Threat Intelligence

SOCRadar Brings Licensed Threat Intelligence Straight into ChatGPT

SOCRadar · 7 Sept 2026
Key Takeaway If your business relies on AI assistants for security tasks, check whether your threat intelligence provider offers a similar direct integration so analysts get consistent, contextualised data instead of stitching together results from multiple tools by hand.

SOCRadar has released a new integration that connects its licensed threat intelligence modules to ChatGPT through a Model Context Protocol (MCP) server. Once analysts authorise the connection over OAuth, they can enrich indicators, check whether a CVE is being actively exploited, and search Dark Web exposure data without leaving the ChatGPT conversation window.

The integration is designed to solve a common workflow problem: investigating a single suspicious indicator often means jumping between a threat intelligence platform, an enrichment service, a vulnerability database, and Dark Web search tools, each with different query syntax and export formats. SOCRadar says this manual stitching slows investigations and can lead to skipped enrichment steps when analysts are under time pressure, resulting in decisions made on incomplete information.

With the SOCRadar Threat Intelligence MCP app connected to the SOCRadar MCP server, analysts can call these licensed intelligence tools in plain language from within the same workspace they already use to draft incident reports and summarise advisories, rather than switching between multiple consoles.

SOCRadar ChatGPT threat intelligence AI security dark web monitoring
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from SOCRadar. We link back to every original so you can read it yourself.