OneFirewall Alliance | Cyber Defense | CTI to Stop Attacks
OneFirewall - Global Real-time threat intelligence IoC/CTI with firewall and IPS integrations for automated blocking from Crowd and Alliance prevention network
https://onefirewall.com/Connect straight to this server’s public endpoint.
https://mcp.onefirewall.com/mcpWe add this server to your workspace, walk through sign-in once, then open Studio with tools ready to run.
Last probed Sep 14, 2026 · mcp.onefirewall.com
4tools discovered
Get Ip Intel
Retrieve full Cyber Threat Intelligence (CTI) for a specific IPv4 address. Queries the OneFirewall Alliance CTI database and returns the complete threat profile for the given IP: OFA Crime Score (0–1000), all Alliance member reports and confirmations, MITRE ATT&CK technique mappings, STIX 2.x enrichment bundles, observed attack events with timestamps, geolocation (country, region), and ASN/AS-domain information. The Crime Score is computed by a weighted, time-aware, trust-aware engine that fac
Get Live Ipv4 Feeds
Stream a real-time blocklist of malicious IPv4 addresses filtered by minimum Crime Score. Returns all IPv4 addresses in the OneFirewall Alliance database whose OFA Crime Score meets or exceeds `min_score`. Scores are computed in real time by the v3.2 weighted scoring algorithm (range 0–1000). Recommended starting threshold: ≥ 400 (conservative); ≥ 190 has proven an effective balance between blocking precision and false-positive rate across Alliance deployments. The response is plain text — one
Report Ip
Submit threat intelligence about a malicious IPv4 address to the OneFirewall Alliance. Contributes a threat indicator to the Alliance's collective CTI database. Each submission feeds the OFA Crime Score engine: confidence weighting, source trust (based on your organisation's historical accuracy and false-positive rate), cross-member correlation, and temporal decay are all factored in. Reports from Alliance members are the primary driver of the shared blocklist served by `get_live_ipv4_feeds` an
Get Agent Status
List WCF Agents registered to your organisation with their live configuration and sync status. Returns all WCF Agent installations. Each entry exposes the full operational picture of that agent: - `agid` / `mgid` — Agent ID and organisation ID - `active` — Whether the agent is currently active - `hostname` — Host where the agent binary is installed - `plugin` — IPS/firewall platform being managed (e.g. "fortigate", "checkpoin
Get your MCP into directories
A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.
Directory coverage for brandsOneFirewall - Global Real-time threat intelligence IoC/CTI with firewall and IPS integrations for automated blocking from Crowd and Alliance prevention network
Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.
MCPBundles probed 4 tools on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.
OneFirewall Alliance | Cyber Defense | CTI to Stop Attacks may require signing in to the provider before tools can run. Connect through MCPBundles or your MCP client and complete any provider login when prompted.
Operate OneFirewall Alliance | Cyber Defense | CTI to Stop Attacks? Verify ownership to take over this directory entry.
This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.