Xsoar Mcp

general MCP Server

MCP server for Palo Alto Cortex XSOAR - 30 tools, webhook alerts, MCP Sampling, Docker native.

Verified
generalgeneraldocker
4 views0 stars1 forksMIT

Why This Matters

Discovered via github-topic:model-context-protocol and last synced 4mo ago.

Verified
Source
github-topic:model-context-protocol
Stars
0
Last synced
4mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
65
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (65)

update_incident

Update severity, owner, status, or custom fields

run_playbook_on_incident

Trigger a playbook on an incident

edit_indicator

Update score, comment, or expiration

list_integrations

Discover available integrations

acknowledge_alert

Acknowledge an alert (removes from queue)

1

**OpenAI**

10

**xAI (Grok)**

POST

Acknowledge an alert

close_incident

Close with resolution notes

get_incident_work_plan

View task-level status and dependencies

whitelist_indicators

Mark as safe / false positive

list_incident_types

List configured incident types

analyze_alert_with_ai

AI analysis via MCP Sampling → posts to War Room

AZURE_API_KEY

`gpt-4o`

COHERE_API_KEY

`command-r-plus`

Windows

`%APPDATA%\Claude\claude_desktop_config.json`

Variable

Required

reopen_incident

Reopen a closed incident

complete_task

Mark a playbook task as done

list_users

List XSOAR users and roles

Prompt

Args

3

**Claude (Anthropic)**

12

**Ollama** *(local)*

GET

All alerts (newest first)

create_incident

Create a new incident with type, severity, owner

list_playbooks

List all available playbooks

create_indicator

Create a new IOC with type and context

get_pending_alerts

Get unacknowledged webhook alerts

Provider

Env variable

PERPLEXITY_API_KEY

`llama-3.1-sonar-large-128k-online`

Platform

Path

XSOAR_API_KEY

add_war_room_entry

Add a Markdown note or investigation finding

add_task_note

Add a note to a specific task

search_evidence

Search evidence records

search_automations

Search available scripts/automations

triage_phishing

5

**Groq**

macOS

`~/Library/Application Support/Claude/claude_desktop_config.json`

Tool

Description

get_war_room_entries

Retrieve entries, notes, and command output

get_list_names

List all XSOAR lists (allow/block lists, lookup tables)

query_incident_statistics

Aggregate stats by type, severity, or owner

hunt_ioc

`ioc_value`

6

**Mistral AI**

Endpoint

Method

get_incident

Full incident details — fields, labels, attachments

get_indicator

Full IOC details — score, relationships, history

save_list

Create or update a list

URI

Returns

8

**DeepSeek**

XSOAR_URL

assign_task

Assign a task to an analyst

create_evidence

Add evidence to an incident

get_server_info

Verify connectivity + server version

investigate_incident

`incident_id`

GEMINI_API_KEY

`gemini-2.0-flash`

13

**LM Studio** *(local)*

search_incidents

Search with Lucene query, date range, severity filter

execute_integration_command

**Run any XSOAR command** (`!ip`, `!vt-file-scan`, etc.)

search_indicators

Search by IP, domain, hash, URL, CVE

get_list

Get a named list's contents

search_audit_logs

Query the audit trail

daily_soc_briefing

TOGETHER_API_KEY

`meta-llama/Llama-3-70b-chat-hf`