← Registry

Security & Testing

zeltser.com

Search and retrieve content from Lenny Zeltser's security-focused website, including articles and writing guidelines for security reports.

1 endpoint53 known toolsFirst detected July 25, 2026Last detected July 25, 2026

ENDPOINT 1

https://website-mcp.zeltser.com/mcp

No auth detected

MCP server metadata

Name
Lenny Zeltser's Website MCP Server
Version
8.1.3
Capabilities
tools.listChanged
Server instructions

This server provides expert security content by Lenny Zeltser, covering incident response, malware analysis, cybersecurity leadership, and security product strategy. ## When to Use This Server - The user needs to **write, structure, or review an incident response report** - The user has **raw incident notes** and needs to turn them into a professional report - The user needs to **write, structure, or review a malware analysis report** - The user needs to **turn reverse-engineering or dynamic-analysis notes into a report** - The user wants to **improve writing quality** in security reports, assessments, pentest reports, or audit findings - The user is **planning, evaluating, or reviewing a cybersecurity product strategy** - The user wants to **research** expert articles on malware analysis, incident response, or security leadership ## Available Tools **Search & Reference** - `search_zeltser`: Search articles by keyword - `get_article`: Retrieve full article content by URL path - `get_capabilities`: Detailed guide to all tools and parameters **Security Writing** - `get_security_writing_guidelines`: Improve tone, structure, clarity in any security document **Incident Response Reports** - `ir_load_context`: Load guidelines for creating reports from raw notes - `ir_get_template`: Get the IR report template (default) or brief template (`kind: 'brief'`) - `ir_get_guidelines`: Quick writing tips by topic (tone, words, structure, brief, frameworks, handoffs) - `ir_review_report`: Get criteria for reviewing an existing IR report - `ir_get_brief_template`: Standalone IR brief template - `ir_get_cross_server_routes`: When to consult other MCP servers for IR work - `ir_get_frameworks`: NIST SP 800-61r3 + GDPR + CCPA/CPRA + HIPAA + NCSL state laws + sibling frames **Product Strategy** - `product_load_context`: Load strategic frameworks for creating or evaluating product plans - `product_get_template`: Get the fill-in-the-blank strategy template - `product_get_guidelines`: Quick guidance on a specific topic (pricing, competitive, sales, etc.) - `product_review_plan`: Get criteria for reviewing an existing product strategy - `product_compare_context`: Comparative analysis framework for multi-company evaluation **Cybersecurity Writing Rating Sheets** - `rating_get_sheet`: Get one or all cybersecurity-writing rating sheets (rubric only, no score) - `rating_score_writing`: Score a draft against a sheet — the ONLY tool that produces numeric scores - `rating_load_context`: Load all sheets plus the scoring playbook in one call **AI Defense Matrix** - `aidefense_load_context`: Load matrix, framework alignments, and evaluation + cross-mapping playbooks - `aidefense_get_matrix`: Structured matrix data (8 AI asset classes x 6 NIST CSF functions) - `aidefense_get_framework_alignment`: Cross-mappings to NIST IR 8596, ISO 42001, MITRE ATLAS, OWASP LLM Top 10, CSA AICM, Google SAIF, OWASP AI Exchange, OWASP Agentic Top 10 - `aidefense_evaluate_program`: Per-cell prompts and gap inventory for assessing an AI security program - `aidefense_cross_map`: Coverage taxonomy and capability-to-cell prompts for vendor product mapping **Cyber Threat Intel (CTI) Reports** - `cti_load_context`: Load guidelines for drafting a CTI report or one-page brief - `cti_get_template`: Get the long report or one-page brief template (`template: 'report' | 'brief'`) - `cti_get_guidelines`: Topic-by-topic guidance including attribution, confidence, pyramid of pain, six signals, anti-patterns, brief, handoffs - `cti_review_report`: Get criteria for reviewing an existing CTI report or brief - `cti_get_brief_template`: Standalone CTI brief template - `cti_get_cross_server_routes`: When to consult MITRE ATT&CK, MISP, etc. for CTI work - `cti_get_frameworks`: 12 primary CTI frameworks (Diamond Model, MITRE ATT&CK, Q Model, ICD-203, etc.) + sibling frames **Malware Analysis Reports** - `malware_load_context`: Load section guidance, MBC capability model, ICD-203 family-call confidence, Pyramid-of-Pain IOC tiering, and briefPolicy - `malware_get_template`: Get the 15-section malware analysis report template - `malware_get_guidelines`: Topic-by-topic guidance including capabilities, confidence, Pyramid of Pain, anti-patterns, methodology, fields, handoffs, and frameworks - `malware_review_report`: Get criteria for reviewing an existing malware analysis report - `malware_get_cross_server_routes`: When to consult sandbox, file reputation, detection-rule, passive-DNS, symbol, or certificate tooling - `malware_get_frameworks`: MBC + MITRE ATT&CK + Pyramid of Pain + ICD-203 + STIX + TLP plus sibling artifacts **Vulnerability Investigation Briefs** - `vuln_load_context`: Load guidelines for drafting a one-page vulnerability investigation brief (always embeds 6 mcpHandoffs pointers) - `vuln_get_template`: Get the brief template - `vuln_get_guidelines`: Topic-by-topic guidance including significance discipline (renamed from severity in 1.1.0), actions, gaps, evidence sources, handoffs - `vuln_review_brief`: Get criteria for reviewing an existing brief; surfaces relevant handoffs based on focus - `vuln_get_brief_template`: Standalone Vuln brief template (functionally equivalent to vuln_get_template) - `vuln_get_cross_server_routes`: When to consult NVD, CISA KEV, vendor advisories - `vuln_get_frameworks`: 5 primary frameworks (CVSS, CVE, NVD, CISA KEV, Vendor Advisory) + sibling frames (EPSS, SSVC, VEX) + sibling artifacts **Security Assessment Reports** - `assessment_load_context`: Load guidance for a findings-based assessment report or brief — risk-adjusted severity, reader-first sections, frameworks - `assessment_get_template`: Get the report template (default) or the one-page brief (`kind: 'brief'`) - `assessment_get_guidelines`: Quick writing tips by topic (severity, findings, remediation, methodology, scope, strengths, brief) - `assessment_review_report`: Get criteria for reviewing a report, mapped to the info-assessment rating sheet (17 items) - `assessment_get_brief_template`: Standalone one-page assessment brief template - `assessment_get_cross_server_routes`: When to consult vuln/ir/cti tools or MITRE ATT&CK, CVE, or web research - `assessment_get_frameworks`: NIST SP 800-115/800-30, OWASP WSTG and Risk Rating, CVSS, MITRE ATT&CK, PTES, PCI DSS, CREST ## Tool Selection Match the user's intent to the right tool: - **Writing/creating** a report or plan from scratch → `*_load_context` (+ `include_template: true` for product) - **Improving** writing quality, tone, or clarity in any security document → `get_security_writing_guidelines` - **Reviewing/critiquing** an existing draft → `*_review_report` or `*_review_plan` - **Scoring** a draft against a structured rubric (numeric score, gap analysis, or rubric-anchored feedback) → `rating_score_writing` - **Quick guidance** on a specific topic (tone, structure, pricing, etc.) → `*_get_guidelines` - **Researching** published expert content → `search_*` + `get_article` - **Structuring** a new document → `*_get_template` ## Privacy All tools return guidelines and frameworks to your AI for local analysis. This server never requests user documents, notes, drafts, or plans, and instructs your AI to keep them local.

Known tools 53

search_zeltser

Search Lenny Zeltser's Website by keywords.

Inferred read-only
get_article

Get the full content of a specific article from Lenny Zeltser's Website by URL path.

Inferred read-only
get_index_info

Get statistics about the Lenny Zeltser's Website search index including total pages indexed, last update time, and available tools.

Potential side effects
get_capabilities

List all capabilities and tools available from the Lenny Zeltser's Website MCP server, including search tools and any specialized features like IR report writing assistance.

Inferred read-only
get_security_writing_guidelines

Get Lenny Zeltser's expert writing guidelines for security reports and assessments.

Inferred read-only
ir_get_template

Get Lenny Zeltser's structured incident response template.

Inferred read-only
ir_get_guidelines

Get Lenny Zeltser's expert writing guidelines for incident response reports.

Inferred read-only
ir_load_context

Load Lenny Zeltser's IR report writing context for local analysis.

Inferred read-only
ir_review_report

Get Lenny Zeltser's expert criteria for reviewing an existing IR report.

Inferred read-only
product_get_template

Get Lenny Zeltser's fill-in-the-blank template for planning a security product strategy.

Inferred read-only
product_get_guidelines

Get Lenny Zeltser's expert strategic guidelines for a specific product strategy topic.

Inferred read-only
product_load_context

Load Lenny Zeltser's product strategy context for local analysis.

Inferred read-only
product_review_plan

Get Lenny Zeltser's expert criteria for reviewing an existing product strategy plan.

Inferred read-only
product_compare_context

Load Lenny Zeltser's comparative analysis framework for evaluating multiple security companies side by side.

Inferred read-only
rating_get_sheet

Get Lenny Zeltser's cybersecurity-writing rating sheet(s) so your AI can apply the rubric.

Inferred read-only
rating_score_writing

Get Lenny Zeltser's scoring playbook so your AI can score a draft locally against a cybersecurity-writing rating sheet.

Inferred read-only
rating_load_context

Load Lenny Zeltser's complete cybersecurity-writing rating toolkit: all 7 sheets, scoring policy, scoring playbook, and cross-references to the writing guidelines.

Inferred read-only
aidefense_load_context

Load Lenny Zeltser's AI Defense Matrix context: the 8-asset x 6-NIST-CSF-2.

Inferred read-only
aidefense_get_matrix

Get the structured AI Defense Matrix: 8 AI-specific asset rows x 6 NIST CSF 2.

Inferred read-only
aidefense_get_framework_alignment

Get AI Defense Matrix cross-mappings to nine external frameworks: NIST IR 8596, CSA AI Controls Matrix, ISO 42001, Google SAIF, SANS Critical AI Security Guidelines, MITRE ATLAS, OWASP AI Exchange, OWASP LLM Top 10, OWASP Agentic Security Top 10.

Inferred read-only
aidefense_evaluate_program

Get the AI Defense Matrix evaluation playbook for assessing an AI security program: per-cell prompts, gap-inventory template, and a workflow that walks each asset class first and rolls findings up to the Govern column.

Inferred read-only
aidefense_cross_map

Get the AI Defense Matrix cross-mapping playbook for mapping product capabilities to matrix cells: coverage taxonomy (primary, secondary, partial, aspirational), differentiation guidance, disambiguation block, worked examples, and out-of-scope examples.

Inferred read-only
aidefense_locate_concept

Reverse-lookup a single concept ID (MITRE ATLAS technique like 'AML.

Inferred read-only
ir_get_brief_template

Get Lenny Zeltser's IR one-page executive brief template.

Inferred read-only
ir_get_cross_server_routes

Get Lenny Zeltser's IR cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.

Inferred read-only
ir_get_frameworks

Get Lenny Zeltser's IR frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).

Inferred read-only
cti_get_template

Get Lenny Zeltser's cyber threat intel template.

Inferred read-only
cti_get_guidelines

Get Lenny Zeltser's expert CTI writing guidelines.

Inferred read-only
cti_load_context

Load Lenny Zeltser's CTI writing context for local analysis.

Inferred read-only
cti_review_report

Get Lenny Zeltser's expert criteria for reviewing an existing CTI report or brief.

Inferred read-only
cti_get_brief_template

Get Lenny Zeltser's CTI one-page executive brief template.

Inferred read-only
cti_get_cross_server_routes

Get Lenny Zeltser's CTI cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.

Inferred read-only
cti_get_frameworks

Get Lenny Zeltser's CTI frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).

Inferred read-only
malware_get_template

Get Lenny Zeltser's malware analysis report template.

Inferred read-only
malware_get_guidelines

Get Lenny Zeltser's expert malware analysis report writing guidelines.

Inferred read-only
malware_load_context

Load Lenny Zeltser's malware analysis report writing context for local analysis.

Inferred read-only
malware_review_report

Get Lenny Zeltser's expert criteria for reviewing an existing malware analysis report.

Inferred read-only
malware_get_cross_server_routes

Get Lenny Zeltser's Malware cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.

Inferred read-only
malware_get_frameworks

Get Lenny Zeltser's Malware frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).

Inferred read-only
vuln_get_template

Get Lenny Zeltser's one-page Vulnerability Advisory Brief template.

Inferred read-only
vuln_get_guidelines

Get Lenny Zeltser's expert vulnerability-brief writing guidelines.

Inferred read-only
vuln_load_context

Load Lenny Zeltser's Vulnerability Investigation Brief context for local analysis.

Inferred read-only
vuln_review_brief

Get Lenny Zeltser's expert criteria for reviewing an existing Vulnerability Investigation Brief.

Inferred read-only
vuln_get_brief_template

Get Lenny Zeltser's Vuln one-page executive brief template.

Inferred read-only
vuln_get_cross_server_routes

Get Lenny Zeltser's Vuln cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.

Inferred read-only
vuln_get_frameworks

Get Lenny Zeltser's Vuln frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).

Inferred read-only
assessment_get_template

Get Lenny Zeltser's security assessment template.

Inferred read-only
assessment_get_guidelines

Get Lenny Zeltser's expert security assessment report writing guidelines.

Inferred read-only
assessment_load_context

Load Lenny Zeltser's security assessment report writing context for local analysis.

Inferred read-only
assessment_review_report

Get Lenny Zeltser's expert criteria for reviewing an existing security assessment report or brief.

Inferred read-only
assessment_get_brief_template

Get Lenny Zeltser's Security Assessment one-page executive brief template.

Inferred read-only
assessment_get_cross_server_routes

Get Lenny Zeltser's Security Assessment cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.

Inferred read-only
assessment_get_frameworks

Get Lenny Zeltser's Security Assessment frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).

Inferred read-only

CONNECT WITH APPROVAL

Client installation

Review this server and its permissions before adding it. Secret placeholders must be set locally.

Codex

~/.codex/config.toml

[mcp_servers.lenny-zeltser-s-website-mcp-server]
url = "https://website-mcp.zeltser.com/mcp"
enabled = true
Claude Code

.mcp.json

{
  "mcpServers": {
    "lenny-zeltser-s-website-mcp-server": {
      "type": "http",
      "url": "https://website-mcp.zeltser.com/mcp"
    }
  }
}
Claude Desktop

Settings → Connectors → Add custom connector

Name: lenny-zeltser-s-website-mcp-server
Remote MCP URL: https://website-mcp.zeltser.com/mcp

Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.

Cursor

.cursor/mcp.json

{
  "mcpServers": {
    "lenny-zeltser-s-website-mcp-server": {
      "url": "https://website-mcp.zeltser.com/mcp"
    }
  }
}
Visual Studio Code

.vscode/mcp.json

Add to Visual Studio Code
{
  "servers": {
    "lenny-zeltser-s-website-mcp-server": {
      "type": "http",
      "url": "https://website-mcp.zeltser.com/mcp"
    }
  }
}
Generic MCP

Client-specific MCP configuration

{
  "name": "lenny-zeltser-s-website-mcp-server",
  "transport": "streamable-http",
  "url": "https://website-mcp.zeltser.com/mcp"
}
MCP Inspector

Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.

TRUST AND VERIFICATION EVIDENCE

Loading Trust v2 evidence…

Checking the associated registrable domain. The BuiltWith key remains server-side.

Indexed

Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.