Skip to main content
Glama

sec-ops-mcp

SecOps MCP Server (sec-ops-mcp)

License: MIT MCP Version

SecOps MCP is an enterprise-grade Model Context Protocol server that arms LLMs and AI agents with direct diagnostic capabilities for defensive security posture assessments, privilege escalation surface auditing, and Post-Quantum Cryptography (PQC) readiness checks.


🛠️ Integrated Tooling Modules

Module

Scope

Key Diagnostic Capabilities

QuantumGuard

PQC & Modern Cryptography

Scans x509 cert chains for classical vs. PQC algorithms (FIPS 203/204), evaluates Shor's vulnerability risks on RSA/ECC, and probes TLS endpoints for hybrid key exchange support.

PrivScope

Linux Privilege Surface

Identifies dangerous SUID/SGID binaries (GTFOBins mapped), unauthorized cap_setuid/cap_dac_override capabilities, and writable scheduled task matrices.

WinScope

Windows Privilege Surface

Audits AlwaysInstallElevated registry bypasses, unquoted service paths running under SYSTEM, and misconfigured service binary DACLs.


Related MCP server: PentestMCP

🚀 Quickstart

Prerequisites

  • Python 3.10+

  • pip / venv

Installation

git clone [https://github.com/JoaquinHernandez/sec-ops-mcp.git](https://github.com/JoaquinHernandez/sec-ops-mcp.git)
cd sec-ops-mcp
python3 -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate
pip install -r requirements.txt

⚙️ Client Integration

Add this MCP server definition to your client configuration:

Claude Desktop (claude_desktop_config.json)

{
  "mcpServers": {
    "secops-scanner": {
      "command": "/absolute/path/to/sec-ops-mcp/.venv/bin/python",
      "args": ["/absolute/path/to/sec-ops-mcp/server.py"]
    }
  }
}

Cursor / Local MCP Agents

{
  "mcpServers": {
    "secops-scanner": {
      "command": "python",
      "args": ["./server.py"],
      "cwd": "/absolute/path/to/sec-ops-mcp"
    }
  }
}

📋 Available MCP Tools

  • scan_pqc_readiness(target_dir): Evaluates local certificate stores against NIST PQC migration guidelines.

  • scan_tls_quantum_posture(hostname, port): Connects to TLS services to check for post-quantum hybrid key exchange suites.

  • audit_linux_posture(deep_scan): Scans Linux hosts for SUID escalation vectors and capability leaks.

  • audit_windows_posture(): Scans Windows registry and service tables for privilege escalation flaws.


🔒 Security & Defense-in-Depth Notes

This MCP server is built specifically for read-only posture assessment and hardening verification. It performs passive analysis and structured reporting, enabling autonomous defensive assistants to guide engineers through remediation workflows without generating offensive payloads.

A
license - permissive license
Not graded
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.
    1
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    Enables LLMs to perform Active Directory penetration testing using tools like NetExec, Bloodhound, Nmap, Certipy, and John the Ripper. Automates vulnerability discovery, attack path analysis, and documentation generation for security assessments.
    26
    6
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables AI assistants to perform authorized penetration testing and security assessments by exposing 20+ Kali Linux security tools (nmap, sqlmap, gobuster, hydra, etc.) through a safe, validated interface with command allowlists, rate limiting, and input sanitization.
    19
    1
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables authorized compliance verification and security auditing through natural language, bridging AI assistants with industry-standard security tools for enterprise audits.
    24

View all related MCP servers

Related MCP Connectors

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.

  • Read-only tools over the Safer Agentic AI framework: 238 patterns + 14 heuristics.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/JoaquinHernandez/sec-ops-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server