mcp-server-malcolm
Related Servers
Alternatives to mcp-server-malcolm
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceA governed MCP server for digital-forensics and incident-response (DFIR) work, exposing curated forensic tools (Volatility 3, Plaso, RegRipper, etc.) through a single FastMCP HTTP endpoint with bearer-token authentication and tamper-evident audit logging.MIT

Trestle MCPofficial
AlicenseAqualityAmaintenanceMCP server to easily use compliance-trestle for OSCAL compliance workflows from any MCP-compliant client.92Apache 2.0- FlicenseNot gradedqualityBmaintenanceEnterprise MCP server for Google SecOps (Chronicle) SIEM/SOAR, enabling alert triage, UDM telemetry search, YARA-L detection rule management, log ingestion, and parser administration via Streamable HTTP.-
- AlicenseNot gradedqualityCmaintenanceA universal MCP server for registering internal, external, and OpenAPI-based APIs as MCP tools. It exposes them to MCP clients via Streamable HTTP and provides admin portal, RBAC/session auth, credential injection, and audit logging.Academic Free v1.1
- AlicenseNot gradedqualityDmaintenanceThis repository implements an MCP (Model Connector Plugin) server for NetBox with full CRUD capabilities, search, and changelog retrieval.Apache 2.0
- AlicenseAqualityAmaintenanceLocal-first MCP proxy with BM25 tool discovery, quarantine security, Docker isolation, OAuth support, activity logging, and web UI. Routes multiple upstream MCP servers through a single endpoint.9379MIT
TDQS
Scored across 51 tools
The 51 tools cover many overlapping search and aggregation paths (arkime_sessions vs malcolm_search vs search_dsl, arkime_unique vs malcolm_field_values). Each tool has a documented niche, but the sheer number of similar query tools creates selection ambiguity. Some pairs like malcolm_alerts and malcolm_alerting_alerts are explicitly differentiated, but names alone don't make their distinct roles obvious.
Most tools follow a consistent `<prefix>_<noun>` pattern (malcolm_*, arkime_*), and related tools share stems (arkime_session_*, malcolm_field_*, malcolm_alerting_*). However, there is no consistent verb_noun convention: some are verbs (search_dsl, list_indices), some are nouns (arkime_spigraph, malcolm_ping), and mixed styles like malcolm_saved_objects vs malcolm_dashboard_export exist.
51 tools is far beyond the typical well-scoped count; it reflects a very broad read-only API surface. While each tool fills a niche, the number creates cognitive load and suggests insufficient consolidation (e.g., many Arkime field-analysis variants, multiple file/hash retrieval tools).
The surface covers read-only querying well: search, aggregation, status, field discovery, file metadata, dashboards, alerts, anomalies, NetBox. But write operations are missing entirely, despite descriptions referencing tools like malcolm_create_alert, arkime_create_view, and arkime_create_hunt that are not present. This creates dead ends when an agent needs to create or modify resources.