An MCP server that provides Truss threat intelligence capabilities, enabling natural language search, FilterQL filtering, and querying of threat data, along with STIX export and detection rule generation.
A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
MCP-native agentic threat investigation server that investigates IOCs across multiple threat intelligence sources, correlates findings to detect campaigns, and outputs STIX 2.1 bundles.
An MCP server for Microsoft Defender Advanced Hunting that enables AI assistants to investigate security events using natural language by translating queries to KQL and executing them against Defender.