SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
RiskProfiler launches MCP connector for AI threat hunts

RiskProfiler launches MCP connector for AI threat hunts

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

RiskProfiler has launched the RiskProfiler MCP Connector, which gives authorised users AI-assisted access to external threat intelligence from its platform through compatible AI assistants.

The connector is aimed at security analysts, risk teams, and security leaders investigating issues such as changes to the external attack surface, third-party risk, credential exposure, digital threats, and security operations.

Instead of moving through multiple dashboards, filters, and reports, users can submit natural-language questions through supported AI assistants. The platform remains the system of record, enforcing access controls while providing customer-specific intelligence and investigation context.

How it works

The product uses the Model Context Protocol, or MCP, a standard way for AI applications to request information and functions from connected systems. In this case, the connector translates a user's question into permitted queries or functions within that customer's RiskProfiler environment, then returns relevant results to the assistant.

This is intended to give users another way to access information they are already authorised to view, rather than replace the underlying platform. It positions the AI assistant as an interface layer for exploring data and investigation outputs held in RiskProfiler.

The connector also sits alongside KnyX AI, the company's agentic investigation tool. KnyX AI is designed to collect and correlate evidence, investigate threat signals, generate confidence-scored findings, and support remediation in line with customer-defined policies, while the MCP Connector offers a conversational way to request and review that intelligence.

Investigation use

The connector is designed to support investigations across several external risk areas without forcing users to treat each signal as a separate record. The aim is to help analysts bring together attack-path intelligence across different modules by correlating threat signal analysis, investigation, validation, and prioritisation.

RiskProfiler also outlined entity-centric investigations as a use case. An analyst looking into a domain, for example, can ask for available exposure, digital threat, vulnerability, credential, and third-party context linked to that entity, then refine the inquiry through follow-up questions.

Another example is a daily security briefing. According to RiskProfiler, this can prioritise significant developments across an organisation's external risk landscape based on its configuration and permitted data. The briefing may highlight attack surface changes, new findings, shifts in vendor risk, brand and identity threats, and pending assessment activity.

This is intended to give security teams a focused view of what has changed and which issues may need closer investigation. More broadly, RiskProfiler argues that conversational access could reduce some of the manual work involved in stitching together data from separate parts of a security operation.

"Security teams need to move quickly from identifying a potential issue to understanding its relevance to the business. A conversational way to explore external risk intelligence can reduce time spent navigating disparate data and help analysts focus on investigation, prioritization, and informed action," said Setu Parimi, Co-Founder & CTO, RiskProfiler.

Availability

The connector is expected to initially support Claude. Integrations for OpenAI's ChatGPT and Google Gemini are planned to follow, although product scope and integration timelines remain subject to final confirmation.

The launch reflects a wider move by cybersecurity suppliers to place generative AI interfaces in front of existing data stores and investigation systems. For vendors in external threat intelligence and digital risk protection, the commercial case depends on whether natural-language access can shorten response times without loosening controls over sensitive customer information.

RiskProfiler focuses on external threat intelligence, including brand monitoring, dark web intelligence, third-party risk management, and attack surface management. It said its platform covers attack surfaces, brand threats, vendor breaches, identity risks, physical security vulnerabilities, and emerging cyber threats.