Kyberis
AI agents can be confidently wrong at machine speed. Kyberis delivers confidence-scored, provenance-grounded threat intelligence your agents can reason over and act on.
https://kyberis.ai/Connect straight to this server’s public endpoint.
https://mcp.kyberis.ai/We add this server to your workspace, walk through sign-in once, then open Studio with tools ready to run.
Last probed Sep 14, 2026 · mcp.kyberis.ai
16tools discovered
Threat Investigation Guide
Read this first when the agent needs to perform a threat investigation. Returns the recommended workflow: intel_search for broad questions; entity_resolution to canonicalize; claim_evidence for active_exploitation, sector_targeting, actor_association, campaign_association, malware_association, relevance_to_environment, and observed_in_the_wild; relationships for graph pivots; hunt_pivots for ranked next investigative actions; type-specific assessments for known CVE/actor/IOC subjects; threat_ass
Entity Resolution
Resolve raw user input, aliases, CVEs, actors, malware, campaigns, and observables into canonical entities. Use this before evidence, relationships, or assessments when the entity is not already canonical. Set expected_types aggressively (cve, actor, malware, campaign, ip, domain, url, hash, email) to reduce ambiguity. If resolution.status is ambiguous, disambiguate or retry with narrower expected_types; if not_found, stop or pivot to intel_search.
Entity Resolution Batch
Batch normalize and disambiguate 1-50 raw entity inputs. Use for bounded lists of observables, CVEs, actors, malware, campaigns, or aliases before follow-on investigation. Requires top-level agent_context; each item follows entity_resolution shape and can omit item agent_context. HTTP 200 can still include per-item errors; inspect every item.status, item.result.resolution, and item.error. Use stop_on_error=false for mixed-quality lists.
Claim Evidence
Retrieve bounded evidence for one claim about a canonical subject or raw query. Use after entity_resolution when possible. Provide exactly one of subject or query. claim_type should be one of active_exploitation, sector_targeting, actor_association, campaign_association, malware_association, relevance_to_environment, observed_in_the_wild. For sector_targeting, include context.sector. Use evidence IDs returned here with get_evidence before final synthesis.
Relationships
Retrieve bounded relationship pivots for a canonical subject or raw query. Use after evidence to discover related actors, campaigns, malware, sectors, IoCs, and CVE techniques for follow-on investigation. Provide exactly one of subject or query. Omit relationship_types for all default pivots or request actor/campaign/malware/sector/ioc/technique. Hydrate important returned canonical IDs with get_entity.
Intel Search
Search recent bounded intel capsules for broad or open-ended topic questions before a canonical entity is known. Use for questions like 'what happened with this campaign/topic?' Results are retrieval capsules, not assessments. Use returned canonical_entities and claim_tags as pivots into entity_resolution, claim_evidence, relationships, and assessments.
Prioritize
Rank environment-relevant threat signals for immediate attention. Use when the user asks what to investigate first for a specific environment. Provide environment details such as products, vendors, industry, geography, exposure, and constraints. For top-ranked signals, continue with entity_resolution, claim_evidence, relationships, and type-specific assessments.
Hunt Pivots
Recommend ranked next investigative actions for subject-led or observation-led threat hunting. Use this when the user asks what to hunt next, provides weak telemetry, or has unresolved observables. Use relationships instead when you only need related entities for a resolved subject. Returned pivots include question, query_intent, why, confidence, required_fields, caveats, and optional related_entities.
Threat Assessment
Run deterministic generic threat assessment when the input type is unknown, mixed, or agent-selected dynamically. Use type-specific tools instead when the subject is clearly a CVE, actor, or IOC. Provide exactly one of subject or query. Read resolution to confirm what was scored; treat confidence as score certainty and preserve caveats/degraded metadata.
Cve Assessment
Run deterministic CVE-focused assessment for a known vulnerability. Usually resolve with expected_types=['cve'], gather active_exploitation and sector_targeting evidence, then call this with the canonical subject. Check evidence_refs, signals, caveats, degraded metadata, priority, and confidence before final recommendations.
Actor Assessment
Run deterministic actor-focused assessment for a known threat actor. Resolve aliases first, gather relevance_to_environment and observed_in_the_wild evidence, inspect campaign/malware relationships, then assess. Use threat_assessment instead if the input may be a campaign or malware rather than an actor.
Environment Assessment
Run deterministic environment-context assessment for a threat, CVE, actor, campaign, malware, or IOC. Use when the user asks whether a subject is relevant to their environment, assets, sector, geography, exposure, or controls. Provide exactly one of subject or query plus environment_context; include an optional environment label for readability. For CVE subjects, Kyberis hydrates CVE/KEV metadata from its own data; caller context is supplemental only. environment_context must include at least on
Ioc Assessment
Run deterministic IOC-focused assessment for IPs, domains, URLs, hashes, or emails. Resolve the observable first, gather active_exploitation plus actor/campaign association evidence, inspect relationship pivots, then assess. Preserve lookup status, degraded metadata, caveats, evidence_refs, and next actions.
Assessments Batch
Batch run 1-50 deterministic assessments. Use for bounded IOC/CVE/actor/environment shortlists, especially IOC lists from alerts, SIEM exports, emails, or reports. Each item must include assessment_type and payload; use assessment_type='ioc_assessment' with payload.query for raw IOC strings. Supported assessment_type values are threat_assessment, cve_assessment, actor_assessment, environment_assessment, and ioc_assessment. Requires top-level agent_context; apiv2 propagates it into item payloads
Get Entity
Hydrate canonical entity details by canonical_id after entity_resolution, relationships, or assessment outputs. Use this before final synthesis for important pivots. Requires agent_context, which MCP maps to X-Agent-* headers.
Get Evidence
Hydrate an evidence reference returned by claim_evidence or assessments. Use this for selected evidence_refs before final synthesis so conclusions cite specific supporting material. Requires agent_context, which MCP maps to X-Agent-* headers.
Get your MCP into directories
A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.
Directory coverage for brandsAI agents can be confidently wrong at machine speed. Kyberis delivers confidence-scored, provenance-grounded threat intelligence your agents can reason over and act on.
Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.
Operate Kyberis? Verify ownership to take over this directory entry.
This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.
MCPBundles probed 16 tools on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.
Kyberis may require signing in to the provider before tools can run. Connect through MCPBundles or your MCP client and complete any provider login when prompted.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.