security MCP Server
MCP server for Rapid7 InsightIDR — SIEM log search, investigations, alerts, UBA, and threat intelligence
Discovered via github-topic:model-context-protocol and last synced 3mo ago.
1. Install the package
npx rapid7-mcp
2. Add to claude_desktop_config.json
{
"mcpServers": {
"rapid7-mcp": {
"command": "npx",
"args": [
"rapid7-mcp"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
Search endpoints by hostname, IP, OS
In-flight fix tracking — owner, due date, affected assets
Get full investigation details with timeline
Credentials, hashes, and files extracted from compromised hosts
`false`
`false`
Full details for a single site
Browse the vulnerability library, filter by severity
Configuration and status for a single report
Default
_(empty)_
Why
Description
All vulnerabilities found on a specific asset
Details for a single remediation project
LEQL search across firewall, proxy, DNS, and endpoint logs
List all scan sites — names, asset counts, risk scores, last scan time
Owner, environment, and compliance tags assigned to an asset
Details for a single asset group
Recent scans with status, duration, and vulnerability summaries
Details for a single workspace
Logical asset groupings (PCI scope, DMZ, dynamic OS groups)
Full vuln details — CVSS v2/v3, CVEs, exploit count, description
Trigger on-demand report generation, returns download URI
All Metasploit Pro workspaces (pentest projects)
Details for a single scan
Open security incidents — priority, status, assignee, alert summary
Active Meterpreter and shell sessions — host, exploit, platform, username
`password`
_(empty)_
All configured reports (executive summaries, PCI exports, CSV)
Active threat intelligence IOCs — IPs, domains, hashes, URLs
Contents
`us`
`false`
Background tasks — scan imports, report generation, bruteforce jobs
`https://localhost:3780`
`admin`
`https://localhost:3790`
Create new investigation
Full alert details with evidence
List IOCs in threat library
Analyze user activity for anomalies
List/filter investigations by status, priority, assignee
Aggregate statistics for a time range
User behavior analytics
Guided alert investigation workflow
Get alerts linked to an investigation
List saved LEQL queries
Add comment/note to investigation
Get evidence/indicators from an alert
Search for IOC matches in logs
Description
Update status, assignee, disposition
Update alert status
Add new IOC
Build chronological incident timeline
List available log sets
Recent activity for an asset
LEQL syntax reference and examples
Execute LEQL queries against log sets
Full asset details with software/vulns
Save a LEQL query for reuse
Get alerts with severity/type/status filters
Users with abnormal behavior scores
Search for IOC across all log sources
Get specific log entry by ID
Search user accounts
Description
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.