Threat intelligence for any AI agent.
The OneFirewall MCP Server is a read-only data consumption channel for the World Crime Feed (WCF) platform. It lets Claude, GPT-4, GitHub Copilot, and any MCP-compatible agent query OneFirewall's threat intelligence directly — investigate IPs, pull live blocklists, and check your firewall fleet status. No data is shared with any AI provider.
Ask a question, get a CTI profile — no copy-paste
The Model Context Protocol (MCP) is an open standard that lets AI models call external tools over a secure, structured interface. Without MCP, a SOC analyst manually copies an IP from a SIEM alert, opens the dashboard, runs the lookup, and pastes the result into their AI chat. With MCP, the agent does all of that in one step.
# 1. User prompt (natural language)
User: "What does OneFirewall know about XX.XX.XX.XX?"
# 2. AI selects and calls the matching MCP tool
tool_call: get_ip_intel
params: {"ipv4": "XX.XX.XX.XX"}
# 3. MCP server authenticates with your JWT,
# queries the Alliance CTI API, returns JSON
response: {
"crime_score": 847,
"verdict": "MALICIOUS",
"asn": "AS4766",
"geo": "DE"
}
A read-only, one-way channel
WCF threat intelligence is fetched from OneFirewall's infrastructure and delivered into your AI agent's local context window only. No threat data, IP records, or Alliance intelligence is transmitted to or stored by any AI provider. Your AI client receives the data and uses it to answer your question — it never sends it upstream.
