Precursor Security
Prompt Library

What to ask
Precursor Intelligence.

41 read-only tools mean your agent can answer real security questions with evidence. Here is where to start.

Prioritise the queue

Turn a wall of advisories into a short, evidenced list of what to fix first.

Which CVEs affecting Fortinet are actively being exploited right now?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the search_cves_by_vendor, get_shadowserver_cve_activity tools.

search_cves_by_vendorget_shadowserver_cve_activity

Give me the highest-EPSS vulnerabilities added to CISA KEV in the last 14 days.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the list_kev_recent, list_high_epss_cves tools.

list_kev_recentlist_high_epss_cves

Of these CVEs from my scanner, which ones should I actually patch this week?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_cve, list_high_epss_cves tools.

get_cvelist_high_epss_cves

Is this dependency version affected by anything with a real exploit probability?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_vendor_product_version, get_cve tools.

get_vendor_product_versionget_cve

Remediate faster

Get the fix, not just the finding, without leaving your editor.

Write a remediation plan for CVE-2025-53770.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_cve, list_remediation_summary tools.

get_cvelist_remediation_summary

What is the recommended fix and any interim workaround for this CVE?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_cve, list_remediation_summary tools.

get_cvelist_remediation_summary

Show me the CVEs recently added to the remediation queue.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the list_recent_remediation_queue tool.

list_recent_remediation_queue

Understand the threat

Put a vulnerability in context: who uses it, and where it sits in the kill chain.

Map CVE-2024-3400 to the MITRE ATT&CK techniques it enables.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_cve, get_mitre_technique tools.

get_cveget_mitre_technique

Which threat actors target healthcare, and what do they use?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the list_threat_actors_by_industry, get_threat_actor tools.

list_threat_actors_by_industryget_threat_actor

Explain MITRE technique T1059.001 and how to detect it.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_mitre_technique, list_art_atomic_tests tools.

get_mitre_techniquelist_art_atomic_tests

Which threat actors use this MITRE technique, and what malware do they deploy?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the get_mitre_technique, get_threat_actor tools.

get_mitre_techniqueget_threat_actor

Check an indicator

Enrich an IOC or fingerprint before you decide whether to act.

Look up this indicator and tell me what malware it is associated with.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the lookup_ioc, get_malware_sample tools.

lookup_iocget_malware_sample

Is this SHA1 certificate fingerprint linked to known C2 infrastructure?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the lookup_ssl_blacklist tool.

lookup_ssl_blacklist

Is this JA3 fingerprint on any malware blacklist?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the lookup_ja3_blacklist tool.

lookup_ja3_blacklist

Show me IOCs first seen in the last seven days for this malware family.

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the search_iocs, list_recent_iocs tools.

search_iocslist_recent_iocs

Monitor exposure

Keep an eye on the vendors in your stack and the freshness of the data behind the answers.

Which high-EPSS CVEs for Microsoft were added this week?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the search_cves_by_vendor, list_high_epss_cves tools.

search_cves_by_vendorlist_high_epss_cves

What are the top CVEs by honeypot activity over the last 30 days?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the list_shadowserver_top_cves tool.

list_shadowserver_top_cves

How fresh is your exploitation data across all sources?

Ask this of the Precursor Intelligence MCP server once it is connected to your AI agent. It resolves using the data_freshness tool.

data_freshness

Not set up yet?

Add the server to your agent in about two minutes, then paste any prompt above.

Ask your first question free

Mint a free key, connect your agent, and let it pull real exploitation intelligence into your workflow.