Security & Testing
contrastcyber.com
Provides domain and IP security analysis, threat intelligence, and vulnerability scanning tools.
ENDPOINT 1
https://api.contrastcyber.com/mcp
MCP server metadata
- Name
- contrastapi
- Version
- 1.36.2
Known tools 55
domain_reportQuery DNS, WHOIS, SSL, subdomains, and threat intel for a domain in one call.
Inferred read-onlyaudit_domainPerform comprehensive domain audit: combines domain_report + live HTTP security headers + technology fingerprinting.
Inferred read-onlycontrast_scanActive website security scan: runs the ContrastScan C engine (11 modules — HTTP security headers, SSL/TLS, DNS, redirect chain, information disclosure, cookie flags, DNSSEC, HTTP methods, CORS, HTML hygiene, deep CSP analysis) against the live site and enriches the raw result with severity-ranked vulnerability findings and a letter grade.
Inferred read-onlytech_stack_cve_auditComposite tech-stack + CVE audit (MCP-only, no REST endpoint).
Inferred read-onlythreat_reportQuery comprehensive threat profile for an IP: Shodan host data, AbuseIPDB reputation, ASN/geolocation, and open ports.
Inferred read-onlydns_lookupQuery all DNS record types (A, AAAA, MX, NS, TXT, CNAME, SOA) for a domain.
Inferred read-onlywhois_lookupRetrieve WHOIS registration data: registrar, creation/expiry dates, nameservers, status.
Inferred read-onlyssl_checkAnalyze SSL/TLS certificate: grade (A/B/C/D/F), protocol version, cipher suite, chain, expiry, Subject Alternative Names, and structured validation findings.
Inferred read-onlysubdomain_enumDiscover subdomains using passive methods: Certificate Transparency logs + DNS brute-force (no active probing).
Inferred read-onlytech_fingerprintDetect website technology stack: CMS, frameworks, CDN, analytics tools, web servers, languages (via HTTP headers + HTML analysis).
Inferred read-onlywayback_lookupRetrieve Wayback Machine snapshots for a domain: first capture, latest, total count, snapshot list.
Inferred read-onlyscan_headersPerform live HTTP GET and analyze security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy.
Inferred read-onlyemail_mxAnalyze email security: MX records, SPF policy, DMARC policy, DKIM probe across common+date-based selectors, mail provider, grade.
Potential side effectsemail_security_postureAnalyze domain email authentication posture: SPF, DMARC, DKIM with numeric score and findings.
Potential side effectsemail_disposableCheck if email address uses a known disposable/temporary provider (Guerrilla Mail, Temp Mail, Mailinator, etc.
Potential side effectsemail_verifyOne-call email validation combining syntax + MX records + disposable check + role-address detection (admin@/info@/.
Potential side effectsredirect_chainWalk an HTTP redirect chain hop-by-hop, returning per-hop {url, status_code, location, latency_ms}.
Inferred read-onlybrand_assetsScrape a domain's homepage `<head>` for public brand assets — favicon, og:image, theme-color, og:site_name, JSON-LD `Organization.
Inferred read-onlyseo_auditOne-shot SEO audit of a domain's homepage with a 0-100 composite score + a `missing_signals` list of concrete fixes.
Inferred read-onlygeo_auditDeterministic GEO / AI-visibility readiness audit of a domain's homepage with a 0-100 score + a `missing_signals` fix list.
Inferred read-onlyphone_lookupValidate and analyze phone number: country, region, carrier, line type (mobile/landline/VoIP), timezone, formatted versions.
Inferred read-onlyip_lookupQuery comprehensive IP intelligence: reverse DNS, ASN + holder name + country inline (RIPE Stat, Phase 1), open ports, hostnames, vulnerabilities (Shodan InternetDB enriched with severity + cvss_v3 from local cve.
Inferred read-onlyasn_lookupLook up Autonomous System Number (ASN) for a domain or IP: AS number, organization, IPv4/IPv6 prefixes.
Inferred read-onlycalculate_risk_scoreComposite CVE risk score (0-100) — fuses CVSS, EPSS, KEV, and PoC into a single agent-ready triage signal.
Inferred read-onlycve_searchSearch CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status.
Inferred read-onlycve_leadingList CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data).
Inferred read-onlyexploit_lookupSearch public exploits/PoC for a specific CVE across three sources: (1) GitHub Advisory Database (sources.
Inferred read-onlybulk_cve_lookupBatch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N.
Inferred read-onlykev_detailLook up CISA KEV (Known Exploited Vulnerabilities) full record for a CVE.
Inferred read-onlycwe_lookupLook up MITRE CWE (Common Weakness Enumeration) catalog record from research view 1000.
Inferred read-onlyatlas_technique_lookupLook up a MITRE ATLAS technique — the AI/ML adversarial attack catalog.
Inferred read-onlybulk_atlas_technique_lookupBulk ATLAS technique lookup — retrieve full records for up to 50 techniques in a single request instead of N separate atlas_technique_lookup calls.
Inferred read-onlyatlas_technique_searchSearch the MITRE ATLAS catalog of AI/ML attack techniques by keyword, tactic, or maturity.
Inferred read-onlyatlas_case_study_lookupLook up a MITRE ATLAS case study — a documented real-world AI/ML attack incident.
Inferred read-onlyatlas_case_study_searchSearch ATLAS case studies (real-world AI/ML attack incidents) by keyword or referenced technique.
Inferred read-onlyd3fend_defense_searchSearch the MITRE D3FEND catalog of defensive techniques by keyword, tactic, or targeted artifact.
Inferred read-onlyd3fend_defense_for_attackReverse lookup: given an ATT&CK T-code, return D3FEND defenses that mitigate it.
Inferred read-onlyd3fend_attack_coverageBatch coverage breakdown: given a list of ATT&CK T-codes, return distinct defense counts per D3FEND tactic + identify which techniques have NO D3FEND mapping (undefended_techniques).
Inferred read-onlysigma_rule_lookupLook up a single Sigma detection rule by UUID from the SigmaHQ corpus (~3,200 rules, refreshed daily at 02:00 UTC).
Inferred read-onlybulk_sigma_rule_lookupBulk Sigma rule lookup — retrieve full records for up to 50 rule UUIDs in a single request instead of N separate sigma_rule_lookup calls.
Inferred read-onlyioc_lookupEnrich Indicator of Compromise (IP/domain/URL/hash) by auto-detecting type and querying abuse.
Inferred read-onlyhash_lookupQuery MalwareBazaar for file hash (MD5/SHA1/SHA256): malware family, file type, size, tags, first/last seen, download count.
Inferred read-onlypassword_checkCheck if SHA-1 hash appears in Have I Been Pwned (HIBP) breach dataset using k-anonymity (5-char prefix only, full hash never leaves tool).
Inferred read-onlybulk_ioc_lookupBatch query multiple IOCs (IP/domain/URL/hash, up to 50 per call, same for Free and Pro) in 1 request: auto-detects type + queries abuse.
Inferred read-onlycheck_secretsScan source code (or snippet) for hardcoded secrets — cloud provider keys, API tokens, connection strings, private keys, passwords.
Inferred read-onlycheck_injectionScan source code for injection vulnerabilities: SQL injection, command injection, path traversal via unsafe string concatenation/unsanitized input.
Potential side effectsusername_lookupSearch for username across 15+ social/dev platforms (GitHub, Reddit, X/Twitter, LinkedIn, Instagram, TikTok, Discord, YouTube, Keybase, HackerOne, etc.
Inferred read-onlycheck_headersValidate HTTP security headers you provide (JSON): CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy against best practices.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.contrastapi]
url = "https://api.contrastcyber.com/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"contrastapi": {
"type": "http",
"url": "https://api.contrastcyber.com/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: contrastapi
Remote MCP URL: https://api.contrastcyber.com/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"contrastapi": {
"url": "https://api.contrastcyber.com/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"contrastapi": {
"type": "http",
"url": "https://api.contrastcyber.com/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "contrastapi",
"transport": "streamable-http",
"url": "https://api.contrastcyber.com/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Trust Data Available
BuiltWith Trust API v2 evidence for contrastcyber.com was fetched 2026-08-25T12:04:50.033Z.
contrastcyber.com is assessed as Neutral: No suspicious signals found, but no strong positive signal either
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.