Security agent investigations
Give security agents data an analyst can verify
Let an agent query FullHunt, then inspect what came back.
The question
Can the analyst verify what the agent found?
An agent can use Model Context Protocol (MCP) to call named FullHunt tools for assets, domains, vulnerabilities, exploits, and history. The analyst can inspect every returned record before acting.
How it works
01
Connect the MCP server
Expose the FullHunt tools to a compatible agent or development environment.
02
Give it one scoped task
Ask it to enrich an IP or find observed assets affected by a specific CVE.
03
Let the agent call the tools
The agent runs the necessary FullHunt queries and collects each response.
04
Inspect the records
Check the returned host, DNS, vulnerability, or exploit data before taking action.
The records behind the answer
Asset tools
Observed organizations, domains, hosts, ports, and services.
Indicator tools
IP and domain enrichment with passive DNS, history, and Tor context.
Vulnerability tools
CVEs, EPSS, CISA KEV, public exploits, and affected observed assets.
Production API
Documented endpoints for workflows that move beyond an interactive agent.
The answer comes with records an analyst can check.
The agent handles the query sequence. FullHunt returns the underlying data.
What you get
- Named FullHunt tools inside compatible agent clients
- Host, DNS, vulnerability, and exploit records behind the answer
- Prompts that can repeat the same investigation path
- API access for production applications
Run one investigation through MCP.
Connect the server, choose an IP, domain, or CVE, and inspect the records it returns.