watchtowr-mcp
watchTowr publishes an official open-source MCP server (watchtowr/watchtowr-mcp, v0.1.2) that connects AI assistants to the watchTowr Platform Client API — attack surface assets, findings, hunts, certificates, suspicious domains, threat intel, plus composite intelligence tools (attack-surface summaries, change detection, executive scorecards, compliance reporting). Self-hosted: stdio for MCP clients or HTTP as a standalone service (Docker supported). Authenticates with a watchTowr Platform API key and per-tenant host; no hosted remote endpoint is published. Tool list extracted from the server source (fastmcp).
One-click install for Cursor, VS Code, Claude, and 20+ other MCP clients, powered by API Commons MCP Install — visit install.apicommons.org for more information.
Documentation
Documentation link · transport stdio | http (self-hosted)
Tools
get_asset_changelog— Get change history (changelog) for a specific asset.list_asset_ips— List discovered IP addresses.get_asset_ip_details— Get full details for a specific IP address asset.list_ports_for_ip— List all discovered ports belonging to a specific IP address.get_ip_port_details— Get full details for a specific port belonging to an IP address.list_asset_domains— List discovered root domains.get_asset_domain_details— Get full details for a specific domain.list_asset_subdomains— List discovered subdomains.get_asset_subdomain_details— Get full details for a specific subdomain.list_asset_ports— List discovered open ports across assets.get_asset_port_details— Get full details for a specific port including banner and service.list_asset_ip_ranges— List discovered IP ranges with ASN and country information.get_asset_iprange_details— Get full details for a specific IP range.list_cloud_storage_assets— List discovered cloud storage assets (S3, GCS, Azure blobs, etc.).get_asset_cloud_storage_details— Get full details for a specific cloud storage asset.list_source_code_repositories— List discovered source code repositories.get_asset_repository_details— Get full details for a specific source code repository.list_container_assets— List discovered container registry images.get_asset_container_details— Get full details for a specific container registry image.list_saas_platforms— List discovered SaaS platform instances.get_asset_saas_details— Get full details for a specific SaaS platform instance.list_mobile_app_assets— List discovered mobile applications.get_asset_mobile_app_details— Get full details for a specific mobile application.list_cloud_assets— List discovered cloud assets (AWS, GCP, Azure, etc.).get_cloud_asset_details— Get full details for a specific cloud asset.list_api_documentations— List discovered API documentation assets.get_api_documentation_details— Get full details for a specific API documentation asset.list_package_managers— List discovered package manager registry assets.get_package_manager_details— Get full details for a specific package manager asset.manage_engine_settings— Get or update scan engine settings for a domain, subdomain, or IP asset.set_asset_criticality— Set the criticality level for any supported asset type.manage_asset_business_units— Assign or unassign business units for any supported asset type.manage_asset_custom_property— List, create, update, or delete custom properties on an asset.manage_asset_notes— List, create, update, or delete notes on an asset.update_asset_status— Update the status of any asset type.add_seed_asset— Submit a new seed asset for discovery and monitoring.get_asset_dns_records— Get DNS records associated with a specific asset by name.search_dns_records— Search DNS records globally across all monitored assets.get_attack_surface_summary— Get an overview of the entire attack surface with asset counts by type and finding counts by severity.get_new_assets_since— List all newly discovered assets across every type within a given number of days.get_attack_surface_delta— Get a combined view of new assets AND new findings discovered within a time window.get_business_unit_posture— Get a full security posture overview for a business unit: details, unresolved findings, asset counts, services, certificates, and points of interest.get_finding_with_asset_context— Get finding details enriched with the related asset's full details.get_expiring_certificates_with_services— List certificates expiring within N days, cross-referenced with exposed services on the same hosts.get_hunt_remediation_list— Get expanded finding details for a hunt, formatted for remediation handoff.get_critical_exposure_report— Executive-level exposure summary: critical/high finding counts, CISA-KEV count, expiring certificates, and top recurring finding titles.get_findings_by_asset— Search findings associated with a specific asset by looking up the asset name first.get_stale_findings— List findings that have been open/unresolved for more than N days.get_unassigned_critical_findings— List critical and high severity findings that have no assignee.get_asset_findings_count_by_type— Get a count of unresolved findings broken down by asset type.get_shadow_it_candidates— List newly discovered assets that are not assigned to any business unit.list_cisa_kev_findings— List findings tagged as CISA-KEV (Known Exploited Vulnerabilities).list_findings_by_severity— List findings filtered by severity level.get_finding_details— Get full details for a specific finding including description, evidence, CVSS, CVE, EPSS, and retest history.search_findings— Search findings with rich filters.update_finding_status— Update the status of a finding. Use get_finding_statuses to see available values.retest_finding— Trigger a retest for a specific finding to verify remediation.get_finding_statuses— List all available finding status values.get_findings_summary_by_severity— Get a count breakdown of findings by severity level.get_unresolved_findings_by_business_unit— List open/unresolved findings for a specific business unit.export_finding_pdf— Export a finding report as PDF.update_finding_state— Update the handling state of a finding (e.g. Uninvestigated, In Progress, Completed).list_recent_hunts— List recent hunts with their findings and asset counts.get_hunt_details— Get full details for a specific hunt including description, hypothesis, and references.list_findings_by_hunt— List all findings discovered by a specific hunt.list_assets_by_hunt— List all assets tested by a specific hunt.search_hunts— Search hunts with rich filters.get_hunt_impact_summary— Get a combined impact summary for a hunt: detail, findings by severity, and assets tested.search_assets_by_country— Find services located in a specific country.get_internet_facing_services_summary— Aggregate view of exposed services grouped by service type with counts.get_assets_by_technology— Find all services running a specific technology (e.g. Apache, nginx, Exchange).get_cisa_kev_remediation_status— CISA-KEV tagged findings grouped by status to show KEV compliance posture.find_related_assets— Find assets related to a given asset — subdomains under a domain, ports on an IP, etc.list_vulnerability_intelligence— List vulnerability intelligence entries (CVEs tracked by watchTowr).get_vulnerability_intelligence_details— Get full details for a vulnerability intelligence entry.list_adversary_intelligence— List adversary intelligence profiles (threat actors tracked by watchTowr).get_adversary_intelligence_details— Get full details for an adversary intelligence profile.list_finding_retest_history— List finding retest history across all findings (global audit view).get_finding_retest_history_details— Get retest history for a specific finding (all retest runs).search_active_defense_library— Browse or search the active defense rule library.search_capabilities— Search watchTowr security coverage by hunt title, CVE ID, or TTP tactic.get_watchtowr_source_ips— Get watchTowr Platform source IP addresses that should be whitelisted.get_activity_logs— Get recent activity logs from the watchTowr Platform.search_activity_logs— Search activity logs with filters for type, user, keyword, and date range.list_business_units— List business units. Useful for discovering BU IDs to filter other tools.get_business_unit_details— Get full details for a specific business unit.get_asset_inventory_by_business_unit— Full asset inventory for a business unit with counts and sample assets per type.get_out_of_scope_assets— List all assets marked as out of scope or incorrect identification across all types.get_verified_vs_unverified_assets— Breakdown of asset verification status across all types (verified vs unverified counts).get_finding_age_distribution— Bucket open findings by age (0-7d, 7-30d, 30-90d, 90d+) and severity.get_finding_status_timeline— Show how many findings were opened vs remediated per week over the last N days.get_open_ports_summary— Summarize the most common open ports across the attack surface with counts.get_assets_without_findings— List asset types that have assets but zero unresolved findings — potential coverage gaps.get_certificate_health_report— Certificates grouped by health: expired, expiring within 7 days, expiring within 30 days, and valid.get_executive_risk_scorecard— Single-call executive risk dashboard: total assets, findings by severity, CISA-KEV, mean finding age, expiring certs, and newest finding.get_week_over_week_delta— Weekly trend report: new assets and new findings per week.get_security_posture— Get the security posture dashboard — overall score, coverage metrics, and trends.get_top_findings_by_occurrence— Most frequently occurring finding titles across the attack surface — reveals systemic issues.list_technology_statistics— List technology statistics for discovered services, ordered by count.list_services— List exposed services across the attack surface with extensive filtering.list_suspicious_domains— List domains flagged as suspicious (typosquatting, lookalikes, brand impersonation).get_suspicious_domain_details— Get full details for a suspicious domain including WHOIS data.list_points_of_interest— List points of interest (leaked credentials, exposed configs, interesting endpoints).list_certificates— List SSL/TLS certificates with subject, issuer, and expiry information.get_certificate_details— Get full details for a specific certificate including subject, issuer, SANs, and validity.get_expiring_certificates— List certificates expiring within a given number of days.search_pending_domains— List pending/unclaimed domains that could be claimed by adversaries.get_recent_remediations— List findings remediated within the last N days.get_daily_digest— 24-hour digest: new assets, new findings, and recent activity log entries.bulk_retest_findings— Trigger retests for multiple findings at once.bulk_update_finding_status— Update the status of multiple findings at once.get_actionable_findings_queue— Prioritized queue of open findings sorted by severity then age, optionally filtered by assignee.get_findings_needing_assignment— All open findings with no assignee, grouped by severity — the triage inbox.
About MCP
The Model Context Protocol (MCP) is an open protocol Anthropic introduced for connecting LLM-based agents to external tools and data sources. Providers publish MCP servers that expose their API surface as structured, discoverable tools — an MCP-compatible client (Claude Desktop, Cursor, Cline, Continue, etc.) can connect to the server and call its tools without any per-provider integration code.
Browse every MCP server on the APIs.io network or compare with the broader Agent Skill surfaces of the same providers.
Work with this as data
Every MCP server here is available over the APIs.io API and to AI agents over MCP.