup
- phonefmt
- phonenanp
- phonecc
- phonepivot
- phoneapps
- phonespam
- phonevcard
- imageexif
- imagegps
- imagemeta
- imagehash
- imagecolors
- imagerev
- imagephash
- imagethumb
- imageicc
- imagechunks
- imagexmp
- imagelsb
- quakes
- iss
- spacepeople
- airquality
- marineweather
- flightsnear
- whatsnearby
- maidenhead
- pluscode
- antipode
- geodist
- moonphase
- morse
- nato
- roman
- caesar
- snowflake
- ulid
- cron
- hexdump
- numwords
- jsonfmt
- passentropy
- cryptoprice
- agify
- genderize
- nationalize
- randomuser
- holidays
- binarytext
- rot47
- ascii85
- emoji
- slug
- wordcount
- ipint
- tempconv
- disasters
- spaceweather
- weatheralerts
- onthisday
- trendingwiki
- btcfees
- blockheight
- cryptomarket
- coininfo
- jslibs
- htmlcomments
- formaudit
- metatags
- telegram_channel
- linktree
- imei
- creditcard
- ean
- punycode
- homoglyph
- base58
- vatid
- swiftbic
- utm
- mgrs
- bearing
- passgen
- casify
- leet
- atbash
- railfence
- rdap
- ghevents
- cratestats
- isin
- barcode
- macvendor
- vigenere
- base36
- goproxy
- checksum
- sha256lookup
- crc32
- rot13
- spamhauslookup
- isexitnode
- asnlookup
- hostname
- portquick
- dnsquery
- creditcardtest
- htmlencode
- disposablecheck
- quoted_printable
- base32
- uuencode
- semver
- macvalid
- uuid_validate
- datauri
- stringmetrics
- whois_check
- hibp
- hibp_email
- leakcheck
- hudsonrock
- paste_email
- paste_domain
- gh_dorking
- gh_secret_scan
- intelx_email
- dehashed_domain
- breachdirectory
- snusbase_hash
- wayback_leaks
- trufflehog_url
- comb_search
- leaklookup
- cdxwayback
- cfradar
- bgphistory
- dnsgraph
- github_code
- pageinfo
- jarm
- threatcrowd
- apileak
- hibp_breaches
- breachdb
- password_dumps
- ssn_check
- phone_leak
- api_key_scan
- robotstxt_history
- exploit_cve
- cve_timeline
- cve_poc_checker
- mitre_technique
- cisa_alerts
- ransomware_tracker
- malware_family
- ioc_reputation
- zerodday_timeline
- apt_track
- botnet_tracker
- c2_infrastructure
- breach_aggregator
- darkweb_monitor
- credential_stuffing
- supply_chain_risk
- vuln_feed
- cve_severity
- threat_pattern
- emerging_threats
- phishing_intel
- infra_fingerprint
- attack_surface
- youtube
- soundcloud
- vimeo
- deviantart
- sec_edgar
- binlookup
- github_trending
- hackernews_front
- apod
- random_fact
- tempmail
- urban
- ddg_instant
- gdelt
- tiktok
- revimg
- correlate_sweep
- person_sweep
- agent_manifest
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.