cybersec-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cybersec-mcpassess my AWS IAM permissions for compliance"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cybersec-mcp
MCP server with 323 cybersecurity prompts and 7 chained workflows. Install it and Claude (or any MCP-compatible client) can run an incident-response plan, a cloud audit, or a pentest by calling tools instead of you copy-pasting prompts.
Live demo · MIT License · Model Context Protocol
Install
npx -y @xu-c0/cybersec-mcpClaude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"cybersec": {
"command": "npx",
"args": ["-y", "@xu-c0/cybersec-mcp"]
}
}
}Then:
Use cybersec to plan an incident response for unusual outbound traffic from a SIEM-flagged host. SIEM is Splunk, EDR is CrowdStrike.
The agent picks the incident-response scenario, fills your variables in, and walks through detection, triage, containment, eradication, and post-mortem with concrete commands at each step.
Related MCP server: Tengu
Tools
323 prompts across 8 categories. Every prompt takes typed variables and returns output in a defined shape (steps, tables, SIEM queries, MITRE tags).
Category | Prompts | Covers |
Red Team | 45 | Pentest methodology, AD attack paths, C2 infra, social engineering |
Blue Team | 42 | Log analysis, IR playbooks, detection engineering, deception |
SOC Operations | 42 | Splunk/Sentinel/Elastic queries, alert triage, runbooks, shift handover |
Cloud Security | 38 | AWS/Azure/GCP audits, IAM, container security, CSPM |
OSINT | 38 | Domain intel, threat actor profiling, footprinting, attribution |
GRC | 38 | ISO 27001, SOC 2, NIST CSF, risk assessment, policy generation |
Vulnerability Analysis | 42 | CVE triage, CVSS 4.0, patch prioritization, pentest reports |
AI Agent Security | 38 | LLM red teaming, prompt injection, agent guardrails, supply chain |
Source: content/prompts-master.md → generated web-app/js/data.js.
Scenarios
Seven end-to-end workflows that chain prompts and pass variables between steps:
Web App Penetration Test — recon → mapping → fingerprinting → API testing → exploitation → post-exploit → reporting
Incident Response — detection → log investigation → severity → containment → eradication → comms → lessons learned
Cloud Security Audit — IAM → network → storage → database → logging → compliance
Bug Bounty Recon — subdomains → ports → tech → OSINT → surface → vuln assessment
Compliance Audit (ISO 27001) — scoping → risk → controls → evidence → gaps → docs
Threat Hunting — hypothesis → query design → pivot → validation → response
AI Security Assessment — inventory → access control → red team → prompt injection → supply chain → monitoring
Definitions live in web-app/js/scenarios.js.
Web demo
cybersec-mcp.vercel.app — browse every prompt, fill in variables, copy the rendered text into any LLM. Dark mode, English / 한국어 / 日本語, no signup. Same data as the MCP server, different interface.
Useful when you want to inspect what a tool will send before wiring up the server, or hand a teammate a one-off prompt.
ATT&CK mapping
Red team, blue team, and SOC prompts are tagged to MITRE ATT&CK tactics. The full mapping is in ATTACK_MATRIX.md — useful for purple-team exercises and detection-coverage reviews.
Layout
mcp/ MCP server (TypeScript, in progress)
web-app/ Static demo deployed to Vercel
content/ prompts-master.md — prompt source of truth
examples/ Client configs (Claude Desktop, Cursor, Claude Code)parse_prompts.py regenerates web-app/js/data.js from content/prompts-master.md.
Contributing
PRs welcome — new prompts, MITRE tags, scenario workflows, translations, MCP tool fixes. Schema and quality bar in CONTRIBUTING.md.
This project is for authorized security testing, defensive operations, security research, and education. PRs promoting unauthorized access will be rejected. See CODE_OF_CONDUCT.md.
License
MIT — see LICENSE. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; this project is not affiliated with MITRE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceCyberSecurity MCP Server extends Claude with real-time cybersecurity reconnaissance capabilities that Claude doesn't have by default. Instead of manually running 5 different tools across different terminals, just tell Claude "analyze google.com" and get a complete security breakdown instantly. Tools included: * WHOIS Lookup — registrar, ownership, creation/expiry dates * DNS Enumeration — A,Last updated819MIT
- Alicense-qualityDmaintenanceTurns Claude into a penetration testing copilot with 80 security tools, safety controls, and automatic reporting.Last updated53MIT
- Flicense-qualityDmaintenanceProvides 180+ tools for full system control including terminal, Git, Docker, Kubernetes, VMs, BIOS, kernel, cybersecurity, AI, and cloud, designed to work with MCP clients like Cursor and Claude Desktop.Last updated
- AlicenseAqualityCmaintenanceConverts Claude into a cybersecurity assistant by exposing 17 tools for network reconnaissance, cryptography, and security analysis, enabling users to perform tasks like SSL certificate checking, port scanning, and JWT analysis directly within conversations.Last updated17MIT
Related MCP Connectors
Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Hosted MCP with 91 agent tools: X, domains, SEO, Maps, Trends, Search, YouTube, TikTok, and more.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/xu-c0/cybersec-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server