deeptempo-mcp-servers
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@deeptempo-mcp-serverslist recent findings"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
DeepTempo MCP Servers
Model Context Protocol (MCP) servers for DeepTempo AI SOC.
Overview
This package provides 4 MCP servers for DeepTempo AI SOC:
deeptempo-findings - Findings and case management (FastMCP)
tempo-flow - Investigation workflow orchestration
approval - Action approval workflow
attack-layer - MITRE ATT&CK layer generation
Related MCP server: cti-mcp-server
Installation
# Install from source (development)
pip install -e .
# Install deeptempo-core dependency first
pip install -e ../deeptempo-core
# Install from git
pip install git+https://github.com/YOUR_USERNAME/deeptempo-mcp-servers.gitUsage
Running Individual Servers
# deeptempo-findings server (FastMCP)
python servers/deeptempo_findings.py
# tempo-flow server
python servers/tempo_flow.py
# approval server
python servers/approval.py
# attack-layer server
python servers/attack_layer.pyUsing with Claude Desktop
Add to your Claude Desktop MCP configuration (~/.config/claude/mcp.json):
{
"mcpServers": {
"deeptempo-findings": {
"command": "python3",
"args": ["/path/to/deeptempo-mcp-servers/servers/deeptempo_findings.py"],
"cwd": "/path/to/your/project"
},
"tempo-flow": {
"command": "python3",
"args": ["/path/to/deeptempo-mcp-servers/servers/tempo_flow.py"],
"cwd": "/path/to/your/project"
},
"approval": {
"command": "python3",
"args": ["/path/to/deeptempo-mcp-servers/servers/approval.py"],
"cwd": "/path/to/your/project"
},
"attack-layer": {
"command": "python3",
"args": ["/path/to/deeptempo-mcp-servers/servers/attack_layer.py"],
"cwd": "/path/to/your/project"
}
}
}Server Descriptions
deeptempo-findings
Provides comprehensive access to findings and cases:
Tools:
list_findings- List security findings with filtersget_finding- Get detailed finding informationlist_cases- List investigation casesget_case- Get detailed case informationcreate_case- Create new investigation caseupdate_case- Update case detailsadd_finding_to_case- Link finding to caseAnd 17+ more tools for case management
tempo-flow
Investigation workflow orchestration:
Tools:
tempo_get_workflows- List available workflowstempo_run_workflow- Execute investigation workflow
approval
Action approval workflow:
Tools:
create_approval_action- Submit action for approvallist_approval_actions- List pending/approved actionsget_approval_action- Get action detailsapprove_action- Approve pending actionreject_action- Reject pending action
attack-layer
MITRE ATT&CK layer generation:
Tools:
get_attack_layer- Get ATT&CK Navigator layerget_technique_rollup- Get technique statisticsget_findings_by_technique- Find findings for techniquecreate_attack_layer- Create custom layer
Configuration
The servers use configuration from deeptempo-core. Set environment variables:
# Database
export DATABASE_URL=postgresql://user:pass@localhost:5432/deeptempo_soc
# Or individual components
export POSTGRES_HOST=localhost
export POSTGRES_PORT=5432
export POSTGRES_DB=deeptempo_soc
export POSTGRES_USER=deeptempo
export POSTGRES_PASSWORD=your_password
# Demo mode (uses generated sample data)
export DEMO_MODE=trueDevelopment
# Install with dev dependencies
pip install -e ".[dev]"
# Run tests
pytest
# Format code
black servers/
ruff check servers/Architecture
deeptempo-mcp-servers/
├── servers/
│ ├── __init__.py
│ ├── deeptempo_findings.py # FastMCP server
│ ├── tempo_flow.py # Standard MCP server
│ ├── approval.py # Standard MCP server
│ ├── attack_layer.py # Standard MCP server
│ └── base.py # Shared utilities
└── tests/
└── test_servers.pyLicense
MIT License - see LICENSE file for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
Runtime permission, approval, and audit layer for AI agent tool execution.
Agent-native security, trust, reliability, data and procurement tools for AI workflows.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables interaction with Arcanna's AI-powered security use cases, allowing users to manage jobs and integrations, query security events, provide feedback for model training, and generate/execute Python code for security automation.-
- FlicenseNot gradedqualityDmaintenanceProvides threat intelligence tools like IoC lookups, event backtracking, and IP enrichment via MCP, enabling automated triage and evidence queries.1-
- FlicenseNot gradedqualityCmaintenanceEnables LLM clients to interact with ThreatConnect v3 for case management and threat intelligence, providing typed tools for creating/updating cases, indicators, and artifacts while handling HMAC authentication and API quirks.-
- AlicenseAqualityAmaintenanceExposes 79 cybersecurity skills and 12 orchestrator agents over MCP, with a typed 11-field output contract, an enforced resolvable-evidence gate (no verdict without a resolvable source), and human-approval gating for every mutating action. Apache-2.0, stdlib-only.84Apache 2.0