Malwarebytes MCP logo

Integrate Malwarebytes MCP with your AI CRM

Verify links, emails, phone numbers, and domains against Malwarebytes threat intelligence.

Explore Triggers and Actions

Reputation-check email

Use this when you need to check if an email address is associated with phishing, scams, or malicious activity. Checks the email domain against threat intelligence database. Returns one of: - malicious: Confirmed phishing or malicious email domain - suspicious: Potentially dangerous email domain - safe: Verified legitimate email domain - unknown: No threat intelligence available Cross-tool workflow: - If the email contains URLs, consider scanning them with reputation-check_link. - If the email contains phone numbers, consider scanning them with reputation-check_phone. - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). Do not use this for email validation, mailbox verification, or general email lookup services.

ActionTry it

Reputation-check link

Use this when you need to check if a link or URL is safe, suspicious, or malicious. Provides reputation verdict based on threat intelligence database. Returns one of: - malicious: Confirmed harmful link - suspicious: Potentially dangerous link - safe: Verified safe link - unknown: No threat intelligence available Cross-tool workflow: - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). - If the URL redirects to a different domain, consider scanning the destination URL separately. - If the URL came from an email or text message, consider checking the sender with reputation-check_email or reputation-check_phone. Do not use this for general web searches, content fetching, or webpage analysis.

ActionTry it

Reputation-check phone

Use this when you need to check if a phone number is associated with scams or suspicious activity. Provides reputation verdict and additional phone information. Returns one of: - malicious: Confirmed scam or spam phone number - suspicious: Potentially dangerous number - safe: Verified legitimate number - unknown: No threat intelligence available Also provides optional details like carrier, location, and phone type when available. Cross-tool workflow: - If the caller provided links, consider scanning them with reputation-check_link. - If the caller provided email addresses, consider scanning them with reputation-check_email. Do not use this for phone number lookups, caller ID services, or general phone directory searches.

ActionTry it

Reputation-report

Use this when a user wants to report a suspicious link, email address, or phone number. Submits the indicator to the threat intelligence system for analysis. Only use when explicitly requested by the user. Do not use this to automatically report every checked item.

ActionTry it

Reputation-scan all

Use this when you need to check multiple links, emails, or phone numbers at once. Scans all indicators concurrently and returns a unified result. Each indicator needs: - type: 'url', 'email', or 'phone' - value: the URL, email address, or phone number (E.164 format for phones) Returns a summary with counts per verdict and individual results for each indicator. Prefer this over individual scan tools when 3 or more indicators are present. Maximum 10 indicators per request. Cross-tool workflow: - For unknown URL or email verdicts, consider using reputation-whois on the associated domains for additional registration context and abuse contact information.

ActionTry it

Reputation-whois

Use this when you need to look up domain registration information to verify legitimacy or identify suspicious patterns. Provides WHOIS/RDAP data including registrar, registration dates, name servers, and abuse contacts. Particularly useful for identifying newly registered domains (common in phishing and scams). Returns the registrar's abuse contact email when available, which can be used for filing complaints about fraudulent domains. Cross-tool workflow: - Consider using reputation-check_link to check the domain's threat reputation alongside WHOIS registration data. Do not use this for general domain availability checks or bulk domain searches.

ActionTry it

How the Malwarebytes MCP integration works

The Malwarebytes MCP integration connects your Dench AI CRM directly to Malwarebytes MCP, so agents can read and act on your Malwarebytes MCP data as part of everyday work — answering questions in chat, keeping your CRM in sync, and running automations without anyone copying data between tools.

6 actions are available for agents to invoke on your behalf. Every call runs through Malwarebytes MCP's own authorization, scoped to the account you connect.

Set up Malwarebytes MCP in Dench

  1. 1

    Sign in to your Dench workspace and open Integrations.

  2. 2

    Find Malwarebytes MCP and click Connect — you'll authorize access through Malwarebytes MCP's own sign-in flow. No API keys or code required.

  3. 3

    Ask an agent to use Malwarebytes MCP in chat, or call it from an automation.

  4. 4

    Manage or disconnect the connection any time from workspace settings.

Frequently asked questions

How does the Malwarebytes MCP integration work with Dench?

The Dench Malwarebytes MCP integration connects your AI CRM to Malwarebytes MCP, so AI agents can work with your Malwarebytes MCP data as part of chats, automations, and CRM workflows. You connect your account once, and every agent in your workspace can use it — governed by your workspace permissions.

What actions can AI agents perform with Malwarebytes MCP via Dench?

The Malwarebytes MCP integration currently exposes 6 actions, including Reputation-check email, Reputation-check link, Reputation-check phone, Reputation-report, Reputation-scan all, and Reputation-whois. Agents invoke them on your behalf from chat or from automations.

Do I need to write code to connect Malwarebytes MCP to Dench?

No. You connect Malwarebytes MCP from your Dench workspace using Malwarebytes MCP's own sign-in and authorization flow — no API keys to copy, no glue code to maintain.

Is the Malwarebytes MCP integration secure?

Connections are authorized through Malwarebytes MCP's own authentication flow, and Dench stores only the authorization needed to act on your behalf. You can review and disconnect the Malwarebytes MCP connection from your workspace settings at any time.

Malwarebytes MCP | Dench AI CRM