Security & Testing
zeltser.com
Search and retrieve content from Lenny Zeltser's security-focused website, including articles and writing guidelines for security reports.
ENDPOINT 1
https://website-mcp.zeltser.com/mcp
MCP server metadata
- Name
- Lenny Zeltser's Website MCP Server
- Version
- 8.1.3
This server provides expert security content by Lenny Zeltser, covering incident response, malware analysis, cybersecurity leadership, and security product strategy. ## When to Use This Server - The user needs to **write, structure, or review an incident response report** - The user has **raw incident notes** and needs to turn them into a professional report - The user needs to **write, structure, or review a malware analysis report** - The user needs to **turn reverse-engineering or dynamic-analysis notes into a report** - The user wants to **improve writing quality** in security reports, assessments, pentest reports, or audit findings - The user is **planning, evaluating, or reviewing a cybersecurity product strategy** - The user wants to **research** expert articles on malware analysis, incident response, or security leadership ## Available Tools **Search & Reference** - `search_zeltser`: Search articles by keyword - `get_article`: Retrieve full article content by URL path - `get_capabilities`: Detailed guide to all tools and parameters **Security Writing** - `get_security_writing_guidelines`: Improve tone, structure, clarity in any security document **Incident Response Reports** - `ir_load_context`: Load guidelines for creating reports from raw notes - `ir_get_template`: Get the IR report template (default) or brief template (`kind: 'brief'`) - `ir_get_guidelines`: Quick writing tips by topic (tone, words, structure, brief, frameworks, handoffs) - `ir_review_report`: Get criteria for reviewing an existing IR report - `ir_get_brief_template`: Standalone IR brief template - `ir_get_cross_server_routes`: When to consult other MCP servers for IR work - `ir_get_frameworks`: NIST SP 800-61r3 + GDPR + CCPA/CPRA + HIPAA + NCSL state laws + sibling frames **Product Strategy** - `product_load_context`: Load strategic frameworks for creating or evaluating product plans - `product_get_template`: Get the fill-in-the-blank strategy template - `product_get_guidelines`: Quick guidance on a specific topic (pricing, competitive, sales, etc.) - `product_review_plan`: Get criteria for reviewing an existing product strategy - `product_compare_context`: Comparative analysis framework for multi-company evaluation **Cybersecurity Writing Rating Sheets** - `rating_get_sheet`: Get one or all cybersecurity-writing rating sheets (rubric only, no score) - `rating_score_writing`: Score a draft against a sheet — the ONLY tool that produces numeric scores - `rating_load_context`: Load all sheets plus the scoring playbook in one call **AI Defense Matrix** - `aidefense_load_context`: Load matrix, framework alignments, and evaluation + cross-mapping playbooks - `aidefense_get_matrix`: Structured matrix data (8 AI asset classes x 6 NIST CSF functions) - `aidefense_get_framework_alignment`: Cross-mappings to NIST IR 8596, ISO 42001, MITRE ATLAS, OWASP LLM Top 10, CSA AICM, Google SAIF, OWASP AI Exchange, OWASP Agentic Top 10 - `aidefense_evaluate_program`: Per-cell prompts and gap inventory for assessing an AI security program - `aidefense_cross_map`: Coverage taxonomy and capability-to-cell prompts for vendor product mapping **Cyber Threat Intel (CTI) Reports** - `cti_load_context`: Load guidelines for drafting a CTI report or one-page brief - `cti_get_template`: Get the long report or one-page brief template (`template: 'report' | 'brief'`) - `cti_get_guidelines`: Topic-by-topic guidance including attribution, confidence, pyramid of pain, six signals, anti-patterns, brief, handoffs - `cti_review_report`: Get criteria for reviewing an existing CTI report or brief - `cti_get_brief_template`: Standalone CTI brief template - `cti_get_cross_server_routes`: When to consult MITRE ATT&CK, MISP, etc. for CTI work - `cti_get_frameworks`: 12 primary CTI frameworks (Diamond Model, MITRE ATT&CK, Q Model, ICD-203, etc.) + sibling frames **Malware Analysis Reports** - `malware_load_context`: Load section guidance, MBC capability model, ICD-203 family-call confidence, Pyramid-of-Pain IOC tiering, and briefPolicy - `malware_get_template`: Get the 15-section malware analysis report template - `malware_get_guidelines`: Topic-by-topic guidance including capabilities, confidence, Pyramid of Pain, anti-patterns, methodology, fields, handoffs, and frameworks - `malware_review_report`: Get criteria for reviewing an existing malware analysis report - `malware_get_cross_server_routes`: When to consult sandbox, file reputation, detection-rule, passive-DNS, symbol, or certificate tooling - `malware_get_frameworks`: MBC + MITRE ATT&CK + Pyramid of Pain + ICD-203 + STIX + TLP plus sibling artifacts **Vulnerability Investigation Briefs** - `vuln_load_context`: Load guidelines for drafting a one-page vulnerability investigation brief (always embeds 6 mcpHandoffs pointers) - `vuln_get_template`: Get the brief template - `vuln_get_guidelines`: Topic-by-topic guidance including significance discipline (renamed from severity in 1.1.0), actions, gaps, evidence sources, handoffs - `vuln_review_brief`: Get criteria for reviewing an existing brief; surfaces relevant handoffs based on focus - `vuln_get_brief_template`: Standalone Vuln brief template (functionally equivalent to vuln_get_template) - `vuln_get_cross_server_routes`: When to consult NVD, CISA KEV, vendor advisories - `vuln_get_frameworks`: 5 primary frameworks (CVSS, CVE, NVD, CISA KEV, Vendor Advisory) + sibling frames (EPSS, SSVC, VEX) + sibling artifacts **Security Assessment Reports** - `assessment_load_context`: Load guidance for a findings-based assessment report or brief — risk-adjusted severity, reader-first sections, frameworks - `assessment_get_template`: Get the report template (default) or the one-page brief (`kind: 'brief'`) - `assessment_get_guidelines`: Quick writing tips by topic (severity, findings, remediation, methodology, scope, strengths, brief) - `assessment_review_report`: Get criteria for reviewing a report, mapped to the info-assessment rating sheet (17 items) - `assessment_get_brief_template`: Standalone one-page assessment brief template - `assessment_get_cross_server_routes`: When to consult vuln/ir/cti tools or MITRE ATT&CK, CVE, or web research - `assessment_get_frameworks`: NIST SP 800-115/800-30, OWASP WSTG and Risk Rating, CVSS, MITRE ATT&CK, PTES, PCI DSS, CREST ## Tool Selection Match the user's intent to the right tool: - **Writing/creating** a report or plan from scratch → `*_load_context` (+ `include_template: true` for product) - **Improving** writing quality, tone, or clarity in any security document → `get_security_writing_guidelines` - **Reviewing/critiquing** an existing draft → `*_review_report` or `*_review_plan` - **Scoring** a draft against a structured rubric (numeric score, gap analysis, or rubric-anchored feedback) → `rating_score_writing` - **Quick guidance** on a specific topic (tone, structure, pricing, etc.) → `*_get_guidelines` - **Researching** published expert content → `search_*` + `get_article` - **Structuring** a new document → `*_get_template` ## Privacy All tools return guidelines and frameworks to your AI for local analysis. This server never requests user documents, notes, drafts, or plans, and instructs your AI to keep them local.
Known tools 53
get_articleGet the full content of a specific article from Lenny Zeltser's Website by URL path.
Inferred read-onlyget_index_infoGet statistics about the Lenny Zeltser's Website search index including total pages indexed, last update time, and available tools.
Potential side effectsget_capabilitiesList all capabilities and tools available from the Lenny Zeltser's Website MCP server, including search tools and any specialized features like IR report writing assistance.
Inferred read-onlyget_security_writing_guidelinesGet Lenny Zeltser's expert writing guidelines for security reports and assessments.
Inferred read-onlyir_get_guidelinesGet Lenny Zeltser's expert writing guidelines for incident response reports.
Inferred read-onlyir_review_reportGet Lenny Zeltser's expert criteria for reviewing an existing IR report.
Inferred read-onlyproduct_get_templateGet Lenny Zeltser's fill-in-the-blank template for planning a security product strategy.
Inferred read-onlyproduct_get_guidelinesGet Lenny Zeltser's expert strategic guidelines for a specific product strategy topic.
Inferred read-onlyproduct_load_contextLoad Lenny Zeltser's product strategy context for local analysis.
Inferred read-onlyproduct_review_planGet Lenny Zeltser's expert criteria for reviewing an existing product strategy plan.
Inferred read-onlyproduct_compare_contextLoad Lenny Zeltser's comparative analysis framework for evaluating multiple security companies side by side.
Inferred read-onlyrating_get_sheetGet Lenny Zeltser's cybersecurity-writing rating sheet(s) so your AI can apply the rubric.
Inferred read-onlyrating_score_writingGet Lenny Zeltser's scoring playbook so your AI can score a draft locally against a cybersecurity-writing rating sheet.
Inferred read-onlyrating_load_contextLoad Lenny Zeltser's complete cybersecurity-writing rating toolkit: all 7 sheets, scoring policy, scoring playbook, and cross-references to the writing guidelines.
Inferred read-onlyaidefense_load_contextLoad Lenny Zeltser's AI Defense Matrix context: the 8-asset x 6-NIST-CSF-2.
Inferred read-onlyaidefense_get_matrixGet the structured AI Defense Matrix: 8 AI-specific asset rows x 6 NIST CSF 2.
Inferred read-onlyaidefense_get_framework_alignmentGet AI Defense Matrix cross-mappings to nine external frameworks: NIST IR 8596, CSA AI Controls Matrix, ISO 42001, Google SAIF, SANS Critical AI Security Guidelines, MITRE ATLAS, OWASP AI Exchange, OWASP LLM Top 10, OWASP Agentic Security Top 10.
Inferred read-onlyaidefense_evaluate_programGet the AI Defense Matrix evaluation playbook for assessing an AI security program: per-cell prompts, gap-inventory template, and a workflow that walks each asset class first and rolls findings up to the Govern column.
Inferred read-onlyaidefense_cross_mapGet the AI Defense Matrix cross-mapping playbook for mapping product capabilities to matrix cells: coverage taxonomy (primary, secondary, partial, aspirational), differentiation guidance, disambiguation block, worked examples, and out-of-scope examples.
Inferred read-onlyaidefense_locate_conceptReverse-lookup a single concept ID (MITRE ATLAS technique like 'AML.
Inferred read-onlyir_get_cross_server_routesGet Lenny Zeltser's IR cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.
Inferred read-onlyir_get_frameworksGet Lenny Zeltser's IR frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).
Inferred read-onlycti_review_reportGet Lenny Zeltser's expert criteria for reviewing an existing CTI report or brief.
Inferred read-onlycti_get_cross_server_routesGet Lenny Zeltser's CTI cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.
Inferred read-onlycti_get_frameworksGet Lenny Zeltser's CTI frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).
Inferred read-onlymalware_get_guidelinesGet Lenny Zeltser's expert malware analysis report writing guidelines.
Inferred read-onlymalware_load_contextLoad Lenny Zeltser's malware analysis report writing context for local analysis.
Inferred read-onlymalware_review_reportGet Lenny Zeltser's expert criteria for reviewing an existing malware analysis report.
Inferred read-onlymalware_get_cross_server_routesGet Lenny Zeltser's Malware cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.
Inferred read-onlymalware_get_frameworksGet Lenny Zeltser's Malware frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).
Inferred read-onlyvuln_get_templateGet Lenny Zeltser's one-page Vulnerability Advisory Brief template.
Inferred read-onlyvuln_get_guidelinesGet Lenny Zeltser's expert vulnerability-brief writing guidelines.
Inferred read-onlyvuln_load_contextLoad Lenny Zeltser's Vulnerability Investigation Brief context for local analysis.
Inferred read-onlyvuln_review_briefGet Lenny Zeltser's expert criteria for reviewing an existing Vulnerability Investigation Brief.
Inferred read-onlyvuln_get_brief_templateGet Lenny Zeltser's Vuln one-page executive brief template.
Inferred read-onlyvuln_get_cross_server_routesGet Lenny Zeltser's Vuln cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.
Inferred read-onlyvuln_get_frameworksGet Lenny Zeltser's Vuln frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).
Inferred read-onlyassessment_get_guidelinesGet Lenny Zeltser's expert security assessment report writing guidelines.
Inferred read-onlyassessment_load_contextLoad Lenny Zeltser's security assessment report writing context for local analysis.
Inferred read-onlyassessment_review_reportGet Lenny Zeltser's expert criteria for reviewing an existing security assessment report or brief.
Inferred read-onlyassessment_get_brief_templateGet Lenny Zeltser's Security Assessment one-page executive brief template.
Inferred read-onlyassessment_get_cross_server_routesGet Lenny Zeltser's Security Assessment cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult.
Inferred read-onlyassessment_get_frameworksGet Lenny Zeltser's Security Assessment frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone).
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.lenny-zeltser-s-website-mcp-server]
url = "https://website-mcp.zeltser.com/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"lenny-zeltser-s-website-mcp-server": {
"type": "http",
"url": "https://website-mcp.zeltser.com/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: lenny-zeltser-s-website-mcp-server
Remote MCP URL: https://website-mcp.zeltser.com/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"lenny-zeltser-s-website-mcp-server": {
"url": "https://website-mcp.zeltser.com/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"lenny-zeltser-s-website-mcp-server": {
"type": "http",
"url": "https://website-mcp.zeltser.com/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "lenny-zeltser-s-website-mcp-server",
"transport": "streamable-http",
"url": "https://website-mcp.zeltser.com/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Loading Trust v2 evidence…
Checking the associated registrable domain. The BuiltWith key remains server-side.
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.