CrowdSentinel

AI-powered threat hunting and incident response framework for Elasticsearch and OpenSearch with detection rules, EVTX analysis, an

thomasxm 203 ↓ 21k
Claude CodeClaude DesktopGeneric
View source ↗

Connects language models to enterprise security data for natural language threat hunting, AI-guided investigation workflows, and cross-tool IoC correlation. Supports Elasticsearch, OpenSearch, EVTX logs via Chainsaw, and PCAP files via Wireshark with persistent investigation state and multiple security framework mappings including MITRE ATT&CK and Cyber Kill Chain.

Source

Repository: https://github.com/thomasxm/crowdsentinels-ai-mcp

Maintain CrowdSentinel?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

CrowdSentinel on getagentictools
[![CrowdSentinel on getagentictools](https://getagentictools.com/badge/mcp/thomasxm-crowdsentinels-ai-mcp.svg)](https://getagentictools.com/mcp/thomasxm-crowdsentinels-ai-mcp?ref=badge)