AWS‑IReveal‑MCP

Integrations

  • Provides a unified interface to AWS services for security investigation, including CloudTrail, Athena, CloudWatch, GuardDuty, AWS Config, VPC Flow Logs, Network Access Analyzer, and IAM Access Analyzer for tracing activities, examining data events, searching logs, and analyzing security alerts.

AWS‑IReveal‑MCP

AWS‑IReveal‑MCP是一款模型上下文协议 (MCP) 服务器,旨在为安全团队和事件响应人员提供统一的 AWS 服务接口,方便他们进行调查。通过将 AWS‑IReveal‑MCP 连接到任何 MCP 客户端(例如 Claude Desktop 或 Cline),您无需离开 LLM 驱动的工作区,即可跨多个 AWS 服务调用查询和分析。

特征

AWS‑IReveal‑MCP 与以下 AWS 服务和功能集成:

  • CloudTrail — API 活动的管理事件日志
  • Amazon Athena — 通过 CloudTrail 日志进行 SQL 查询
  • CloudWatch — 操作日志和临时分析
  • Amazon GuardDuty — 威胁检测和发现调查
  • AWS Config — 资源配置历史记录和合规性状态
  • VPC 流日志— 用于取证分析的网络流量元数据
  • 网络访问分析器— 跨 SG/NACL/VPC 的可达性检查
  • IAM 访问分析器— 基于策略和资源的访问结果

这些服务让您

  • 追踪“谁在何时何地做了什么事”(CloudTrail、Config)
  • 检查详细数据事件(Athena)
  • 搜索和可视化日志(CloudWatch、VPC Flow Logs)
  • 表面安全警报(GuardDuty、IAM Access Analyzer)
  • 验证网络可达性和配置(网络访问分析器)

示例提示

  • 分析过去 5 天内 IP xxxx 的活动
  • 分析过去 24 小时内“sysadmin”角色的活动
  • 调查过去 7 天内 us-west-2 上 Cloudtrail 上的可疑活动
  • 过去 7 天内,名称包含“客户”的存储桶上是否有任何数据事件?
  • 调查与 Bedrock 相关的 CloudWatch 日志
  • 针对过去 2 天内发生的 GuardDuty 高风险发现提出补救措施
  • 识别不合规的资源,解释违反的规则,并提出补救措施

安装

先决条件

  • Python 3
  • MCP Python SDK( mcp[cli]
  • boto3 (适用于 Python 的 AWS 开发工具包)
  • 已配置 AWS 凭证

配置

将以下配置添加到您的 MCP 客户端的设置文件:

{ "mcpServers": { "aws-ireveal": { "command": "uv", "args": [ "run", "/path/to/aws-ireveal-mcp/server.py" ], "env": { "AWS_PROFILE": "<YOUR_PROFILE>" } } } }

You must be authenticated.

A
security – no known vulnerabilities
A
license - permissive license
A
quality - confirmed to work

remote-capable server

The server can be hosted and run remotely because it primarily relies on remote services or has no dependency on the local environment.

AWS‑IReveal‑MCP

  1. 特征
    1. 示例提示
  2. 安装
    1. 先决条件
    2. 配置

Related MCP Servers

  • -
    security
    A
    license
    -
    quality
    MCP server for interacting with Prometheus metrics and data.
    Last updated -
    8
    JavaScript
    MIT License
    • Apple
  • Amazon Web Services
    aws-mcp

    A
    security
    F
    license
    A
    quality
    A Model Context Protocol (MCP) server that enables AI assistants like Claude to interact with your AWS environment. This allows for natural language querying and management of your AWS resources during conversations. Think of better Amazon Q alternative.
    Last updated -
    3
    222
    TypeScript
    • Apple
  • A
    security
    F
    license
    A
    quality
    An MCP server that provides tools for interacting with AWS S3 buckets, enabling direct access to S3 operations through the Model Context Protocol.
    Last updated -
    1
    Python
    • Apple

View all related MCP servers

ID: myt94uniyf