UTMStack MCP Server
OfficialRelated Servers
Alternatives to UTMStack MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to converse in plain language with a Wazuh SIEM deployment, querying and aggregating alerts, hunting threats, triaging vulnerabilities, running compliance checks, and executing or rolling back active responses across multi-cluster environments. Works with both cloud and fully local, air-gapped LLM clients while enforcing scoped, audited access to the security tools.MIT
- AlicenseNot gradedqualityBmaintenanceEnables natural language interaction with Wazuh SIEM for alert querying, threat hunting, vulnerability scanning, and active response actions.MIT
- AlicenseNot gradedqualityDmaintenanceBridges AI assistants with Wazuh SIEM infrastructure, providing natural language access to security alerts, vulnerability analysis, CVE databases, and network documentation for security operations.MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to query Wazuh security alerts, investigate hosts, detect brute-force attempts, and generate security summaries by connecting to a Wazuh manager.-
- AlicenseNot gradedqualityAmaintenanceBrings the full AlertLogic MDR platform into AI assistants, exposing 473+ tools for incident response, log search, SOAR automation, and multi-account security operations at MSSP scale.MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to operate a Splunk SOAR instance headlessly via its REST API, supporting container triage, playbook authoring and execution, and asset management.2MIT
TDQS
Scored across 44 tools
Most tools have clear, distinct purposes. Some overlap exists between alert search/get and agent lookups, but they serve different query needs. Overall, an agent should be able to differentiate them.
Predominantly verb_noun snake_case, with some deviations like 'ping', 'whoami', and 'can_run_command'. The pattern is consistent enough for predictable navigation.
44 tools is on the heavy side for a single server, covering multiple domains (alerts, incidents, agents, rules, filters). While each tool serves a purpose, the count borders on excessive.
The tool surface is comprehensive for SIEM operations, covering CRUD for alerts, incidents, rules, and filters. Minor gaps exist (e.g., no update incident details or agent modification) but core workflows are well-supported.