Purple AI MCP Server
OfficialRelated Servers
Alternatives to Purple AI MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceEnables read-only access to SentinelOne's platform through MCP, allowing security investigations, threat hunting, and asset inventory queries via natural language.MIT
- AlicenseNot gradedqualityCmaintenanceEnables interaction with SentinelOne's security platform, including Purple AI, events, alerts, vulnerabilities, and asset inventory, through MCP.MIT
- AlicenseNot gradedqualityBmaintenanceEnables security analysts and engineers to triage incidents, audit vulnerabilities, query multi-cloud telemetry, inspect network infrastructure, and automate ITSM remediations through natural language.MIT

AccuKnox MCP Serverofficial
FlicenseNot gradedqualityCmaintenanceEnables interaction with the AccuKnox cloud security platform through MCP, allowing users to query cloud assets, vulnerabilities, and perform security analysis via natural language or API.1-- FlicenseAqualityBmaintenanceExposes eSentire Atlas API (Findings, Ticketing, MVS) and Threat Intelligence feeds (IP Watch, Advanced/STIX) as MCP tools, enabling security operations and threat intelligence queries through natural language.29-

octowatch-mcpofficial
AlicenseBqualityBmaintenanceEnables read-only interaction with OctoWatch DLP Cloud, allowing users to query risks, anomalies, user activity, productivity, and reports via natural language.222MIT
TDQS
Scored across 33 tools
Most tools are clearly separated by list/search/get patterns per domain, and the purple_ai vs powerquery distinction is carefully documented. However, several boundaries are fuzzy: get_vulnerability vs cve_search_by_id, threat_intel_by_hash vs threat_intel_get_file_behavior/relationships, and list_inventory_items vs search_inventory_items overlap in ways that could cause misselection.
Resource tools mostly follow a consistent get_/ list_/ search_ pattern, and threat_intel_/ cve_ prefixes impose some order. But core tools purple_ai and powerquery are bare nouns, timestamp helpers use two different styles (get_timestamp_range vs iso_to_unix_timestamp), and threat_intel_get_file_* deviates from the by_* pattern.
33 tools is well into the too-many range for most MCP servers, even for a broad security domain. Several near-duplicate list/search variants and repeated notes/history triples across alerts, misconfigurations, and vulnerabilities suggest the surface could be consolidated.
The read-side surface is strong: every finding type has get/list/search plus notes and history, and threat intel + CVE search are well covered. However, there are no write/action tools (update alert status, assign, add notes, remediate), so investigation workflows hit dead ends and the server is effectively read-only for security operations.