cybershield

CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.

使うべきか

品質と安全性

A
説明の品質
96%
スキーマの完全性
70%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(1)

  • LOWTool 'threat_landscape' description lacks action verbthreat_landscape 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~1,102トークン数(ツール定義)
~693 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.86%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "cybershield": {
      "url": "https://tooloracle.io/cybershield/mcp/"
    }
  }
}

リモートエンドポイント

https://tooloracle.io/cybershield/mcp/streamable-http

できること

ツール一覧

ツール(12)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
⚪threat_landscape(sector)

Current cyber threat landscape overview per ENISA categories. Top 8 threats with sector relevance and mitigations.

入力スキーマ

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string",
      "description": "energy|finance|healthcare|manufacturing|public_admin|general"
    }
  },
  "additionalProperties": false
}
⚪cve_risk_score(cve_id, cvss_score, epss_score, in_kev_catalog, public_exploit, ...)

CVE risk prioritization combining CVSS, EPSS, KEV catalog, exploit availability. Returns weighted priority score with patching SLA.

入力スキーマ

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string"
    },
    "cvss_score": {
      "type": "number"
    },
    "epss_score": {
      "type": "number",
      "description": "0-1 EPSS probability"
    },
    "in_kev_catalog": {
      "type": "boolean"
    },
    "public_exploit": {
      "type": "boolean"
    },
    "internet_facing": {
      "type": "boolean"
    },
    "affected_systems": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
🟢attack_surface_check(web_applications, remote_access_vpn, cloud_services, iot_devices, employee_count)

Attack surface assessment checklist. Web apps, remote access, cloud, IoT, email. Prioritized security checks.

入力スキーマ

{
  "type": "object",
  "properties": {
    "web_applications": {
      "type": "boolean"
    },
    "remote_access_vpn": {
      "type": "boolean"
    },
    "cloud_services": {
      "type": "boolean"
    },
    "iot_devices": {
      "type": "boolean"
    },
    "employee_count": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
🟢phishing_indicators(sender_email, subject, suspicious_url, creates_urgency, has_unexpected_attachment, ...)

Analyze email/URL for phishing indicators. Scores sender, urgency, attachments, URL patterns. Returns verdict and recommended actions.

入力スキーマ

{
  "type": "object",
  "properties": {
    "sender_email": {
      "type": "string"
    },
    "subject": {
      "type": "string"
    },
    "suspicious_url": {
      "type": "string"
    },
    "creates_urgency": {
      "type": "boolean"
    },
    "has_unexpected_attachment": {
      "type": "boolean"
    },
    "asks_for_credentials": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪nis2_compliance(sector, employee_count, annual_turnover_meur, risk_management, incident_handling, ...)

NIS2 Directive (EU 2022/2555) compliance assessment. All 10 Art. 21 measures, entity classification, penalties, incident reporting.

入力スキーマ

{
  "type": "object",
  "properties": {
    "sector": {
      "type": "string"
    },
    "employee_count": {
      "type": "integer"
    },
    "annual_turnover_meur": {
      "type": "number"
    },
    "risk_management": {
      "type": "boolean"
    },
    "incident_handling": {
      "type": "boolean"
    },
    "business_continuity": {
      "type": "boolean"
    },
    "supply_chain_security": {
      "type": "boolean"
    },
    "vulnerability_management": {
      "type": "boolean"
    },
    "cyber_hygiene_training": {
      "type": "boolean"
    },
    "cryptography_policy": {
      "type": "boolean"
    },
    "access_control": {
      "type": "boolean"
    },
    "mfa_deployed": {
      "type": "boolean"
    },
    "incident_reporting_process": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪nis2_incident_report(incident_type, severity, affected_services, affected_users_estimate, cross_border_impact)

NIS2 incident notification template. 24h early warning, 72h notification, 1-month final report templates.

入力スキーマ

{
  "type": "object",
  "properties": {
    "incident_type": {
      "type": "string"
    },
    "severity": {
      "type": "string"
    },
    "affected_services": {
      "type": "string"
    },
    "affected_users_estimate": {
      "type": "integer"
    },
    "cross_border_impact": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪iso27001_gap(controls)

ISO 27001:2022 Annex A gap analysis. All 93 controls across 4 themes, new 2022 controls highlighted, certification process.

入力スキーマ

{
  "type": "object",
  "properties": {
    "controls": {
      "type": "object",
      "description": "Optional: status of specific controls"
    }
  },
  "additionalProperties": false
}
⚪dora_ict_risk(ict_risk_framework, ict_asset_inventory, protection_prevention, detection_measures, response_recovery, ...)

DORA Art. 5-12 ICT risk management compliance check. 8 articles assessed with specific requirements per article.

入力スキーマ

{
  "type": "object",
  "properties": {
    "ict_risk_framework": {
      "type": "boolean"
    },
    "ict_asset_inventory": {
      "type": "boolean"
    },
    "protection_prevention": {
      "type": "boolean"
    },
    "detection_measures": {
      "type": "boolean"
    },
    "response_recovery": {
      "type": "boolean"
    },
    "learning_evolving": {
      "type": "boolean"
    },
    "communication_plans": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
⚪password_policy

Generate password policy per NIST SP 800-63B (2024) and BSI recommendations. Modern best practices — no forced rotation.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪incident_playbook(incident_type)

Incident response playbook for ransomware, data breach, phishing compromise. Phase-by-phase actions with legal obligations.

入力スキーマ

{
  "type": "object",
  "properties": {
    "incident_type": {
      "type": "string",
      "description": "ransomware | data_breach | phishing_compromise"
    }
  },
  "additionalProperties": false
}
🟢risk_matrix(risks)

Risk assessment matrix (likelihood × impact). ISO 31000/27005 methodology. Provide risks for assessment or get template.

入力スキーマ

{
  "type": "object",
  "properties": {
    "risks": {
      "type": "string",
      "description": "JSON array [{name, likelihood(1-5), impact(1-5)}]"
    }
  },
  "additionalProperties": false
}
🟡security_metrics

Security KPI/metrics dashboard template. MTTD, MTTR, patch compliance, phishing rate. Board-ready reporting guidance.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 12 件
検証済みバージョンは記録されていませんツール 12 件