Skip to content
FullHunt

Security agent investigations

Give security agents data an analyst can verify

Let an agent query FullHunt, then inspect what came back.

MCP tools Scoped prompts Source records API access

The question

Can the analyst verify what the agent found?

An agent can use Model Context Protocol (MCP) to call named FullHunt tools for assets, domains, vulnerabilities, exploits, and history. The analyst can inspect every returned record before acting.

How it works

01

Connect the MCP server

Expose the FullHunt tools to a compatible agent or development environment.

02

Give it one scoped task

Ask it to enrich an IP or find observed assets affected by a specific CVE.

03

Let the agent call the tools

The agent runs the necessary FullHunt queries and collects each response.

04

Inspect the records

Check the returned host, DNS, vulnerability, or exploit data before taking action.

The records behind the answer

Asset tools

Observed organizations, domains, hosts, ports, and services.

Indicator tools

IP and domain enrichment with passive DNS, history, and Tor context.

Vulnerability tools

CVEs, EPSS, CISA KEV, public exploits, and affected observed assets.

Production API

Documented endpoints for workflows that move beyond an interactive agent.

The answer comes with records an analyst can check.

The agent handles the query sequence. FullHunt returns the underlying data.

What you get

  • Named FullHunt tools inside compatible agent clients
  • Host, DNS, vulnerability, and exploit records behind the answer
  • Prompts that can repeat the same investigation path
  • API access for production applications

Run one investigation through MCP.

Connect the server, choose an IP, domain, or CVE, and inspect the records it returns.