general MCP Server
MCP server for Palo Alto Cortex XSOAR - 30 tools, webhook alerts, MCP Sampling, Docker native.
Discovered via github-topic:model-context-protocol and last synced 4mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Update severity, owner, status, or custom fields
Trigger a playbook on an incident
Update score, comment, or expiration
Discover available integrations
Acknowledge an alert (removes from queue)
**OpenAI**
**xAI (Grok)**
Acknowledge an alert
Close with resolution notes
View task-level status and dependencies
Mark as safe / false positive
List configured incident types
AI analysis via MCP Sampling → posts to War Room
`gpt-4o`
`command-r-plus`
`%APPDATA%\Claude\claude_desktop_config.json`
Required
Reopen a closed incident
Mark a playbook task as done
List XSOAR users and roles
Args
**Claude (Anthropic)**
**Ollama** *(local)*
All alerts (newest first)
Create a new incident with type, severity, owner
List all available playbooks
Create a new IOC with type and context
Get unacknowledged webhook alerts
Env variable
`llama-3.1-sonar-large-128k-online`
Path
✅
Add a Markdown note or investigation finding
Add a note to a specific task
Search evidence records
Search available scripts/automations
—
**Groq**
`~/Library/Application Support/Claude/claude_desktop_config.json`
Description
Retrieve entries, notes, and command output
List all XSOAR lists (allow/block lists, lookup tables)
Aggregate stats by type, severity, or owner
`ioc_value`
**Mistral AI**
Method
Full incident details — fields, labels, attachments
Full IOC details — score, relationships, history
Create or update a list
Returns
**DeepSeek**
✅
Assign a task to an analyst
Add evidence to an incident
Verify connectivity + server version
`incident_id`
`gemini-2.0-flash`
**LM Studio** *(local)*
Search with Lucene query, date range, severity filter
**Run any XSOAR command** (`!ip`, `!vt-file-scan`, etc.)
Search by IP, domain, hash, URL, CVE
Get a named list's contents
Query the audit trail
—
`meta-llama/Llama-3-70b-chat-hf`
Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins and AI feature, and can be your openclaw alternative. ✨
ToolJet is the open-source foundation of ToolJet AI - the enterprise app generation platform for building internal tools, dashboard, business applications, workflows and AI agents 🚀
Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation.
Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation.
Learn how to use the Redis Manager Claude skill. Complete guide with installation instructions and examples.
Learn how to use the Privacy Search Claude skill. Complete guide with installation instructions and examples.
Learn how to use the Clawboard Claude skill. Complete guide with installation instructions and examples.