惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
阮一峰的网络日志
阮一峰的网络日志
T
Tailwind CSS Blog
博客园 - 【当耐特】
量子位
博客园 - 叶小钗
有赞技术团队
有赞技术团队
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
博客园 - 司徒正美
爱范儿
爱范儿
美团技术团队
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
罗磊的独立博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
Hugging Face - Blog
Hugging Face - Blog
I
InfoQ
D
DataBreaches.Net
宝玉的分享
宝玉的分享

New in Feedly

Pivot from an IP IoC to live host data in Censys | Feedly Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly
Feedly MCP Server: Automate CTI workflows with Claude and...
Shawn Jaques · 2025-11-05 · via New in Feedly

Context engineering is the new AI multiplier: output quality is no longer about how you ask, it's what context the AI can access when it answers.

With the new Feedly Threat Graph MCP Server, Claude gets real-time access to enriched articles and threat insights from 10,000+ trusted sources: relationships between 800+ threat actors, 10K+ malware families, 300K+ CVEs, 500K+ IoCs, 800+ techniques and tactics, and 10K+ cyber attacks.

The 16 tools exposed by the Threat Graph MCP server allow Claude to research like a CTI analyst and deliver more accurate and timely responses.

Ask about a ransomware campaign, and Claude correlates threat actors, their TTPs, exploited CVEs, and associated IoCs.

Or use multiple MCP servers to orchestrate end-to-end threat hunt workflows.

Let's walk through four scenarios, from simple queries to complex workflows, that showcase how you can perform more accurate CTI research when connecting Claude to the Feedly Real-Time Threat Graph.

First, what is an MCP Server, and how can they help

An MCP (Model Context Protocol) server is a standardized interface that enables AI assistants to access tools and data sources directly in real-time. The Feedly MCP Server allows Claude AI to pull fresh intelligence directly from Feedly’s Real-Time Threat Graph.

For CTI analysts, this means you can ask Claude CTI research questions, such as "What are the latest TTPs associated with APT29?" and it will fetch current data from the Feedly Threat Graph, rather than relying solely on fragmented web search data. This improved context enables Claude to provide more timely, relevant, and actionable insights.

Claude's reasoning and use of specialized tools shows how it thinks like a CTI analyst: identifying and looking up APT29, extracting relationships, and synthesizing recent campaign intelligence with cited sources.

Demo 1: Tracking active ransomware campaigns

Prompt

What's trending in ransomware attacks this month?

Web search gives Claude and other AI tools a few articles to improve the currency of it’s LLM-trained answer. However, rarely does it give a comprehensive view of current and evolving cyber events. The Feedly MCP Server connects your AI tools directly to our Real-Time Threat Graph, giving you comprehensive, connected intelligence from 10,000+ sources with pre-mapped relationships between actors, campaigns, and vulnerabilities.

Result

When you ask Claude this question with the Feedly MCP Server enabled, it automatically queries our Threat Graph for ransomware activity from the last 30 days. The AI selects and chains multiple tools, pulling trending cyber attacks, filtering by attack type, and identifying the responsible threat actors.

What you get: Specific ransomware trends with attribution, affected sectors, ransom demands, and financial impact. Not fragments from random search results that miss the connections.

Why it matters: More complete and up-to-date context from the Real-Time Threat Graph, rather than a few articles that ranked well in search, helps the AI produce answers that reflect all known relationships and recent activity. The responses are more actionable so you can quickly move from question to action and start protecting your business.

Demo 2: Identifying actively exploited vulnerabilities

Prompt

What are the most dangerous vulnerabilities discovered in the past week that threat actors are already exploiting? For each one, tell me: who's exploiting it, what malware they're using, what industries they're targeting, and if there are any proof-of-concept exploits or Metasploit modules available.

Result

This query triggers complex reasoning. The MCP Server pulls trending vulnerabilities, cross-references them with threat actor activity, identifies associated malware families, and checks for available exploits—all automatically.

What you get: CVEs with active exploitation evidence, specific threat actor attribution, targeted sectors, associated malware families, and exploit availability status.

Why it matters: Instead of manually pivoting between NVD, threat feeds, and campaign reports, you get the full threat context in one query. You immediately know if a CVE is being weaponized, by whom, and against what sectors, so you can prioritize patching based on actual risk to your environment, not just CVSS scores.

Demo 3: Building actionable threat hunts

Prompt

Build me a threat hunt for Scattered Spider based on their last 3 months of activity.

Result

The MCP Server reasons through Scattered Spider's recent campaigns, extracting their current TTPs, infrastructure patterns, and targeting preferences from reported incidents.

What you get:

  • Current TTPs mapped to MITRE ATT&CK based on observed activity.
  • Detection opportunities tied to their recent Salesforce and identity provider campaigns.
  • Queries ready to run in your SIEM.

Why it matters: When investigating Scattered Spider, you need a full operational picture, not search results. The Feedly MCP Server gives you deduplicated intelligence from thousands of sources, temporally organized so you can see how their tactics evolved. You're working with their complete recent activity profile, ready to operationalize.

Demo 4: Multi-tool orchestration for end-to-end workflows

Prompt

Conduct research in Feedly on the latest TTPs for Scattered Spider and conduct a threat hunt in my SIEM. Then share the findings in Slack using the threat hunting Notion template.

Result

This demo shows true orchestration: the Threat Graph MCP Server working alongside other MCP tools to automate a complete threat hunting workflow.

The automated workflow:

  1. Feedly MCP queries the Threat Graph for Scattered Spider intelligence.
  2. Generates specific Wazuh queries based on extracted IoCs and TTPs.
  3. Structures findings using your Notion threat hunting template.
  4. Posts formatted results to your Slack channel.

What you get: A complete, documented threat hunt with:

  • Intelligence context from Feedly's Threat Graph
  • Ready-to-run SIEM queries
  • Structured documentation in your existing format
  • Team notification with key findings

Why it matters: MCP isn't just about querying data. It's also about integrating real-time threat intelligence into your existing workflows. The context from Feedly's Threat Graph flows directly into your security tools, eliminating the copy-paste shuffle between platforms and ensuring your hunts are based on current intelligence.

From signals to action in minutes

Context makes AI better. Web search gives you fragments, while the Feedly MCP Server, extracting context from the Feedly Threat Graph, gives you a complete, connected picture. By automating threat investigations that used to take hours, your team can prioritize faster, respond sooner, and reduce risk exposure. Your AI tools now operate with real-time context, making responses actionable, verifiable, and ready when threats emerge.

Feedly’s MCP Server gives AI tools the context they need to deliver more accurate CTI responses.

Book Demo