SOCRadar Brings Licensed Threat Intelligence Straight into ChatGPT
SOCRadar has released a new integration that connects its licensed threat intelligence modules to ChatGPT through a Model Context Protocol (MCP) server. Once analysts authorise the connection over OAuth, they can enrich indicators, check whether a CVE is being actively exploited, and search Dark Web exposure data without leaving the ChatGPT conversation window.
The integration is designed to solve a common workflow problem: investigating a single suspicious indicator often means jumping between a threat intelligence platform, an enrichment service, a vulnerability database, and Dark Web search tools, each with different query syntax and export formats. SOCRadar says this manual stitching slows investigations and can lead to skipped enrichment steps when analysts are under time pressure, resulting in decisions made on incomplete information.
With the SOCRadar Threat Intelligence MCP app connected to the SOCRadar MCP server, analysts can call these licensed intelligence tools in plain language from within the same workspace they already use to draft incident reports and summarise advisories, rather than switching between multiple consoles.