Securitytrails MCP integration
Pulls DNS, SSL, and infrastructure detail for a domain, queries the hosts and ips tables directly, and keeps ASI asset scope current.
12actions available
Three actions you can hand over today
Every action runs live through MCP. Nothing to build, nothing to maintain.
Get domain details
Lyro retrieves comprehensive domain intelligence including DNS records and infrastructure details. You assess whether a website is legitimate or identify security issues.
Search ips
Lyro searches IP addresses using advanced filters to find infrastructure associated with a domain. Your team investigates suspicious traffic and maps network infrastructure.
Get company associated ips
Lyro identifies all IP addresses associated with a company domain to understand their infrastructure. You quickly map network topology and spot rogue infrastructure.
How businesses use Securitytrails + Lyro
Each card is one request a support team gets, and the Securitytrails actions Lyro runs to close it.
Profile a domain and the infrastructure behind it
Lyro retrieves current DNS records, infrastructure detail, and statistics for a domain, reads its current and historical SSL certificates, and lists the IPs linked to that organisation.
Get Domain DetailsGet Domain SSLGet Company Associated IPsFilter IP space with a targeted query
Lyro runs a DSL query across IP addresses, reads the aggregate picture including top open ports and common reverse DNS patterns, and pages through the matches.
Search IPsIP Search StatisticsScroll ResultsAsk a question the prebuilt lookups do not cover
Lyro executes a SQL-style query against the hosts table for domain and DNS data or the ips table for address detail, then pages through the result set.
SQL API Execute QuerySQL API Scroll ResultsKeep an attack surface project scoped correctly
Lyro lists the ASI projects on the account and adds or removes static asset rules in bulk, so the domains and IPs a project watches match what the organisation actually owns.
List ASI ProjectsBulk Static Asset Rules
How it works
Get started in 3 steps
Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Securitytrails actions it has and picks the ones a request needs.
- 01
Connect Securitytrails
Authorize the Securitytrails account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.
- 02
Tell your agent what you need
Describe the job the way you would hand it to a teammate. Lyro maps it to the Securitytrails actions that close it and chains as many as the request needs.
- 03
Watch it work
The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.
Get started free
Everything else about Securitytrails
Setup, permissions, and the limits of what Lyro can do inside Securitytrails.
Only the scope of an ASI project. Bulk Static Asset Rules adds or removes the domains and IPs a project includes or excludes; every other action in the toolkit reads data. Nothing here alters DNS, certificates, or any record outside your own project configuration.
Every action available in Securitytrails
All 12 actions your agent can call on Securitytrails, straight from the live MCP connection.
Bulk static asset rules
Bulk add or remove static asset rules for a SecurityTrails ASI project.
Get company associated ips
Retrieve IPs associated with a company domain.
Get domain details
Retrieves comprehensive domain information from SecurityTrails including current DNS records, infrastructure details, and statistics.
Get domain ssl
Fetch current and historical SSL certificate details for a hostname.
IP search statistics
Fetch aggregated statistics for IP addresses matching a DSL query.
List asi projects
List ASI projects available to the account.
Ping
Test authentication and connectivity with the SecurityTrails API.
Scroll results
Continue scrolling through DSL search results.
Search ips
Search IP addresses via SecurityTrails DSL.
SQL API execute query
Execute SQL-like queries against SecurityTrails data.
SQL API scroll results
Fetch next page of SQL query results.
Temp scrape securitytrails usage
Retrieve account usage information from the SecurityTrails API.
The tools Securitytrails sits next to
Same connection, same setup. Pick the next one your team already uses.
Amplitude
Reads funnel, retention, and revenue metrics on request, annotates releases on the chart, updates cohort membership, and files GDPR deletions.
Databox
Creates Databox data sources and datasets, pushes records into them, verifies each ingestion landed, and removes what is no longer feeding a dashboard.
Google search console
Pulls clicks, impressions, and position data from a live property, inspects URLs that will not index, and submits or audits sitemaps.
Mopinion
Pulls survey responses for a form or report, resolves the fields behind them, and reports where and when a feedback form is shown.
Radar
Reads and updates trip status, starts and completes trips, maintains geofences and beacons, and turns partial addresses into verified coordinates.
Tally
Reads form responses and the questions behind them, builds and edits forms from block definitions, and wires submissions out through webhooks.

Ready to connect Securitytrails?
Authorize the account and your agent has all 12 actions from the first conversation.


