ContrastAPI
ContrastCyber · https://contrastcyber.com
https://api.contrastcyber.com/.well-known/agent-card.json
● healthy
Security + OSINT API with 53 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and conditional triage Prompt for AI agents: CVE/KEV/CWE lookup, composite risk scoring (CVSS+EPSS+KEV+PoC fusion), CVSS v3.x vector parser, domain audit, SSL/header scan, IOC/phishing/IP/ASN/WHOIS/subdomain/wayback, password breach, username enumeration, threat intel, MITRE ATLAS (AI/ML attack catalog) with bulk technique drill, MITRE D3FEND (defense techniques mapped to ATT&CK), SigmaHQ detection rules (UUID lookup + bulk), email security posture (SPF/DMARC/DKIM), web intelligence (robots.txt parser, redirect-chain walker, email validation, brand-asset scraper, SEO audit).
Transport
—
Protocol
0.3
Price
—
Skills
-
CVE LookupLook up CVE details with CVSS, EPSS, KEV, patch infosecuritycvevulnerability
-
CVE SearchSearch CVEs by vendor, product, keywordsecuritycve
-
Leading CVEsTop trending/high-severity CVEssecuritycve
-
Bulk CVE LookupBatch CVE detailssecuritycve
-
Exploit LookupPublic exploits for a CVEsecurityexploit
-
KEV DetailCISA KEV record: federal patch deadline, required action, ransomware association, CWE listsecuritycvekevcisa
-
CWE LookupMITRE CWE catalog: description, mitigations, parent/child weakness chain, CVE countsecuritycweweakness
-
Domain AuditFull-stack domain security auditosintdomain
-
Domain ReportSummary report for a domainosintdomain
-
Subdomain EnumerationEnumerate subdomains via crt.shosintdomain
-
DNS LookupDNS records (A, AAAA, MX, TXT, NS)osintdns
-
WHOIS LookupDomain registration infoosintwhois
-
SSL/TLS CheckCertificate validation + grading (A-F)securityssl
-
Security HeadersHTTP security header validation with value checkssecurityheaders
-
Scan HeadersBulk header scansecurityheaders
-
Tech FingerprintDetect CMS, frameworks, servers, JS librariesosintfingerprint
-
Injection CheckBasic SQLi/XSS reflection testsecurityinjection
-
Secret Leakage CheckScan for exposed secrets in responsessecuritysecrets
-
Dependency CheckVulnerable JS library detectionsecuritydependencies
-
IOC LookupIndicator of compromise check (IP, domain, hash)threat-intelioc
-
Bulk IOC LookupBatch IOC checkthreat-intelioc
-
IP LookupIP geolocation, ASN, reputationosintip
-
ASN LookupAutonomous system infoosintasn
-
Hash LookupFile hash reputation (MD5/SHA1/SHA256)threat-intelhash
-
Threat IntelMulti-source threat lookupthreat-intel
-
Threat ReportConsolidated threat reportthreat-intel
-
Phishing CheckPhishing URL detectionsecurityphishing
-
Password BreachHIBP password breach check (k-anonymity)securitypassword
-
Disposable EmailDetect disposable / temp email domainsosintemail
-
Email MXEmail domain MX record validationosintemail
-
Phone LookupPhone carrier, region, countryosintphone
-
Username LookupCross-platform username enumerationosintusername
-
Wayback LookupInternet Archive snapshots for a URLosintwayback
-
ATLAS Technique LookupMITRE ATLAS (AI/ML attack catalog) technique lookup by id (AML.T####). Returns tactics, maturity, ATT&CK bridge, pivot hintssecurityai-mlatlasmitre
-
ATLAS Technique SearchSearch the MITRE ATLAS AI/ML attack catalog by keyword, tactic, or maturitysecurityai-mlatlasmitre
-
Bulk ATLAS Technique LookupDrill into up to 50 MITRE ATLAS technique ids in a single call — natural follow-up to atlas_case_study_lookup's techniques_used arraysecurityai-mlatlasmitrebulk
-
ATLAS Case Study LookupMITRE ATLAS real-world AI/ML attack incident case study (AML.CS####)securityai-mlatlasincident
-
ATLAS Case Study SearchSearch ATLAS case studies by keyword or by referenced ATLAS techniquesecurityai-mlatlasincident
-
D3FEND Defense LookupMITRE D3FEND defense technique lookup by slug (e.g. TokenBinding). Returns tactic, artifact, mapped ATT&CK T-codessecurityd3fenddefensemitre
-
D3FEND Defense SearchSearch D3FEND defenses by keyword, tactic (Harden/Detect/Isolate/...), or targeted artifactsecurityd3fenddefensemitre
-
D3FEND Reverse LookupGiven an ATT&CK T-code, return all D3FEND defenses that mitigate it. Bridges offensive intel (CVE/ATLAS/ATT&CK) to defensive playbooksecurityd3fenddefensemitreattack
-
D3FEND Coverage AuditBatch defense coverage breakdown across multiple ATT&CK T-codes — count defenses per tactic + identify undefended techniquessecurityd3fenddefensemitreaudit
-
Contrast Triage (Prompt)v1.23.0 conditional MCP Prompt: pick a tool chain by perspective ('red' = offensive recon, 'blue' = defensive triage) for an auto-detected target (CVE / ATLAS / ATT&CK / CWE / hash / IP / domain).securityprompttriageworkflow
-
ATLAS Catalog (MCP Resources)v1.23.0 MCP Resources: browse the full MITRE ATLAS catalog (167 techniques + 57 case studies) without spending a tool slot. URIs: atlas://catalog, atlas://technique/{id}, atlas://case-study/{id}.securityai-mlatlasmitreresource
-
D3FEND Catalog (MCP Resources)v1.23.0 MCP Resources: browse the full MITRE D3FEND defense catalog (149 defenses). URIs: d3fend://catalog, d3fend://defense/{id}.securityd3fenddefensemitreresource
-
CWE Catalog (MCP Resources)v1.23.0 MCP Resources: browse the full MITRE CWE catalog (944 weaknesses). URIs: cwe://catalog (slim), cwe://weakness/{id} (full record).securitycwemitreresource
-
Robots.txt Parserv1.25.0 Fetch + parse a target domain's robots.txt — sitemaps, per-User-agent allow/disallow, crawl-delay, Host directive (RFC 9309). Use BEFORE crawling/scraping a target site to honour its published rules.osintweb-intelrobotscrawler
-
Redirect Chain Walkerv1.25.0 Walk a URL's HTTP redirect chain hop-by-hop, returning per-hop status, Location, latency. SSRF-guarded at every hop. Use to deobfuscate URL shorteners, audit suspicious phishing links, trace marketing tracking redirects.osintweb-intelredirectphishing
-
Email Verify (Combined)v1.25.0 One-call email validation combining syntax + MX records + disposable check + role-address detection (admin@/info@/noreply@) + free-provider classification (gmail/outlook/yahoo). Replaces 2-3 tool calls. NO SMTP RCPT TO probing — ethical floor declared.osintemailvalidationlead-gen
-
Brand Assets Scraperv1.25.0 Scrape a domain's homepage <head> for public brand assets — favicon, og:image, theme-color, og:site_name, JSON-LD Organization.logo. Enriches CRM records / company-card UIs without manual screenshots. Honours robots.txt, Cache-Control, per-target throttle.osintweb-intelbrandingcrm
-
SEO Audit (One-Page)v1.25.0 One-shot SEO audit of a domain's homepage with a 0-100 composite score (10 rules) + missing_signals list of concrete fixes. Use BEFORE pitching SEO work, when triaging a lead's marketing maturity, or as a structured pre-flight before deeper Lighthouse / SEMrush audits. Honours robots.txt.seoweb-intelauditmarketing
How to call
A2A endpoint (JSONRPC)
https://api.contrastcyber.com
Documentation
https://api.contrastcyber.com/quickstart
Homepage
https://contrastcyber.com