rapid7-mcp

security MCP Server

MCP server for Rapid7 InsightIDR — SIEM log search, investigations, alerts, UBA, and threat intelligence

VerifiedInstall Ready
securitysecurity
2 views2 stars0 forksv1.0.0MIT

Why This Matters

Discovered via github-topic:model-context-protocol and last synced 3mo ago.

VerifiedInstall Ready
Source
github-topic:model-context-protocol
Stars
2
Last synced
3mo ago
Install
Instructions detected

Install

1. Install the package

npx rapid7-mcp

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "rapid7-mcp": {
      "command": "npx",
      "args": [
        "rapid7-mcp"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

69
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (69)

search_assets

Search endpoints by hostname, IP, OS

list_remediation_projects

In-flight fix tracking — owner, due date, affected assets

get_investigation

Get full investigation details with timeline

get_loot

Credentials, hashes, and files extracted from compromised hosts

R7_VERIFY_SSL

`false`

MSP_VERIFY_SSL

`false`

get_site

Full details for a single site

list_vulnerabilities

Browse the vulnerability library, filter by severity

get_report

Configuration and status for a single report

Variable

Default

IDR_API_KEY

_(empty)_

Library

Why

Tool

Description

get_asset_vulnerabilities

All vulnerabilities found on a specific asset

get_remediation_project

Details for a single remediation project

query_logs

LEQL search across firewall, proxy, DNS, and endpoint logs

list_sites

List all scan sites — names, asset counts, risk scores, last scan time

get_asset_tags

Owner, environment, and compliance tags assigned to an asset

get_asset_group

Details for a single asset group

list_scans

Recent scans with status, duration, and vulnerability summaries

get_workspace

Details for a single workspace

list_asset_groups

Logical asset groupings (PCI scope, DMZ, dynamic OS groups)

get_vulnerability

Full vuln details — CVSS v2/v3, CVEs, exploit count, description

execute_report

Trigger on-demand report generation, returns download URI

list_workspaces

All Metasploit Pro workspaces (pentest projects)

get_scan

Details for a single scan

list_investigations

Open security incidents — priority, status, assignee, alert summary

list_sessions

Active Meterpreter and shell sessions — host, exploit, platform, username

R7_PASSWORD

`password`

MSP_TOKEN

_(empty)_

list_reports

All configured reports (executive summaries, PCI exports, CSV)

list_indicators

Active threat intelligence IOCs — IPs, domains, hashes, URLs

Fixture

Contents

IDR_REGION

`us`

DEMO_MODE

`false`

list_msp_tasks

Background tasks — scan imports, report generation, bruteforce jobs

R7_CONSOLE_URL

`https://localhost:3780`

R7_USERNAME

`admin`

MSP_URL

`https://localhost:3790`

create_investigation

Create new investigation

get_alert

Full alert details with evidence

list_threat_indicators

List IOCs in threat library

user-behavior-review

Analyze user activity for anomalies

search_investigations

List/filter investigations by status, priority, assignee

get_log_stats

Aggregate statistics for a time range

get_user_activity

User behavior analytics

investigate-alert

Guided alert investigation workflow

get_investigation_alerts

Get alerts linked to an investigation

list_saved_queries

List saved LEQL queries

add_investigation_comment

Add comment/note to investigation

get_alert_evidence

Get evidence/indicators from an alert

search_threat_activity

Search for IOC matches in logs

URI

Description

update_investigation

Update status, assignee, disposition

update_alert_status

Update alert status

add_threat_indicator

Add new IOC

incident-timeline

Build chronological incident timeline

list_log_sets

List available log sets

get_asset_activity

Recent activity for an asset

leql_help

LEQL syntax reference and examples

search_logs

Execute LEQL queries against log sets

get_asset

Full asset details with software/vulns

create_saved_query

Save a LEQL query for reuse

list_alerts

Get alerts with severity/type/status filters

get_risky_users

Users with abnormal behavior scores

hunt-ioc

Search for IOC across all log sources

get_log_entry

Get specific log entry by ID

search_users

Search user accounts

Prompt

Description