ms-sentinel-mcp-server
If you are the rightful owner of ms-sentinel-mcp-server and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.
A Model Context Protocol (MCP) server for Microsoft Sentinel, providing read-only access for advanced querying and incident viewing in Azure Sentinel environments.
The Microsoft Sentinel MCP Server is designed to facilitate observation-only security operations and analysis within Azure Sentinel environments. It offers a modular and extensible platform that allows users to execute KQL queries, manage log analytics, view security incidents, and explore various resources in a read-only capacity. This server is intended for test environments only, ensuring that sensitive data is not exposed to public LLMs or operators. It supports a wide range of features, including analytics rule management, threat intelligence lookups, and Entra ID user and group details viewing. The server is set up using a PowerShell script that checks for Python installation, creates a virtual environment, and installs necessary dependencies, making it easy to integrate with MCP clients like Claude Desktop.
Features
- KQL Query Execution: Run and validate KQL queries, test with mock data
- Log Analytics Management: Workspace info, table listings and schemas
- Security Incidents: List and view detailed incident information
- Analytics Rules: List, view, and analyze by MITRE tactics/techniques
- Threat Intelligence: Domain WHOIS and IP geolocation lookups