Exploitation-led threat intelligence,
in your stack this week
Precursor Intelligence curates threat feeds from private and public sources, scores exploitation risk with EPSS, CISA KEV and Shadowserver honeypot signal, and maps alerts to MITRE ATT&CK down to sub-technique. One bearer token gives you every dataset, over REST or a 41-tool MCP server.
A threat intelligence platform (TIP) collects, normalises, correlates and operationalises cyber-threat data so a SOC can query it and act on it. Precursor Intelligence is a threat intelligence platform that fuses Shadowserver honeypot exploitation data with the standard open feeds (EPSS, CISA KEV, MITRE ATT&CK) into one queryable platform, available over a REST API and an MCP server.
Already have an account? Log in
MITRE-mapped intelligence you can act on, not just read
Every alert and threat actor maps to MITRE ATT&CK down to sub-technique. Curated IOC feeds and ransomware and threat-actor tracking filter out the noise, and each finding carries remediation guidance with alerts routed straight to email, Slack, Microsoft Teams or a webhook.
API-first and agent-native
Every dataset is queryable over a single bearer-token REST API. A production MCP server exposes 41 tools over Streamable HTTP, so AI agents can query threat intelligence directly, and webhooks push JSON events into your pipeline as they happen.
- Bearer-token REST API
- MCP server, 41 tools, Streamable HTTP
- Webhooks: real-time JSON events
- Alerts via Email, Slack, MS Teams or Webhook
Exploitation risk, not just severity
CVSS tells you how bad a vulnerability could be. Precursor Intelligence scores whether it is actually being exploited, then has AI explain the impact in plain English.
Built for enterprise and MSSP scale
Precursor Intelligence runs agentless, with UK and EU data residency, transparent published pricing and a free forever tier, built and run by a CREST-accredited team.
The threat intelligence platform market in 2026 spans large commercial players and open-source tools. Precursor Intelligence sits alongside them as a platform that scores exploitation risk with EPSS, CISA KEV and Shadowserver honeypot signal, with transparent published pricing and a free forever tier where most competitors default to quote-only sales.
Put threat intelligence to work
One bearer token, every dataset, and a 41-tool MCP server for agent workflows. Pair it with vulnerability prioritisation, point-in-time penetration testing, and 24/7 managed SOC for a closed intelligence loop.
Enterprise or MSSP? Talk to sales.
Common questions
A threat intelligence platform (TIP) collects, normalises, correlates and operationalises cyber-threat data, so a SOC or security team can query it and act on it rather than manually stitching together feeds. It typically covers CVEs, malware, threat actors, ransomware groups and indicators of compromise (IOCs) in one queryable system.
Most threat intelligence platforms hand you a feed and leave the deployment work to you. Precursor Intelligence turns intelligence into action across three areas.
- Deployable: every alert and threat actor maps to MITRE ATT&CK down to sub-technique, backed by curated IOC feeds, remediation guidance and alerts routed to email, Slack, Microsoft Teams or a webhook.
- Exploitation-led: EPSS probability scoring, CISA KEV flagging and Shadowserver honeypot signal decide what matters, not severity alone, with AI summarising the impact in plain English.
- API-first and agent-native: one bearer token covers the REST API, a 41-tool MCP server for AI agents such as Claude, and webhooks for real-time events.
Yes. Every dataset, CVE, EPSS, CISA KEV, MITRE ATT&CK, threat actors, ransomware, and IOCs, is queryable over a bearer-token REST API. A production MCP server exposes 41 tools over Streamable HTTP for AI agents such as Claude, and webhooks push JSON events into your own pipeline in real time. Alerts can also be routed to email, Slack, Microsoft Teams or a webhook, so a curated indicator reaches your team without you polling an API.
Precursor Intelligence combines EPSS probability scoring with CISA KEV flagging (kept live as the catalogue updates) and Shadowserver honeypot exploitation data as a live input signal. AI analysis then reads the underlying security advisory and summarises the impact in plain English, so a score comes with the context to act on it.
Yes. Every alert and threat actor is mapped to MITRE ATT&CK down to sub-technique level, not just the broad tactic, so you can see exactly where a threat sits in the kill chain.
The platform is available over a REST API and a production MCP server, with transparent published pricing rather than a quote-only sales process, so it fits into an existing MSSP toolchain. For specific enterprise or managed-service requirements, talk to us.