Harris HawkEye MCP
Related Servers
Alternatives to Harris HawkEye MCP
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceEnables querying and analysis of a unified database of security detection rules across multiple formats, including Sigma, Splunk, Elastic, KQL, and CrowdStrike CQL.89 npm490Apache 2.0
- AlicenseNot gradedqualityDmaintenanceUnifies 7,283+ detection rules from Sigma, Splunk ESCU, Elastic, and KQL into a single queryable interface via MCP, with a web dashboard and autonomous agent pipeline for detection engineering.89 npm1Apache 2.0
- AlicenseAqualityBmaintenanceProvides access to Atomic Red Team tests, enabling search, validation, and execution of atomic tests via natural language.6132MIT
- FlicenseBqualityDmaintenanceEnables cybersecurity training, purple-team collaboration, and executive readiness through tools for scenario generation, attack simulation, telemetry analysis, incident investigation, forensics, and reporting with an immutable audit trail.12-
- FlicenseBqualityDmaintenanceEnables context-aware EVTX hunting with process lineage tracing and rarity baselining to surface real threats from security logs, transforming raw alerts into actionable kill chain intelligence.31-

mlab.sh MCP serverofficial
AlicenseNot gradedqualityCmaintenanceEnables threat intelligence for SOC and DFIR workflows, including IOC enrichment, CVE and threat actor lookup, domain scanning, and account-based scan management.2MIT
TDQS
Scored across 129 tools
The set contains large clusters of functionally identical tools: 10 CERT/government advisory searches and 12+ vendor blog searches differ only by data source, not operation, forcing agents to choose among near-duplicates for the same task. The coverage/gap cluster (analyze_coverage, get_coverage_summary, identify_gaps, get_top_gaps, get_technique_count, get_technique_ids) also has blurry boundaries that the descriptions only partially resolve.
Most tools follow a predictable snake_case verb_noun or source-prefixed pattern (e.g., {vendor}_search, threatfox_search_*, lookup_*, list_by_*, art_*, coverage_*), making clusters internally coherent. Minor deviations exist: epss_bulk_check vs epss_score_lookup, check_cisa_kev vs cisa_search_advisories, and analyze_coverage vs get_coverage_summary use inconsistent verbs for the same domain.
At 129 tools, this far exceeds even the 50+ extreme threshold. The bloat is driven largely by 20+ source-parameterized duplicate searches and an 8-tool knowledge graph/tribal knowledge subsystem that feels tangential to the core threat-intel mission. The server could be halved by consolidating sources into a single parameterized search tool without losing scope.
The domain surface is unusually comprehensive: IOC lookup/pivoting, CVE enrichment, MITRE ATT&CK querying, detection rule search, coverage assessment sessions, Atomic Red Team validation, query conversion, and hunt report generation form complete end-to-end workflows with few dead ends. Minor gaps exist — knowledge graph entities lack update/delete and detection rules are read-only — but these are peripheral to the server's analysis-oriented purpose.