Skip to main content
Glama
legionultramax

Harris HawkEye MCP

Related Servers

Alternatives to Harris HawkEye MCP

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      D
      maintenance
      Enables querying and analysis of a unified database of security detection rules across multiple formats, including Sigma, Splunk, Elastic, KQL, and CrowdStrike CQL.
      89 npm
      490
      Apache 2.0
    • F
      license
      B
      quality
      D
      maintenance
      Enables cybersecurity training, purple-team collaboration, and executive readiness through tools for scenario generation, attack simulation, telemetry analysis, incident investigation, forensics, and reporting with an immutable audit trail.
      12
      -
    • F
      license
      B
      quality
      D
      maintenance
      Enables context-aware EVTX hunting with process lineage tracing and rarity baselining to surface real threats from security logs, transforming raw alerts into actionable kill chain intelligence.
      3
      1
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables threat intelligence for SOC and DFIR workflows, including IOC enrichment, CVE and threat actor lookup, domain scanning, and account-based scan management.
      2
      MIT

    TDQS

    B3.2/5.0

    Scored across 129 tools

    Disambiguation2/5

    The set contains large clusters of functionally identical tools: 10 CERT/government advisory searches and 12+ vendor blog searches differ only by data source, not operation, forcing agents to choose among near-duplicates for the same task. The coverage/gap cluster (analyze_coverage, get_coverage_summary, identify_gaps, get_top_gaps, get_technique_count, get_technique_ids) also has blurry boundaries that the descriptions only partially resolve.

    Naming Consistency4/5

    Most tools follow a predictable snake_case verb_noun or source-prefixed pattern (e.g., {vendor}_search, threatfox_search_*, lookup_*, list_by_*, art_*, coverage_*), making clusters internally coherent. Minor deviations exist: epss_bulk_check vs epss_score_lookup, check_cisa_kev vs cisa_search_advisories, and analyze_coverage vs get_coverage_summary use inconsistent verbs for the same domain.

    Tool Count1/5

    At 129 tools, this far exceeds even the 50+ extreme threshold. The bloat is driven largely by 20+ source-parameterized duplicate searches and an 8-tool knowledge graph/tribal knowledge subsystem that feels tangential to the core threat-intel mission. The server could be halved by consolidating sources into a single parameterized search tool without losing scope.

    Completeness4/5

    The domain surface is unusually comprehensive: IOC lookup/pivoting, CVE enrichment, MITRE ATT&CK querying, detection rule search, coverage assessment sessions, Atomic Red Team validation, query conversion, and hunt report generation form complete end-to-end workflows with few dead ends. Minor gaps exist — knowledge graph entities lack update/delete and detection rules are read-only — but these are peripheral to the server's analysis-oriented purpose.

    Maintenance

    ActivityMaintained
    ResponsivenessNo issues