threatlocker-mcp-server
Related Servers
Alternatives to threatlocker-mcp-server
No user-submitted related servers found.
Related Servers
- AlicenseCqualityDmaintenanceAn MCP server that connects AI assistants to the ThreatLocker Portal API with 44 tools for managing computers, approvals, action logs, tags, maintenance mode, and more across single-org and multi-tenant setups.441MIT

DelineaMCPofficial
AlicenseNot gradedqualityBmaintenanceMCP server for the Delinea Secret Server and Platform APIs, enabling AI agents to manage secrets, users, groups, folders, roles, and access requests through natural language commands.46MIT- AlicenseBqualityAmaintenanceMCP server that gives AI assistants read-only access to TacticalRMM fleet data (agents, checks, alerts, services, processes, etc.) and, with explicit approval, lets them run commands on managed machines.202AGPL 3.0
- AlicenseNot gradedqualityBmaintenanceMCP server for managing devices via JAMF Pro and Microsoft Intune APIs, enabling AI assistants to query and control device management tasks.MIT
- AlicenseNot gradedqualityBmaintenanceMCP server that enables AI-powered assessment of Active Directory on-premises environments by exposing AD data as queryable tools for LLMs like Claude.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server for ThreatLocker — zero-trust application allowlisting, approval requests, audit logs1-
TDQS
Scored across 18 tools
Each tool maps to a distinct ThreatLocker domain—computers, groups, applications, policies, logs, approvals, organizations, reports, maintenance, scheduling, tags, storage/network policies, versions, online devices, saved searches, and upload requests. Potential overlaps like system_audit vs action_log and policies vs storage_policies/network_access_policies are clearly differentiated by both naming and description.
All tools follow the same snake_case resource-noun pattern: computers, computer_groups, applications, policies, action_log, maintenance_mode, storage_policies, etc. While actions are passed via an 'action' parameter rather than verb-prefixed tool names, the convention is uniform and easy to predict.
18 tools is above the ideal 3-15 range, but the count is justified by the breadth of the ThreatLocker platform—each tool covers a distinct functional area. It feels slightly heavy rather than bloated, and there are no redundant tools that could be merged.
Core lifecycle coverage is strong for applications and policies (create/update/delete/deploy), and there are solid querying tools for logs, approvals, and computers. However, several areas are read-only or lack management operations: computer_groups cannot be created/edited/deleted, storage_policies and network_access_policies are read-only, maintenance_mode is history-only, and scheduled_actions cannot be created or cancelled.