Security Infrastructure

Integrates with Splunk SIEM, CrowdStrike EDR, and Microsoft MISP to enable cross-platform threat hunting, security event searches,

jmstar85 22
Claude CodeClaude DesktopGeneric
View source ↗

This security infrastructure MCP server provides unified access to three major security platforms - Splunk SIEM, CrowdStrike EDR, and Microsoft MISP - through a comprehensive web interface and backend API integration. Built with Python async/await patterns and featuring both MCP server implementations and a React-based documentation frontend, it enables security analysts to perform cross-platform threat hunting, search security events, retrieve detections, and query threat intelligence through natural language interactions. The implementation includes Docker containerization, comprehensive test coverage, and a live documentation site with interactive code examples, making it valuable for SOC operations where analysts need to correlate data across multiple security tools without switching between different vendor interfaces.

Source

Repository: https://github.com/jmstar85/securityinfrastructure

Maintain Security Infrastructure?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[Security Infrastructure on getagentictools](https://getagentictools.com/mcp/jmstar85-securityinfrastructure?ref=badge)