wazuh-mcp-server
Related Servers
Alternatives to wazuh-mcp-server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceAn MCP server that enables conversational interaction with Wazuh SIEM, allowing users to investigate alerts, hunt threats, tune false positives, edit rules, and run security actions via natural language.MIT
- AlicenseAqualityAmaintenanceAn MCP server that connects language models to a Wazuh SIEM cluster, enabling read-only plain-language queries, schema inspection, field coverage analysis, and decoder testing.10Apache 2.0
- AlicenseBqualityAmaintenanceAn MCP server for the Wazuh SIEM/XDR platform that enables users to query agents, security alerts, detection rules, and decoders through Claude or other MCP clients. It provides specialized tools and prompts for investigating security alerts, performing agent health checks, and generating environmental security overviews.2810 npm4MIT
- AlicenseAqualityDmaintenanceMCP server that exposes OSSEC HIDS security monitoring capabilities as tools, resources, and prompts for AI assistants.262MIT
- AlicenseNot gradedqualityDmaintenanceA production-ready Model Context Protocol (MCP) server for seamless integration between Wazuh SIEM and Large Language Models (LLMs).92AGPL 3.0
- FlicenseNot gradedqualityCmaintenanceEnables natural-language security operations by connecting Wazuh SIEM to Claude Desktop via MCP, allowing querying of alerts, agents, vulnerabilities, and generating security reports with Slack integration.1-
TDQS
Scored across 28 tools
Every tool has a clearly distinct purpose, from agent management to alert querying to compliance checks. Overlapping functions like listing vs. searching alerts are differentiated by scope and detail.
All tools follow a consistent 'wazuh_verb_noun' pattern (e.g., wazuh_list_agents, wazuh_get_alert), making it predictable and easy for an agent to infer action and resource.
With 28 tools, the set is comprehensive but still well-scoped for the Wazuh security management domain. While slightly above the typical 3-15 range, each tool addresses a specific function without redundancy.
The tool surface covers agent lifecycle, health, alerts, rules, compliance, vulnerability, FIM, cluster, logs, and active response. No obvious dead ends; destructive tools are paired with safety confirmation flows.