Skip to main content
Glama
yslee96

AWS Security Remediation MCP Server

by yslee96

AWS Security Remediation MCP Server

An MCP (Model Context Protocol) server that provides automated security incident remediation tools for AWS environments. Designed to work with GuardDuty findings for real-time threat response.

Tools

Tool

Description

quarantine_s3_object

Move a malicious S3 object to a quarantine bucket and delete the original

restrict_iam_access

Block all access for a compromised IAM user or role by attaching a deny-all policy

update_security_group

Remove overly permissive inbound rules (0.0.0.0/0) from a security group

Related MCP server: SamiGPT

Prerequisites

  • Python 3.10+

  • AWS credentials configured (environment variables, ~/.aws/credentials, or IAM role)

  • QUARANTINE_BUCKET environment variable set (required for quarantine_s3_object)

Required IAM Permissions

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject",
        "s3:DeleteObject",
        "s3:CopyObject"
      ],
      "Resource": [
        "arn:aws:s3:::SOURCE-BUCKET/*",
        "arn:aws:s3:::QUARANTINE-BUCKET/*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": [
        "iam:PutUserPolicy",
        "iam:PutRolePolicy"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeSecurityGroups",
        "ec2:RevokeSecurityGroupIngress"
      ],
      "Resource": "*"
    }
  ]
}

Installation

pip install -e .

Usage

As a CLI tool (stdio transport)

QUARANTINE_BUCKET=my-quarantine-bucket security-remediation-mcp-server

With Claude Desktop / Amazon Q / Cline

Add to your MCP configuration:

{
  "mcpServers": {
    "security-remediation": {
      "command": "security-remediation-mcp-server",
      "env": {
        "QUARANTINE_BUCKET": "my-quarantine-bucket",
        "AWS_REGION": "us-east-1"
      }
    }
  }
}

With Docker

docker build -t security-remediation-mcp-server .

docker run --rm \
  -e AWS_ACCESS_KEY_ID \
  -e AWS_SECRET_ACCESS_KEY \
  -e AWS_REGION=us-east-1 \
  -e QUARANTINE_BUCKET=my-quarantine-bucket \
  -p 8000:8000 \
  security-remediation-mcp-server

Tool Details

quarantine_s3_object

Moves a malicious S3 object to a quarantine bucket with a date-based path structure, then deletes the original.

Parameters:

  • bucket_name (str): Source S3 bucket name

  • object_key (str): Object key (path) to quarantine

Example response:

{
  "action_type": "quarantine_s3_object",
  "status": "SUCCESS",
  "target_resource": "s3://source-bucket/malware.txt",
  "details": "Moved to quarantine bucket: s3://quarantine-bucket/2026/03/02/source-bucket/malware.txt"
}

restrict_iam_access

Attaches an inline deny-all policy (ACO-EmergencyDenyAll) to an IAM user or role, immediately revoking all permissions.

Parameters:

  • principal_arn (str): Full ARN of the IAM user or role

update_security_group

Removes all inbound rules that allow traffic from 0.0.0.0/0 (any IP address).

Parameters:

  • security_group_id (str): Security group ID (e.g., sg-0123456789abcdef0)

Use Case: GuardDuty Automated Response

This MCP server is designed to be used with an AI agent that receives GuardDuty findings and automatically takes remediation actions:

  1. GuardDuty detects a threat (e.g., malware in S3)

  2. EventBridge routes the finding to an AI agent

  3. Agent analyzes the finding and calls the appropriate tool

  4. Tool executes the remediation (quarantine, block, cleanup)

  5. Agent reports the result

License

MIT

A
license - permissive license
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    B
    quality
    D
    maintenance
    Provides real-time access to AWS security best practices, incident response playbooks, and preventive security measures from the official AWS Customer Playbook Framework repository. Enables users to query AWS security guidance for services like S3, IAM, EC2, and RDS through natural language.
    Last updated
    3
  • A
    license
    -
    quality
    D
    maintenance
    An AI-powered security operations platform that integrates with SIEM, EDR, and case management systems via MCP to automate incident response and investigation workflows. It provides specialized tools for alert triage, threat intelligence enrichment, and endpoint remediation across vendor-neutral APIs.
    Last updated
    45
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Orchestrates multiple AWS security services to provide comprehensive security assessments, threat analysis, and multi-framework compliance monitoring. It enables users to perform automated remediation recommendations and incident investigations through a unified Model Context Protocol interface.
    Last updated
    3
    1
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yslee96/security-remeidation-mcp-sever'

If you have feedback or need assistance with the MCP directory API, please join our Discord server