watchtowr-mcp
watchTowr publishes an official open-source MCP server (watchtowr/watchtowr-mcp, v0.1.2) that connects AI assistants to the watchTowr Platform Client API — attack surface assets, findings, hunts, certificates, suspicious domains, threat intel, plus composite intelligence tools (attack-surface summaries, change detection, executive scorecards, compliance reporting). Self-hosted: stdio for MCP clients or HTTP as a standalone service (Docker supported). Authenticates with a watchTowr Platform API key and per-tenant host; no hosted remote endpoint is published. Tool list extracted from the server source (fastmcp).
One-click install for Cursor, VS Code, Claude, and 20+ other MCP clients, powered by API Commons MCP Install — visit install.apicommons.org for more information.
Documentation
Documentation link · transport stdio | http (self-hosted)
Tools
get_asset_changelog— Get change history (changelog) for a specific asset.list_asset_ips— List discovered IP addresses.get_asset_ip_details— Get full details for a specific IP address asset.list_ports_for_ip— List all discovered ports belonging to a specific IP address.get_ip_port_details— Get full details for a specific port belonging to an IP address.list_asset_domains— List discovered root domains.get_asset_domain_details— Get full details for a specific domain.list_asset_subdomains— List discovered subdomains.get_asset_subdomain_details— Get full details for a specific subdomain.list_asset_ports— List discovered open ports across assets.get_asset_port_details— Get full details for a specific port including banner and service.list_asset_ip_ranges— List discovered IP ranges with ASN and country information.get_asset_iprange_details— Get full details for a specific IP range.list_cloud_storage_assets— List discovered cloud storage assets (S3, GCS, Azure blobs, etc.).get_asset_cloud_storage_details— Get full details for a specific cloud storage asset.list_source_code_repositories— List discovered source code repositories.get_asset_repository_details— Get full details for a specific source code repository.list_container_assets— List discovered container registry images.get_asset_container_details— Get full details for a specific container registry image.list_saas_platforms— List discovered SaaS platform instances.get_asset_saas_details— Get full details for a specific SaaS platform instance.list_mobile_app_assets— List discovered mobile applications.get_asset_mobile_app_details— Get full details for a specific mobile application.list_cloud_assets— List discovered cloud assets (AWS, GCP, Azure, etc.).get_cloud_asset_details— Get full details for a specific cloud asset.list_api_documentations— List discovered API documentation assets.get_api_documentation_details— Get full details for a specific API documentation asset.list_package_managers— List discovered package manager registry assets.get_package_manager_details— Get full details for a specific package manager asset.manage_engine_settings— Get or update scan engine settings for a domain, subdomain, or IP asset.set_asset_criticality— Set the criticality level for any supported asset type.manage_asset_business_units— Assign or unassign business units for any supported asset type.manage_asset_custom_property— List, create, update, or delete custom properties on an asset.manage_asset_notes— List, create, update, or delete notes on an asset.update_asset_status— Update the status of any asset type.add_seed_asset— Submit a new seed asset for discovery and monitoring.get_asset_dns_records— Get DNS records associated with a specific asset by name.search_dns_records— Search DNS records globally across all monitored assets.get_attack_surface_summary— Get an overview of the entire attack surface with asset counts by type and finding counts by severity.get_new_assets_since— List all newly discovered assets across every type within a given number of days.get_attack_surface_delta— Get a combined view of new assets AND new findings discovered within a time window.get_business_unit_posture— Get a full security posture overview for a business unit: details, unresolved findings, asset counts, services, certificates, and points of interest.get_finding_with_asset_context— Get finding details enriched with the related asset's full details.get_expiring_certificates_with_services— List certificates expiring within N days, cross-referenced with exposed services on the same hosts.get_hunt_remediation_list— Get expanded finding details for a hunt, formatted for remediation handoff.get_critical_exposure_report— Executive-level exposure summary: critical/high finding counts, CISA-KEV count, expiring certificates, and top recurring finding titles.get_findings_by_asset— Search findings associated with a specific asset by looking up the asset name first.get_stale_findings— List findings that have been open/unresolved for more than N days.get_unassigned_critical_findings— List critical and high severity findings that have no assignee.get_asset_findings_count_by_type— Get a count of unresolved findings broken down by asset type.get_shadow_it_candidates— List newly discovered assets that are not assigned to any business unit.list_cisa_kev_findings— List findings tagged as CISA-KEV (Known Exploited Vulnerabilities).list_findings_by_severity— List findings filtered by severity level.get_finding_details— Get full details for a specific finding including description, evidence, CVSS, CVE, EPSS, and retest history.search_findings— Search findings with rich filters.update_finding_status— Update the status of a finding. Use get_finding_statuses to see available values.retest_finding— Trigger a retest for a specific finding to verify remediation.get_finding_statuses— List all available finding status values.get_findings_summary_by_severity— Get a count breakdown of findings by severity level.get_unresolved_findings_by_business_unit— List open/unresolved findings for a specific business unit.export_finding_pdf— Export a finding report as PDF.update_finding_state— Update the handling state of a finding (e.g. Uninvestigated, In Progress, Completed).list_recent_hunts— List recent hunts with their findings and asset counts.get_hunt_details— Get full details for a specific hunt including description, hypothesis, and references.list_findings_by_hunt— List all findings discovered by a specific hunt.list_assets_by_hunt— List all assets tested by a specific hunt.search_hunts— Search hunts with rich filters.get_hunt_impact_summary— Get a combined impact summary for a hunt: detail, findings by severity, and assets tested.search_assets_by_country— Find services located in a specific country.get_internet_facing_services_summary— Aggregate view of exposed services grouped by service type with counts.get_assets_by_technology— Find all services running a specific technology (e.g. Apache, nginx, Exchange).get_cisa_kev_remediation_status— CISA-KEV tagged findings grouped by status to show KEV compliance posture.find_related_assets— Find assets related to a given asset — subdomains under a domain, ports on an IP, etc.list_vulnerability_intelligence— List vulnerability intelligence entries (CVEs tracked by watchTowr).get_vulnerability_intelligence_details— Get full details for a vulnerability intelligence entry.list_adversary_intelligence— List adversary intelligence profiles (threat actors tracked by watchTowr).get_adversary_intelligence_details— Get full details for an adversary intelligence profile.list_finding_retest_history— List finding retest history across all findings (global audit view).get_finding_retest_history_details— Get retest history for a specific finding (all retest runs).search_active_defense_library— Browse or search the active defense rule library.search_capabilities— Search watchTowr security coverage by hunt title, CVE ID, or TTP tactic.get_watchtowr_source_ips— Get watchTowr Platform source IP addresses that should be whitelisted.get_activity_logs— Get recent activity logs from the watchTowr Platform.search_activity_logs— Search activity logs with filters for type, user, keyword, and date range.list_business_units— List business units. Useful for discovering BU IDs to filter other tools.get_business_unit_details— Get full details for a specific business unit.get_asset_inventory_by_business_unit— Full asset inventory for a business unit with counts and sample assets per type.get_out_of_scope_assets— List all assets marked as out of scope or incorrect identification across all types.get_verified_vs_unverified_assets— Breakdown of asset verification status across all types (verified vs unverified counts).get_finding_age_distribution— Bucket open findings by age (0-7d, 7-30d, 30-90d, 90d+) and severity.get_finding_status_timeline— Show how many findings were opened vs remediated per week over the last N days.get_open_ports_summary— Summarize the most common open ports across the attack surface with counts.get_assets_without_findings— List asset types that have assets but zero unresolved findings — potential coverage gaps.get_certificate_health_report— Certificates grouped by health: expired, expiring within 7 days, expiring within 30 days, and valid.get_executive_risk_scorecard— Single-call executive risk dashboard: total assets, findings by severity, CISA-KEV, mean finding age, expiring certs, and newest finding.get_week_over_week_delta— Weekly trend report: new assets and new findings per week.get_security_posture— Get the security posture dashboard — overall score, coverage metrics, and trends.get_top_findings_by_occurrence— Most frequently occurring finding titles across the attack surface — reveals systemic issues.list_technology_statistics— List technology statistics for discovered services, ordered by count.list_services— List exposed services across the attack surface with extensive filtering.list_suspicious_domains— List domains flagged as suspicious (typosquatting, lookalikes, brand impersonation).get_suspicious_domain_details— Get full details for a suspicious domain including WHOIS data.list_points_of_interest— List points of interest (leaked credentials, exposed configs, interesting endpoints).list_certificates— List SSL/TLS certificates with subject, issuer, and expiry information.get_certificate_details— Get full details for a specific certificate including subject, issuer, SANs, and validity.get_expiring_certificates— List certificates expiring within a given number of days.search_pending_domains— List pending/unclaimed domains that could be claimed by adversaries.get_recent_remediations— List findings remediated within the last N days.get_daily_digest— 24-hour digest: new assets, new findings, and recent activity log entries.bulk_retest_findings— Trigger retests for multiple findings at once.bulk_update_finding_status— Update the status of multiple findings at once.get_actionable_findings_queue— Prioritized queue of open findings sorted by severity then age, optionally filtered by assignee.get_findings_needing_assignment— All open findings with no assignee, grouped by severity — the triage inbox.
About MCP
The Model Context Protocol (MCP) is an open protocol Anthropic introduced for connecting LLM-based agents to external tools and data sources. Providers publish MCP servers that expose their API surface as structured, discoverable tools — an MCP-compatible client (Claude Desktop, Cursor, Cline, Continue, etc.) can connect to the server and call its tools without any per-provider integration code.
Browse every MCP server on the APIs.io network or compare with the broader Agent Skill surfaces of the same providers.