zeek-mcp
Related Servers
Alternatives to zeek-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceA Model Context Protocol server that integrates Zeek network analysis capabilities with LLM chatbots, allowing them to analyze PCAP files and parse network logs through natural language interactions.7Apache 2.0
- AlicenseAqualityAmaintenanceAn MCP server that connects language models to a Wazuh SIEM cluster, enabling read-only plain-language queries, schema inspection, field coverage analysis, and decoder testing.10Apache 2.0
- FlicenseBqualityDmaintenanceA log analysis MCP server that enables tailing, searching, filtering, and summarizing logs from local files and Docker containers.7-
- AlicenseNot gradedqualityCmaintenanceAn MCP server that enables querying logs and metrics from Graylog, Prometheus, and InfluxDB 2.x. It provides tools for executing Lucene log searches, PromQL queries, and Flux queries directly within MCP-compatible clients.MIT
- FlicenseNot gradedqualityDmaintenanceSuricataMCP is a Model Context Protocol Server that allows MCP clients to autonomously use suricata for network traffic analysis. It enables programmatic interaction with Suricata through tools like get\_suricata\_version, get\_suricata\_help, and get\_alerts\_from\_pcap\_file.14-
- FlicenseNot gradedqualityNot gradedmaintenanceA production-oriented, read-only MCP server for secure ELK stack analysis, compatible with OpenClaw.-
TDQS
Scored across 39 tools
Tools are clearly organized by source (zeek, suricata, misp, thehive, pcap, nids) and action, with distinct purposes. Even within Zeek, query tools target specific log types and detection tools address different anomalies, minimizing confusion.
All tool names follow a consistent pattern: source_prefix (zeek_, suricata_, misp_, etc.) followed by a verb or descriptor. Underscores and lowercase are used uniformly, making the set predictable and easy to navigate.
With 39 tools, the server is heavily weighted, exceeding the typical well-scoped range. While the tools are justified by the breadth of NIDS functionality, the count is borderline high and may overwhelm agents.
The tool set covers the full lifecycle of network threat detection and response: data acquisition (pcap, logs), querying (all log types), anomaly detection, threat intelligence integration (MISP), case management (TheHive), and cross-referencing (Suricata-Zeek). No obvious gaps.