Skip to main content
Back to Integrations

DarkWebSonar MCP Server

Connect any MCP client to DarkWebSonar. Search threat actors, count events, and pull recent activity. Each query uses your API credits.

MCP endpoint

https://connect.darkwebsonar.io/mcp
  1. 1

    Create an API key

    Open Profile → API Keys, name a key, and copy it. You will paste this key when your client asks you to authorize.

    Open API Keys
  2. 2

    Add the server in your client

    Any client that supports remote MCP (Streamable HTTP) can use the endpoint above. Claude and Cursor are two common options:

    Claude

    Settings → Connectors → Add custom connector. Paste the endpoint above. When the authorize screen opens, paste your API key and approve.

    Cursor

    Add this to your MCP config. Cursor opens the same authorize screen so you can paste your API key.

    Cursor MCP config

    {
      "mcpServers": {
        "darkwebsonar": {
          "url": "https://connect.darkwebsonar.io/mcp"
        }
      }
    }
  3. 3

    Ask a question

    Once connected, ask for a threat actor profile, recent events in a country, or a count over the last 30 days. To disconnect, revoke the API key.

Example questions

  • Who is LockBit, and which countries have they targeted in the last 90 days?
  • How many ransomware events hit healthcare this month?
  • Which industries does Qilin go after?
  • Recommend threat actors for financial services in the United States.
  • What MITRE techniques show up most for Akira?
  • Show recent leak-site posts from the last 7 days.

Prefer REST? See the API documentation.

We use cookies to improve your experience

Help us understand how visitors interact with our website by collecting anonymous information (Google Analytics, Ahrefs, PostHog).