Skip to main content
Glama
wyre-technology

abnormal-mcp

abnormal-mcp

MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.

Tools

This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.

Navigation

Tool

Description

abnormal_navigate

Navigate to a domain (threats, messages, remediation, abuse, cases)

abnormal_back

Return to domain selection

Threats domain

Tool

Description

abnormal_threats_list

List detected threat cases (paginated)

abnormal_threats_get

Get full details of a specific threat by ID

Messages domain

Tool

Description

abnormal_messages_list

List messages within a threat case

abnormal_messages_get

Get detailed message analysis (headers, URLs, attachments, AI analysis)

Remediation domain

Tool

Description

abnormal_remediation_manage

Trigger or check remediation actions for a message

Abuse domain

Tool

Description

abnormal_abuse_list

List phishing emails reported via the Abuse Mailbox

Cases domain

Tool

Description

abnormal_cases_list

List active security investigation cases

abnormal_cases_get

Get details of a specific case

Interactive Threat Card (MCP Apps)

  • abnormal_threats_get renders as an interactive threat card in MCP Apps hosts (Claude Desktop/web): subject, sender, attack classification, remediation status, and the messages in the threat. The card is read-only — remediation stays a deliberate, model-mediated action. Plain-JSON behavior is unchanged in other hosts. Neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.

Related MCP server: blumira-mcp

Authentication

Abnormal Security uses Bearer token authentication.

Standalone (env mode)

export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js

Generate your token in the Abnormal portal under Settings > Integrations > API.

Gateway mode

When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.

Running

stdio (for Claude Desktop)

npm install
npm run build
node dist/index.js

HTTP Streamable (for hosted/gateway deployment)

MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js

Docker

docker compose up

Development

npm install
npm run dev          # watch mode
npm test             # run tests
npm run typecheck    # TypeScript type check
npm run build:ui     # rebuild the MCP Apps card bundle (only needed when ui/ changes)

License

Apache-2.0

Install Server
A
license - permissive license
A
quality
A
maintenance

Maintenance

Maintainers
Response time
1wRelease cycle
11Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    An MCP server that integrates ThreatBook's threat intelligence API, offering 15 specialized tools for security analysis. It enables AI models to perform IP reputation checks, domain investigations, file sandbox analysis, and vulnerability intelligence lookups.
    Last updated
    47
    MIT
  • F
    license
    -
    quality
    A
    maintenance
    An MCP server for Blumira SIEM platform, enabling management of security event detection, alerts, and threat response through Blumira's API.
    Last updated
  • A
    license
    -
    quality
    A
    maintenance
    An MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.
    Last updated
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • An MCP server for Arcjet - the runtime security platform that ships with your AI code.

  • MCP server for Appcircle mobile CI/CD platform.

  • MCP server for ScanMalware.com URL scanning, malware detection, and analysis.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/wyre-technology/abnormal-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server