cybershield
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
我該用這個嗎
品質與安全性
發現項目(1)
- LOW在 threat_landscape 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"cybershield": {
"url": "https://tooloracle.io/cybershield/mcp/"
}
}
}遠端端點
https://tooloracle.io/cybershield/mcp/streamable-http它能做什麼
工具清單
工具(12)
⚪threat_landscape(sector)
Current cyber threat landscape overview per ENISA categories. Top 8 threats with sector relevance and mitigations.
輸入結構描述
{
"type": "object",
"properties": {
"sector": {
"type": "string",
"description": "energy|finance|healthcare|manufacturing|public_admin|general"
}
},
"additionalProperties": false
}⚪cve_risk_score(cve_id, cvss_score, epss_score, in_kev_catalog, public_exploit, ...)
CVE risk prioritization combining CVSS, EPSS, KEV catalog, exploit availability. Returns weighted priority score with patching SLA.
輸入結構描述
{
"type": "object",
"properties": {
"cve_id": {
"type": "string"
},
"cvss_score": {
"type": "number"
},
"epss_score": {
"type": "number",
"description": "0-1 EPSS probability"
},
"in_kev_catalog": {
"type": "boolean"
},
"public_exploit": {
"type": "boolean"
},
"internet_facing": {
"type": "boolean"
},
"affected_systems": {
"type": "integer"
}
},
"additionalProperties": false
}🟢attack_surface_check(web_applications, remote_access_vpn, cloud_services, iot_devices, employee_count)
Attack surface assessment checklist. Web apps, remote access, cloud, IoT, email. Prioritized security checks.
輸入結構描述
{
"type": "object",
"properties": {
"web_applications": {
"type": "boolean"
},
"remote_access_vpn": {
"type": "boolean"
},
"cloud_services": {
"type": "boolean"
},
"iot_devices": {
"type": "boolean"
},
"employee_count": {
"type": "integer"
}
},
"additionalProperties": false
}🟢phishing_indicators(sender_email, subject, suspicious_url, creates_urgency, has_unexpected_attachment, ...)
Analyze email/URL for phishing indicators. Scores sender, urgency, attachments, URL patterns. Returns verdict and recommended actions.
輸入結構描述
{
"type": "object",
"properties": {
"sender_email": {
"type": "string"
},
"subject": {
"type": "string"
},
"suspicious_url": {
"type": "string"
},
"creates_urgency": {
"type": "boolean"
},
"has_unexpected_attachment": {
"type": "boolean"
},
"asks_for_credentials": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪nis2_compliance(sector, employee_count, annual_turnover_meur, risk_management, incident_handling, ...)
NIS2 Directive (EU 2022/2555) compliance assessment. All 10 Art. 21 measures, entity classification, penalties, incident reporting.
輸入結構描述
{
"type": "object",
"properties": {
"sector": {
"type": "string"
},
"employee_count": {
"type": "integer"
},
"annual_turnover_meur": {
"type": "number"
},
"risk_management": {
"type": "boolean"
},
"incident_handling": {
"type": "boolean"
},
"business_continuity": {
"type": "boolean"
},
"supply_chain_security": {
"type": "boolean"
},
"vulnerability_management": {
"type": "boolean"
},
"cyber_hygiene_training": {
"type": "boolean"
},
"cryptography_policy": {
"type": "boolean"
},
"access_control": {
"type": "boolean"
},
"mfa_deployed": {
"type": "boolean"
},
"incident_reporting_process": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪nis2_incident_report(incident_type, severity, affected_services, affected_users_estimate, cross_border_impact)
NIS2 incident notification template. 24h early warning, 72h notification, 1-month final report templates.
輸入結構描述
{
"type": "object",
"properties": {
"incident_type": {
"type": "string"
},
"severity": {
"type": "string"
},
"affected_services": {
"type": "string"
},
"affected_users_estimate": {
"type": "integer"
},
"cross_border_impact": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪iso27001_gap(controls)
ISO 27001:2022 Annex A gap analysis. All 93 controls across 4 themes, new 2022 controls highlighted, certification process.
輸入結構描述
{
"type": "object",
"properties": {
"controls": {
"type": "object",
"description": "Optional: status of specific controls"
}
},
"additionalProperties": false
}⚪dora_ict_risk(ict_risk_framework, ict_asset_inventory, protection_prevention, detection_measures, response_recovery, ...)
DORA Art. 5-12 ICT risk management compliance check. 8 articles assessed with specific requirements per article.
輸入結構描述
{
"type": "object",
"properties": {
"ict_risk_framework": {
"type": "boolean"
},
"ict_asset_inventory": {
"type": "boolean"
},
"protection_prevention": {
"type": "boolean"
},
"detection_measures": {
"type": "boolean"
},
"response_recovery": {
"type": "boolean"
},
"learning_evolving": {
"type": "boolean"
},
"communication_plans": {
"type": "boolean"
}
},
"additionalProperties": false
}⚪password_policy
Generate password policy per NIST SP 800-63B (2024) and BSI recommendations. Modern best practices — no forced rotation.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪incident_playbook(incident_type)
Incident response playbook for ransomware, data breach, phishing compromise. Phase-by-phase actions with legal obligations.
輸入結構描述
{
"type": "object",
"properties": {
"incident_type": {
"type": "string",
"description": "ransomware | data_breach | phishing_compromise"
}
},
"additionalProperties": false
}🟢risk_matrix(risks)
Risk assessment matrix (likelihood × impact). ISO 31000/27005 methodology. Provide risks for assessment or get template.
輸入結構描述
{
"type": "object",
"properties": {
"risks": {
"type": "string",
"description": "JSON array [{name, likelihood(1-5), impact(1-5)}]"
}
},
"additionalProperties": false
}🟡security_metrics
Security KPI/metrics dashboard template. MTTD, MTTR, patch compliance, phishing rate. Board-ready reporting guidance.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}社群
證據