cybershield
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
使うべきか
品質と安全性
検出事項(1)
- LOWthreat_landscape 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"cybershield": {
"url": "https://tooloracle.io/cybershield/mcp/"
}
}
}リモートエンドポイント
https://tooloracle.io/cybershield/mcp/streamable-httpできること
ツール一覧
ツール(12)
⚪threat_landscape(sector)
Current cyber threat landscape overview per ENISA categories. Top 8 threats with sector relevance and mitigations.
入力スキーマ
{
"type": "object",
"properties": {
"sector": {
"type": "string",
"description": "energy|finance|healthcare|manufacturing|public_admin|general"
}
},
"additionalProperties": false
}⚪cve_risk_score(cve_id, cvss_score, epss_score, in_kev_catalog, public_exploit, ...)
CVE risk prioritization combining CVSS, EPSS, KEV catalog, exploit availability. Returns weighted priority score with patching SLA.
入力スキーマ
{
"type": "object",
"properties": {
"cve_id": {
"type": "string"
},
"cvss_score": {
"type": "number"
},
"epss_score": {
"type": "number",
"description": "0-1 EPSS probability"
},
"in_kev_catalog": {
"type": "boolean"
},
"public_exploit": {
"type": "boolean"
},
"internet_facing": {
"type": "boolean"
},
"affected_systems": {
"type": "integer"
}
},
"additionalProperties": false
}🟢attack_surface_check(web_applications, remote_access_vpn, cloud_services, iot_devices, employee_count)
Attack surface assessment checklist. Web apps, remote access, cloud, IoT, email. Prioritized security checks.
入力スキーマ
{
"type": "object",
"properties": {
"web_applications": {
"type": "boolean"
},
"remote_access_vpn": {
"type": "boolean"
},
"cloud_services": {
"type": "boolean"
},
"iot_devices": {
"type": "boolean"
},
"employee_count": {
"type": "integer"
}
},
"additionalProperties": false
}🟢phishing_indicators(sender_email, subject, suspicious_url, creates_urgency, has_unexpected_attachment, ...)
Analyze email/URL for phishing indicators. Scores sender, urgency, attachments, URL patterns. Returns verdict and recommended actions.
入力スキーマ
{
"type": "object",
"properties": {
"sender_email": {
"type": "string"
},
"subject": {
"type": "string"
},
"suspicious_url": {
"type": "string"
},
"creates_urgency": {
"type": "boolean"
},
"has_unexpected_attachment": {
"type": "boolean"
},
"asks_for_credentials": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪nis2_compliance(sector, employee_count, annual_turnover_meur, risk_management, incident_handling, ...)
NIS2 Directive (EU 2022/2555) compliance assessment. All 10 Art. 21 measures, entity classification, penalties, incident reporting.
入力スキーマ
{
"type": "object",
"properties": {
"sector": {
"type": "string"
},
"employee_count": {
"type": "integer"
},
"annual_turnover_meur": {
"type": "number"
},
"risk_management": {
"type": "boolean"
},
"incident_handling": {
"type": "boolean"
},
"business_continuity": {
"type": "boolean"
},
"supply_chain_security": {
"type": "boolean"
},
"vulnerability_management": {
"type": "boolean"
},
"cyber_hygiene_training": {
"type": "boolean"
},
"cryptography_policy": {
"type": "boolean"
},
"access_control": {
"type": "boolean"
},
"mfa_deployed": {
"type": "boolean"
},
"incident_reporting_process": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪nis2_incident_report(incident_type, severity, affected_services, affected_users_estimate, cross_border_impact)
NIS2 incident notification template. 24h early warning, 72h notification, 1-month final report templates.
入力スキーマ
{
"type": "object",
"properties": {
"incident_type": {
"type": "string"
},
"severity": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"affected_users_estimate": {
"type": "integer"
},
"cross_border_impact": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪iso27001_gap(controls)
ISO 27001:2022 Annex A gap analysis. All 93 controls across 4 themes, new 2022 controls highlighted, certification process.
入力スキーマ
{
"type": "object",
"properties": {
"controls": {
"type": "object",
"description": "Optional: status of specific controls"
}
},
"additionalProperties": false
}⚪dora_ict_risk(ict_risk_framework, ict_asset_inventory, protection_prevention, detection_measures, response_recovery, ...)
DORA Art. 5-12 ICT risk management compliance check. 8 articles assessed with specific requirements per article.
入力スキーマ
{
"type": "object",
"properties": {
"ict_risk_framework": {
"type": "boolean"
},
"ict_asset_inventory": {
"type": "boolean"
},
"protection_prevention": {
"type": "boolean"
},
"detection_measures": {
"type": "boolean"
},
"response_recovery": {
"type": "boolean"
},
"learning_evolving": {
"type": "boolean"
},
"communication_plans": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪password_policy
Generate password policy per NIST SP 800-63B (2024) and BSI recommendations. Modern best practices — no forced rotation.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪incident_playbook(incident_type)
Incident response playbook for ransomware, data breach, phishing compromise. Phase-by-phase actions with legal obligations.
入力スキーマ
{
"type": "object",
"properties": {
"incident_type": {
"type": "string",
"description": "ransomware | data_breach | phishing_compromise"
}
},
"additionalProperties": false
}🟢risk_matrix(risks)
Risk assessment matrix (likelihood × impact). ISO 31000/27005 methodology. Provide risks for assessment or get template.
入力スキーマ
{
"type": "object",
"properties": {
"risks": {
"type": "string",
"description": "JSON array [{name, likelihood(1-5), impact(1-5)}]"
}
},
"additionalProperties": false
}🟡security_metrics
Security KPI/metrics dashboard template. MTTD, MTTR, patch compliance, phishing rate. Board-ready reporting guidance.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false
}コミュニティ
エビデンス