Enterprise SecOps MCP Server
Provides whitelisted, operational read-only CLI diagnostics for Cisco IOS/NX-OS devices.
Allows inspection of compute and GKE container metrics via Google Cloud Monitoring TimeSeries queries.
Generates issue tracking tasks with full markdown diagnostics in Jira.
Audits host resource utilization, service status, and critical event logs on Linux hosts.
Reads NGINX runtime statistics via status modules and inspects upstream pools.
Enables dynamic vulnerability queries and host risk metrics through Qualys VMDR.
Enables executing raw SPL queries, monitoring scheduled search jobs, and extracting live alert streams from Splunk.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Enterprise SecOps MCP ServerQuery Sentinel for open critical incidents in the last 24h"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
enterprise-secops-mcp
🛡️ Enterprise SecOps & Infrastructure MCP Server
A Unified, Hardened Model Context Protocol (MCP) Server for Modern Security Operations, Multi-Cloud Telemetry, and Infrastructure Automation.
Features • Architecture • Supported Integrations • Quickstart • Configuration • Security
⚡ Overview
The Enterprise SecOps MCP Server bridges the gap between Large Language Models (LLMs) and mission-critical enterprise environments. By translating high-level natural language intent into deterministic, validated API actions, security analysts, SREs, and DevOps engineers can triage incidents, audit vulnerabilities, verify network path topologies, and orchestrate automated remediations across hybrid architectures.
Related MCP server: Purple AI MCP Server
🏗️ Architecture
┌───────────────────────────────┐
│ LLM Client / MCP Host │
│ (Claude Desktop, Cursor, AI) │
└───────────────┬───────────────┘
│ stdio / SSE (OAuth 2.1)
▼
┌───────────────────────────────┐
│ FastMCP SecOps Engine │
│ - Input Schema Validator │
│ - Safe Execution Layer │
│ - Least Privilege RBAC │
└───────┬───────────────┬───────┘
│ │
┌────────────────────────┴─┐ ┌─┴────────────────────────┐ │ Hybrid Multi-Cloud & SIEM│ │ Network, ITSM & Agents │ ├──────────────────────────┤ ├──────────────────────────┤ │ • AWS CloudWatch │ │ • Cisco IOS / NX-OS │ │ • Azure Monitor │ │ • F5 BIG-IP Traffic LTM │ │ • GCP Cloud Ops │ │ • NGINX Server Fleet │ │ • Splunk Enterprise/Cloud│ │ • ServiceNow Incidents │ │ • Microsoft Sentinel │ │ • Jira Issue Pipeline │ │ • Tenable.io / Qualys VM │ │ • Microsoft Teams Alerts │ │ • EDR Response Engine │ │ • AiAura Platform API │ └──────────────────────────┘ └──────────────────────────┘
🎯 Supported Integrations
1. 🛡️ SIEM, Vulnerability & Endpoint Response
Splunk: Execute raw SPL queries, monitor scheduled search jobs, extract live alert streams.
Microsoft Sentinel: Query incidents across Log Analytics workspaces by severity and MITRE ATT&CK tactics.
Tenable.io / Tenable.sc: Fetch asset vulnerability postures and CVE exposure levels.
Qualys VMDR: Run dynamic vulnerability queries and host risk metrics.
EDR Agent API: Trigger network isolation, policy quarantine, or process remediation.
2. ☁️ Multi-Cloud Telemetry & Infrastructure
AWS CloudWatch & EC2: Scan alarms across AWS regions, query metrics, and parse status checks.
Azure Monitor: Retrieve alert summaries and resource metrics across enterprise subscriptions.
Google Cloud Monitoring: Inspect compute and GKE container metrics via TimeSeries queries.
3. 🌐 Enterprise Network & Delivery
F5 BIG-IP: Audit LTM pools, active connection distributions, and node health.
Cisco IOS/NX-OS: Execute whitelisted, operational read-only CLI diagnostics via Netmiko.
NGINX: Read runtime statistics via status modules and inspect upstream pools.
4. ⚙️ Operating Systems & ITSM Automation
Linux / Windows Hosts: Audit host resource utilization, service status, and critical event logs.
ServiceNow: Automatically create and triage ITSM incident tickets (Table API).
Jira: Generate issue tracking tasks with full markdown diagnostics.
Microsoft Teams: Dispatch real-time adaptive cards to incident response channels.
AiAura Platform: Connect directly to multi-tenant telemetry and autonomous remediation pipelines.
🚀 Quickstart
Prerequisites
Python
>= 3.10uv (recommended) or standard
pip
1. Clone & Setup
# Clone the repository
git clone [https://github.com/your-username/enterprise-secops-mcp.git](https://github.com/your-username/enterprise-secops-mcp.git)
cd enterprise-secops-mcp
# Create and activate virtual environment using uv
uv venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# Install editable package with core dependencies
uv pip install -e .This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables automated review and analysis of network security controls (AWS Security Groups, Network ACLs) using natural language queries. Supports NSC configuration reviews, network segmentation testing, and identifying security gaps through conversational LLM interaction.MIT

Purple AI MCP Serverofficial
AlicenseAqualityBmaintenanceEnables MCP clients to interact with SentinelOne's cybersecurity platform for security analysis, threat investigation, and asset management through natural language queries. Provides read-only access to alerts, vulnerabilities, misconfigurations, and inventory data.3394MIT- AlicenseBqualityDmaintenanceEnables AI-driven SOC investigations by providing automated Splunk querying, threat intelligence enrichment, and response actions through natural language. Includes tools for IP pivoting, lateral movement detection, and label harvesting.311Apache 2.0
- FlicenseNot gradedqualityDmaintenanceEnables authorized compliance verification and security auditing through natural language, bridging AI assistants with industry-standard security tools for enterprise audits.24
Related MCP Connectors
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/JoaquinHernandez/enterprise-secops-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server