Adyton
MCP server for automated phishing URL triage in SOCs. Seven parallel analysis tools, a Dockerized Playwright agent for deep DOM inspection, and a local LLM that reasons over the grey zone to eliminate false positives.
Read the case study →
- SOC analysts receive hundreds of suspicious URLs per day. Manual triage is slow, and rule-based approaches produce too many false positives in the "grey zone", where a URL is neither clearly legitimate nor clearly malicious.
- I designed an MCP (Model Context Protocol) server exposing 7 typed analysis tools: URL syntax, RDAP/WHOIS, SSL, multi-source reputation, AiTM markers and header auditing. Fast triage runs them in parallel within seconds; deep triage launches a Dockerized Playwright agent (stealth mode) that inspects the live DOM, redirect chains and exfiltration. When the score lands in the ambiguous band, a Decision Engine delegates to a local LLM (Ollama) that reasons like an analyst.
- The system turns phishing triage into a composable pipeline interoperable with any MCP client (Claude Desktop, custom agents), cuts false positives through LLM reasoning without sacrificing sensitivity, and produces structured reports (incl. STIX) ready for the analyst.