mechub sovereign network-security automation ← all projects
mcp server under construction MIT

mecfeedmcp

Governed threat-intel feeds for firewalls (planned)

Planned: governed threat-intel to firewall feeds, built on mecmcp. Under construction: no working code yet, not usable.

About

mecfeedmcp will turn "block this indicator on every firewall" into a governed change: propose, validate, approve, publish. Firewalls pull a versioned feed, so nothing is committed to a device per indicator.

It will be built on the shared mecmcp foundation, with a hardened read-only Rust feed server for firewalls to pull from. It is planned and under construction: there is no working code yet, and it must not be deployed.

Features

  • Planned: read indicators from threat-intel sources (MISP first, OpenCTI later), read-only
  • Planned: propose feed changes as mecmcp change sets, with deterministic validators (reserved ranges, own prefixes, allowlist, mandatory expiry, entry caps)
  • Planned: human approval of the exact digest, and a second human for production
  • Planned feed formats: PAN-OS External Dynamic Lists, Junos SRX feeds, FortiGate threat feeds and OPNsense URL tables
  • Planned: a hardened read-only Rust feed server (rustls, no unsafe code, signed manifests) that firewalls pull from

Quick start

Full instructions in the README ↗