Skip to content

Threat detection and response

Endpoint, network, and SIEM platforms an agent can query for detections, and act on to contain them. 32 integrations, 645 tools.

Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.

19 tools. Connect with API key.

ToolDescriptionArguments
abnormal-security_get_abuse_campaignGet details of a specific abuse campaign including reported messages and threat analysisrequired campaign_id
abnormal-security_get_caseGet details of a specific account takeover case including severity, affected user, and timelinerequired case_id
abnormal-security_get_employeeGet employee information including display name, job title, VIP status, and threat historyrequired email_address
abnormal-security_get_employee_identityGet behavioral identity analysis (Genome data) for an employee from Abnormal’s AI enginerequired email_address
abnormal-security_get_threatGet full details of a specific threat including messages, attack type, sender info, and remediation statusrequired threat_id
abnormal-security_get_threat_action_statusCheck the status of an async threat remediation actionrequired threat_id, action_id
abnormal-security_get_vendor_detailsGet vendor risk details, domain information, and risk score for a specific vendor domainrequired vendor_domain
abnormal-security_list_abuse_campaignsList reported phishing and abuse campaigns from the AI Security Mailboxoptional filter_query, page_number, page_size
abnormal-security_list_audit_logsList portal audit logs with filtering by action type, category, and time range (max 90 days)optional action, category, filter_query, page_number, page_size
abnormal-security_list_casesList account takeover (ATO) cases with time range filtering. Requires Account Takeover license.optional filter_query, page_number, page_size
abnormal-security_list_detection_reportsList Detection 360 misclassification reports (missed attacks and false positives)optional filter_query, page_number, page_size
abnormal-security_list_threatsList detected email threats with filtering by time range, attack type, sender, recipient, and detection sourceoptional attack_strategy, attack_type, attack_vector, filter_query, page_number, page_size, recipient, sender, source, subject
abnormal-security_list_vendor_casesList vendor-related compromise cases detected by Abnormal Securityoptional filter_query, page_number, page_size
abnormal-security_list_vendorsList vendors monitored by Abnormal Security with time range filteringoptional filter_query, page_number, page_size
abnormal-security_manage_caseUpdate the status of an account takeover case (acknowledge, mark not actionable, etc.)required case_id, action
abnormal-security_remediate_messagesBulk remediate email messages found via search (delete or move to a target folder)required action, message_ids
optional remediation_reason, target_folder
abnormal-security_remediate_threatRemediate a threat (move messages to junk/quarantine) or unremediate (restore messages to inbox)required threat_id, action
abnormal-security_search_messagesSearch email messages by sender, recipient, subject, and time range across Abnormal and Quarantine sourcesoptional end_time, filter_operator, page_number, page_size, recipient_email, sender_email, sender_name, start_time, subject
abnormal-security_submit_detection_reportSubmit a Detection 360 misclassification report for a missed attack or false positiverequired inquiry_type, reported_message_id
optional description

16 tools. Available as 2 connections: Akamai Guardicore (Basic Auth) (Basic auth), Akamai Guardicore (Refresh Token) (API key).

ToolDescriptionArguments
akamai-guardicore_get_assetSearch for a single asset by ID, IP address, or hostname. Provide one of: asset_id (starts with ':vm'), ip_address, or name. Returns the first match from a fuzzy search.optional asset_id, ip_address, name
akamai-guardicore_get_asset_by_idGet full details of a specific asset by its unique UUID (e.g., ‘33d2f2e8-6221-4c87-bae1-52ca509ffe91’). Returns complete asset data including IPs, agent details, labels, orchestration info, and metadata.required asset_id
akamai-guardicore_get_connection_trendsGet aggregated network connection graph data grouped by label dimensions. Requires a saved map ID (use list_saved_maps to find one). Computes connection patterns between asset groups over a time range using the Reveal visibility graph.required saved_map_id, from_time, to_time
optional group_by
akamai-guardicore_get_incidentGet detailed information about a specific security incident by ID. Returns full incident data including affected assets, events, tags, recommendations, severity, and policy violations.required incident_id
akamai-guardicore_get_labelGet detailed information about a specific visibility label by its ID. Returns the label definition including key, value, criteria, and associated assets.required label_id
akamai-guardicore_get_label_groupGet detailed information about a specific label group by its ID.required group_id
akamai-guardicore_get_network_connectionsRetrieve network connection data for visibility into traffic between assets. Filter by time range, source, and destination IP. Shows process-level communication details.required from_time, to_time
optional destination, limit, offset, source
akamai-guardicore_list_agentsList installed Akamai Guardicore agents across the environment. Returns agent details including status, version, hostname, and associated asset information.optional agent_type, limit, offset, search
akamai-guardicore_list_assetsSearch and list assets (endpoints/VMs) in the Akamai Guardicore environment. Filter by IP address, hostname, or search string. Returns asset details including IPs, status, labels, and metadata.optional limit, offset, search
akamai-guardicore_list_incidentsList security incidents within a time range. Filter by severity (Low/Medium/High), incident type, source, destination, or tag. Returns incident summaries with affected assets, timing, and severity.required from_time, to_time
optional destination, incident_type, limit, offset, severity, source, tag
akamai-guardicore_list_label_groupsList all label groups used for organizing labels into higher-level groupings. Label groups define segmentation boundaries and policy scopes.optional limit, offset
akamai-guardicore_list_labelsList all visibility labels used for organizing assets into logical groupings such as geographical areas, business units, applications, and roles.optional limit, offset
akamai-guardicore_list_policy_rulesList segmentation policy rules in the Akamai Guardicore environment. Filter by asset ID to see rules affecting a specific asset. Returns rule definitions including source/destination criteria, actions, and associated labels.optional asset_id, limit, offset, search
akamai-guardicore_list_projectsList segmentation projects in the Akamai Guardicore environment. Projects organize segmentation policies and rules into logical groupings.optional limit, offset
akamai-guardicore_list_saved_mapsList saved network visibility maps from the Reveal section. Excludes futile and incident-type maps. Returns map definitions including name, filters, time ranges, and layout configurations.optional limit, offset
akamai-guardicore_manage_labelAdd a label to assets or delete an existing label. Use action=‘add’ with asset_ids to assign a label to specific assets, or action=‘delete’ to permanently remove a label definition (affecting all assets).required action, label_key, label_value
optional asset_ids

53 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
aws-guardduty_accept_administrator_invitationAccept a GuardDuty administrator invitation from a member account. Requires the detector ID, administrator account ID, and invitation ID.required detector_id, administrator_id, invitation_id
aws-guardduty_archive_findingsArchive AWS GuardDuty findings to suppress them from the active findings list. Archived findings are retained and can be retrieved with archived=true filter, but are hidden from the default view.required detector_id, finding_ids
aws-guardduty_create_filterCreate a new finding filter for a GuardDuty detector. Filters can auto-archive findings matching specific criteria (e.g., low severity, specific finding types, or certain resource types).required detector_id, name, finding_criteria
optional action, description, rank
aws-guardduty_create_membersAdd AWS accounts as GuardDuty member accounts. Provide account IDs and emails. After creating members, you must invite them and they must accept.required detector_id, account_details
aws-guardduty_create_sample_findingsGenerate sample AWS GuardDuty findings for testing and validation purposes. Sample findings simulate real GuardDuty findings and can be used to test alerting pipelines, verify integrations, and explore finding formats.required detector_id
optional finding_types
aws-guardduty_decline_invitationsDecline GuardDuty membership invitations from administrator accounts. Provide the account IDs of the administrators whose invitations to decline.required account_ids
aws-guardduty_delete_detectorDelete a GuardDuty detector. WARNING: This stops ALL GuardDuty monitoring in this region and deletes all findings. This action is irreversible.required detector_id
aws-guardduty_delete_filterDelete a GuardDuty finding filter by name. Findings previously suppressed by this filter will no longer be auto-archived.required detector_id, filter_name
aws-guardduty_delete_invitationsDelete GuardDuty membership invitations. Removes the invitation records for the specified administrator accounts.required account_ids
aws-guardduty_delete_ip_setDelete a GuardDuty IP set. The trusted IP list will no longer suppress findings for those IPs.required detector_id, ip_set_id
aws-guardduty_delete_malware_protection_planDelete a GuardDuty malware protection plan. S3 objects will no longer be scanned for malware under this plan.required malware_protection_plan_id
aws-guardduty_delete_membersRemove AWS accounts from GuardDuty membership. The accounts will no longer be monitored by the administrator.required detector_id, account_ids
aws-guardduty_delete_publishing_destinationDelete a GuardDuty publishing destination. Findings will no longer be exported to this destination.required detector_id, destination_id
aws-guardduty_delete_threat_intel_setDelete a GuardDuty threat intelligence set. The threat intel data will no longer be used for detection.required detector_id, threat_intel_set_id
aws-guardduty_describe_malware_scansDescribe GuardDuty malware scan results with optional filtering. Returns scan details including status, resource scanned, threats found, scan start/end times, and trigger type. Useful for malware incident response.required detector_id
optional filter_criteria, max_results, next_token, sort_criteria
aws-guardduty_describe_publishing_destinationGet details for a specific GuardDuty publishing destination, including its type (S3), status, destination ARN, KMS key ARN, and publishing failure information if applicable.required detector_id, destination_id
aws-guardduty_disassociate_membersDisassociate member accounts from the GuardDuty administrator. The member accounts remain but are no longer actively monitored.required detector_id, account_ids
aws-guardduty_get_administrator_accountGet the GuardDuty administrator account for a member detector. In multi-account setups, returns the administrator account ID, invitation ID, and relationship status.required detector_id
aws-guardduty_get_coverage_statisticsGet aggregated GuardDuty coverage statistics showing resource counts by coverage status and resource type. Provides a quick overview of monitoring coverage without listing individual resources.required detector_id, statistics_type
optional filter_criteria
aws-guardduty_get_detectorGet configuration details for a specific AWS GuardDuty detector, including its status (ENABLED/DISABLED), data sources configuration (CloudTrail, DNS logs, VPC Flow Logs, S3, EKS, Malware Protection), finding publishing frequency, and…required detector_id
aws-guardduty_get_filterGet details for a specific GuardDuty finding filter, including its name, action (NOOP or ARCHIVE), description, rank, and finding criteria. Filters define rules for auto-archiving or suppressing findings.required detector_id, filter_name
aws-guardduty_get_findingsRetrieve comprehensive details for specific AWS GuardDuty findings by ID.required detector_id, finding_ids
aws-guardduty_get_findings_statisticsGet aggregated statistics about AWS GuardDuty findings, counting findings by severity level (LOW, MEDIUM, HIGH, CRITICAL). Useful for dashboards and getting a quick overview of the security posture without fetching all findings.required detector_id
optional finding_criteria
aws-guardduty_get_invitations_countGet the count of pending GuardDuty membership invitations for the current account.—
aws-guardduty_get_ip_setGet details for a specific AWS GuardDuty IP set, including its name, format (TXT, STIX, etc.), S3 location, and activation status. IP sets contain trusted IP addresses that suppress findings.required detector_id, ip_set_id
aws-guardduty_get_malware_protection_planGet details for a specific GuardDuty malware protection plan, including protected resource configuration, actions on malware detection, and plan status.required malware_protection_plan_id
aws-guardduty_get_malware_scanGet details for a specific GuardDuty malware scan by scan ID, including status, resource scanned, timing, and scan results.required scan_id
aws-guardduty_get_malware_scan_settingsGet the malware scan settings for a GuardDuty detector, including EBS snapshot preservation settings and scan resource inclusion/exclusion tags. Shows how malware protection is configured for the detector.required detector_id
aws-guardduty_get_membersGet details for specific GuardDuty member accounts by AWS account ID. Returns member account information including email, relationship status, invitation timestamp, and detector ID.required detector_id, account_ids
aws-guardduty_get_remaining_free_trial_daysGet the remaining free trial days for GuardDuty data sources. Shows how many free trial days remain for each feature/data source per account. Useful for cost planning.required detector_id, account_ids
aws-guardduty_get_threat_intel_setGet details for a specific AWS GuardDuty threat intelligence set, including its name, format, location (S3 URL), and activation status. Threat intel sets contain known malicious IP addresses used for detection.required detector_id, threat_intel_set_id
aws-guardduty_get_usage_statisticsGet GuardDuty usage statistics for cost monitoring and capacity planning. Returns usage data grouped by account, data source, resource, or features. Useful for understanding GuardDuty costs and data volumes.required detector_id, usage_statistic_type
optional max_results, next_token, usage_criteria
aws-guardduty_invite_membersSend GuardDuty membership invitations to AWS accounts. The accounts must first be added with create_members. Optionally include a custom message and disable email notifications.required detector_id, account_ids
optional disable_email_notification, message
aws-guardduty_list_coverageList GuardDuty coverage details showing which resources are being monitored and their coverage status. Helps identify gaps in monitoring across EC2, ECS, EKS clusters, and other AWS resources.required detector_id
optional filter_criteria, max_results, next_token, sort_criteria
aws-guardduty_list_detectorsList all AWS GuardDuty detector IDs in the configured region. A detector is the GuardDuty service instance that monitors your AWS environment. Most accounts have one detector per region.optional max_results, next_token
aws-guardduty_list_filtersList all finding filter names for a GuardDuty detector. Filters auto-archive or suppress findings matching specific criteria. Returns filter names to use with get_filter for details.required detector_id
optional max_results, next_token
aws-guardduty_list_findingsList AWS GuardDuty finding IDs with optional filters by severity, finding type, resource type, and archived status. Returns paginated finding IDs — pass them to get_findings to retrieve full details.required detector_id
optional archived, finding_type, max_results, next_token, resource_type, severity_min, sort_by, sort_order
aws-guardduty_list_invitationsList all GuardDuty membership invitations sent to the current account. Returns invitation details including sender account, status, and timestamp.optional max_results, next_token
aws-guardduty_list_ip_setsList all IP set IDs associated with a GuardDuty detector. IP sets are lists of trusted or known malicious IP addresses used by GuardDuty for detection. Returns IDs to use with get_ip_set for details.required detector_id
optional max_results, next_token
aws-guardduty_list_malware_protection_plansList all GuardDuty malware protection plans. Malware protection plans define which S3 buckets are scanned for malware when new objects are uploaded.optional next_token
aws-guardduty_list_malware_scansList GuardDuty malware scans across the account with optional filtering and sorting. This API is account-scoped and does not take detector_id.optional filter_criteria, max_results, next_token, sort_criteria
aws-guardduty_list_membersList member accounts associated with a GuardDuty administrator detector. In multi-account setups, this shows all member accounts being monitored. Returns account details including relationship status.required detector_id
optional max_results, next_token, only_associated
aws-guardduty_list_publishing_destinationsList publishing destinations configured for a GuardDuty detector. Publishing destinations are S3 buckets where GuardDuty exports findings. Returns destination IDs, types, and status.required detector_id
optional max_results, next_token
aws-guardduty_list_tags_for_resourceList tags associated with a GuardDuty resource (detector, filter, IP set, threat intel set). Provide the resource ARN. Returns key-value tag pairs.required resource_arn
aws-guardduty_list_threat_intel_setsList all threat intelligence set IDs associated with a GuardDuty detector. Threat intel sets are custom lists of known malicious IP addresses that GuardDuty uses to generate findings. Returns IDs to use with get_threat_intel_set.required detector_id
optional max_results, next_token
aws-guardduty_start_monitoring_membersRe-enable GuardDuty monitoring for member accounts that were previously stopped. Findings will resume being generated.required detector_id, account_ids
aws-guardduty_stop_monitoring_membersStop GuardDuty monitoring for specific member accounts. Findings will no longer be generated for these accounts.required detector_id, account_ids
aws-guardduty_tag_resourceAdd tags to a GuardDuty resource. Tags are key-value pairs used for resource organization, cost allocation, and access control. Provide the resource ARN and a dict of tag key-value pairs.required resource_arn, tags
aws-guardduty_unarchive_findingsUnarchive previously archived AWS GuardDuty findings, restoring them to the active findings list. Use when a finding was incorrectly archived or requires further investigation.required detector_id, finding_ids
aws-guardduty_untag_resourceRemove tags from a GuardDuty resource by tag key. Provide the resource ARN and a list of tag keys to remove.required resource_arn, tag_keys
aws-guardduty_update_detectorUpdate a GuardDuty detector’s configuration. Can enable/disable the detector or change finding publishing frequency. Disabling a detector stops GuardDuty monitoring in that region.required detector_id
optional enable, finding_publishing_frequency
aws-guardduty_update_filterUpdate an existing GuardDuty finding filter. You can change the action, description, rank, or finding criteria. Use this to adjust suppression rules as your security posture evolves.required detector_id, filter_name
optional action, description, finding_criteria, rank
aws-guardduty_update_findings_feedbackSubmit feedback on AWS GuardDuty findings to indicate whether they are USEFUL (true positives) or NOT_USEFUL (false positives). This feedback helps AWS improve GuardDuty’s machine learning models.required detector_id, finding_ids, feedback
optional comments

10 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
aws-security_analyze_iam_access—optional cursor, include_inherited, limit, principal, resource
aws-security_apply_remediation—required resource, action
optional apply_immediately, certificate_arn, confirm, dry_run, enabled, port, rotation_lambda_arn, security_group_ids
aws-security_aws_api_request—required service, action
optional account, confirm, dry_run, max_items, parameters, query, region
aws-security_delete_resource—required resource
optional confirm, dry_run, final_snapshot_id, force_empty_bucket, recovery_window_days, skip_final_snapshot, url_config_only
aws-security_find_public_exposure—optional accounts, cursor, limit, regions, severity
aws-security_get_resource—required resource_id
optional include
aws-security_list_accounts——
aws-security_list_resources—optional accounts, cursor, limit, public_only, regions, services
aws-security_modify_network_access—required resource, action
optional cidr, confirm, dry_run, ports, protocol
aws-security_set_policy—required resource, action
optional confirm, dry_run, policy, policy_arn, policy_name, statement_id

13 tools. Connect with Basic auth.

ToolDescriptionArguments
cisco-secure-network-analytics_create_host_groupCreate a new host group (tag) in Cisco SNA. Host groups organize IP address ranges for traffic analysis and alarm scoping.required name, parent_id, ranges
optional description, location, tenant_id
cisco-secure-network-analytics_get_alarm_associated_flowsRetrieve the constituent network flows that triggered a multi-peer SNA alarm. Available on SNA 7.5.3 and later. Returns 404 with a version hint on older Managers.required alarm_id
optional max_records, tenant_id
cisco-secure-network-analytics_get_flow_query_resultsFetch the results of a completed SNA flow query job. Use after search_flows returns TIMEOUT, or to re-fetch results for a job that previously completed. The job must be in COMPLETED state.required job_id
optional tenant_id
cisco-secure-network-analytics_get_flow_query_statusReturn the current status of an async SNA flow query job. Possible statuses: QUEUED, IN_PROGRESS, COMPLETED, FAILED. Use after search_flows returns a TIMEOUT response.required job_id
optional tenant_id
cisco-secure-network-analytics_list_flow_exportersList NetFlow/IPFIX exporters feeding this SNA Manager, including health status, exporter IP, and last-seen timestamp. Use this to answer ‘is this network device sending flow data?’ or to diagnose gaps in flow coverage.optional tenant_id
cisco-secure-network-analytics_list_host_groupsList host groups (called ‘tags’ in the SNA REST API, ‘host groups’ in the UI) for a given scope.optional scope, shape, tenant_id
cisco-secure-network-analytics_list_security_event_typesList all security event type templates available on this SNA Manager.optional tenant_id
cisco-secure-network-analytics_list_tenantsList all tenants (also called domains) visible to the authenticated user on this Cisco Secure Network Analytics Manager. Most enterprise deployments have a single tenant.optional tenant_id
cisco-secure-network-analytics_render_security_event_detailsSubstitute event-specific field values (baseline, tolerance, threshold, etc.) into a security event type template to produce a human-readable description of why the event fired.required template_id, fields
optional tenant_id
cisco-secure-network-analytics_search_flowsSearch network flows on Cisco SNA using an async query job. Starts a flow query, polls for completion (up to 90 s), and returns results.required start_time, end_time
optional application_id, host_group_id, record_limit, source_ip, target_ip, tenant_id
cisco-secure-network-analytics_search_security_eventsSearch Cisco SNA security events (alarms) using an async query job. Starts the job, polls for completion (up to 90 s), and returns results.required start_time, end_time
optional alarm_category_id, host_ips, security_event_type_ids, tenant_id
cisco-secure-network-analytics_top_traffic_reportGenerate a top-N traffic report for a Cisco SNA tenant. Aggregates traffic across the specified dimension and returns the top results.required dimension, start_time, end_time
optional host_group_id, limit, tenant_id
cisco-secure-network-analytics_update_host_groupUpdate an existing host group (tag) in Cisco SNA. SNA’s PUT is a full replace — this tool fetches the current host group, merges your changes, and PUTs back, so you only need to specify what you want to change.required host_group_id
optional description, name, ranges, ranges_action, tenant_id

17 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
cofense-triage_add_report_commentAdd an analyst comment to a report. Comments create an auditable trail of investigation activities, findings, and decisions. Requires Triage Operator role or higher.required reportId, body
optional bodyFormat, tags
cofense-triage_categorize_reportCategorize or re-categorize a phishing report. This is a critical operation that classifies the report and may trigger automated workflows (notifications, integrations, metrics). Requires Triage Operator role or higher.required reportId, categoryId
optional categorizationTags, outboundTemplateId
cofense-triage_download_attachmentDownload a specific attachment file from a report. Returns base64-encoded binary data with filename and content type. Use with caution - attachments may contain malware. Consider downloading in a sandboxed environment.required attachmentId
cofense-triage_download_attachment_payloadDownload the raw payload content (binary data as base64). This represents the actual file content shared across potentially multiple attachments with the same hash.required payloadId
cofense-triage_download_report_originalDownload the original email in RFC822 (.eml) format. Returns the complete email source including all headers, body, and MIME parts as base64-encoded data. Useful for forensic analysis or forwarding to external tools.required reportId
cofense-triage_download_report_previewDownload a rendered preview image of the email (PNG or JPG format). Returns base64-encoded image data. Useful for quick visual triage without opening the original email.required reportId
optional format
cofense-triage_get_attachment_payloadGet payload metadata including file hashes (MD5, SHA256), MIME type, and risk score. Useful for threat intelligence lookups without downloading the actual file.required payloadId
cofense-triage_get_categoryGet detailed information about a specific category by its ID, including name, description, color, score, and malicious flag.required categoryId
cofense-triage_get_reportGet detailed information about a specific phishing report by its ID. Returns the full report resource including all attributes and relationship identifiers.required reportId
cofense-triage_get_report_with_contextGet a comprehensive view of a report including all related context: URLs, domains, hostnames, email headers, attachments, payloads, comments, rules, threat indicators, cluster information, and categorization.required reportId
optional includeRelations
cofense-triage_list_categoriesList all available report categories in Triage. Categories classify reports as malicious (phishing, malware, spam) or benign (legitimate, training). Used to discover valid category IDs before categorizing reports.optional malicious, nameContains, page, pageSize
cofense-triage_list_headers_for_reportList all RFC-822 email headers from a report (e.g., From, To, Subject, Received, Message-ID, X-headers). Returns key-value pairs useful for analyzing email routing, authentication (SPF/DKIM/DMARC), and identifying spoofing attempts.required reportId
cofense-triage_list_integration_results_for_reportAggregate all third-party security tool verdicts for URLs and files in a report. Returns integration submission results from tools like VirusTotal, sandboxes, URL reputation services, etc.required reportId
optional targetKinds
cofense-triage_list_iocs_for_reportList all indicators of compromise (IOCs) extracted from a report. Returns URLs, domains, hostnames, and threat indicators in a consolidated response.required reportId
cofense-triage_list_report_attachmentsList all attachments from a report. Returns metadata including filename, size, content type, and linkage to attachment payload (hash information). Essential for identifying suspicious files.required reportId
cofense-triage_list_report_commentsList all comments on a report. Comments contain analyst notes, investigation findings, and collaboration discussion. Supports pagination.required reportId
optional page, pageSize
cofense-triage_list_reportsList and filter phishing reports from Cofense Triage. Supports pagination (max 200 per page), filtering by subject, sender, tags, date range, category, and priority.optional categoryId, fromAddress, matchPriority, page, pageSize, receivedAfter, receivedBefore, sort, subjectContains, tagsAny

81 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
crowdstrike-falcon_aggregate_alertsGet aggregate counts and analytics of alerts across all CrowdStrike Falconsecurity products. Provides powerful analytics for threat intelligence, trend analysis, and security metrics.required field
optional aggregation_type, date_ranges, filter_query, include_hidden, interval, name, size, sort
crowdstrike-falcon_block_identity_authenticationBlock authentication for one or more CrowdStrike Falcon Identity Protection identities by creating a real-time enforcement policy rule (action BLOCK) scoped to those source users. Enforced at the domain controller by the Falcon sensor.required rule_name, source_user_entity_ids
optional simulation_mode, trigger
crowdstrike-falcon_create_identity_protection_policy_ruleCreate a CrowdStrike Falcon Identity Protection policy rule. Defines a conditional access / risk response for identity activity.required name, action, trigger
optional activity, destination, enabled, simulation_mode, source_endpoint, source_user
crowdstrike-falcon_create_ioa_ruleCreate a new Custom IOA rule inside an existing rule group in CrowdStrike Falcon.required rulegroup_id, ruletype_id, name, pattern_severity, disposition_id, field_values
optional comment, description
crowdstrike-falcon_create_ioa_rule_groupCreate a new Custom IOA rule group in CrowdStrike Falcon. A rule group is a per-platform container that holds individual IOA rules. Create the group first, then add rules to it with create_ioa_rule.required name, platform
optional comment, description
crowdstrike-falcon_create_iocCreate a custom Indicator of Compromise (IOC) in CrowdStrike Falcon. Supports IP addresses, domains, and file hashes with configurable detection/prevention actions.required ioc_type, value, action, platforms
optional applied_globally, description, expiration, host_groups, severity, source, tags
crowdstrike-falcon_delete_identity_protection_policy_rulesDelete one or more CrowdStrike Falcon Identity Protection policy rules by ID. This permanently removes the rules. Get rule IDs from list_identity_protection_policy_rules first. WARNING: This action is irreversible.required ids
crowdstrike-falcon_delete_iocDelete one or more custom IOCs from CrowdStrike Falcon by their IDs. This permanently removes the indicators. Get IOC IDs from list_iocs first. WARNING: This action is irreversible.required ids
crowdstrike-falcon_disable_identity_accountDisable an on-prem Active Directory account for a CrowdStrike Falcon Identity Protection entity, enforced through the Falcon sensor on the domain controller (no separate AD connector required).required entity_id
crowdstrike-falcon_find_shadow_adminsList CrowdStrike Falcon Identity Protection entities that are members of the built-in Active Directory Administrator role (BuiltinAdministratorRole). Does NOT enumerate custom, delegated, or nested-group admin roles.optional after, limit
crowdstrike-falcon_find_stale_accountsReturn Active-Directory-backed CrowdStrike Falcon Identity Protection USER entities with account/password age metadata (enabled state, last-update time, password last-change) so stale or dormant accounts can be identified.optional after, limit
crowdstrike-falcon_force_identity_password_resetForce a password reset for a CrowdStrike Falcon Identity Protection entity’s on-prem AD account, enforced via the Falcon sensor on the domain controller.required entity_id
crowdstrike-falcon_get_alert_detailsGet comprehensive details for specific alerts across all CrowdStrike Falconsecurity products. Returns full context including process trees, MITRE ATT&CK mappings, IOCs, device information, and threat intelligence.required ids
optional include_hidden
crowdstrike-falcon_get_alerts_combinedRetrieve all Alerts that match a particular FQL filter in a single API call using cursor-based pagination. Returns alerts and an ‘after’ token for the next page when more results are available.optional after, filter_query, limit, sort
crowdstrike-falcon_get_analysis_reportRetrieve CrowdStrike Falcon Sandbox analysis reports by ID. Returns verdict, extracted IOCs, behavioral indicators, MITRE ATT&CK mappings, and process activity. Requires the falconx-sandbox:read API scope.required ids
optional summary
crowdstrike-falcon_get_cloud_security_policy_detailsGet detailed information for specific Cloud Security (CSPM) policy IDs, including the policy statement, remediation guidance, and current severity/enabled configuration. Get policy IDs from list_cloud_security_policies first.required ids
crowdstrike-falcon_get_content_update_policy_detailsGet detailed configuration for specific content update policy IDs, including the ring assignment settings (ring and delay hours) per content category. Get policy IDs from list_content_update_policies first.required ids
crowdstrike-falcon_get_device_control_policy_detailsGet detailed configuration for specific device control policy IDs, including the per-device-class enforcement actions and exceptions. Get policy IDs from list_device_control_policies first.required ids
crowdstrike-falcon_get_device_detailsGet detailed information for specific device IDs including hardware, OS, network, and policy informationrequired ids
crowdstrike-falcon_get_device_login_historyGet recent login history for devices including user sessions and authentication detailsrequired ids
crowdstrike-falcon_get_device_network_historyGet network address history for devices including IP and MAC address changesrequired ids
crowdstrike-falcon_get_device_online_stateGet the current online status for specific devices (online, offline, unknown)required ids
crowdstrike-falcon_get_environment_scoreGet an environment-wide security risk score and summary (supersedes CrowdScore) computed from alert aggregations.optional filter_query
crowdstrike-falcon_get_identity_auth_historyRetrieve account details for a specific CrowdStrike Falcon Identity Protection identity, resolved by email or entity ID.optional email, entity_id, limit
crowdstrike-falcon_get_identity_protection_policy_rule_detailsGet detailed configuration for specific Identity Protection policy rule IDs, including the trigger, action, simulation mode, and source/destination/activity matching criteria. Get rule IDs from list_identity_protection_policy_rules first.required ids
crowdstrike-falcon_get_identity_risk_scoresReturn CrowdStrike Falcon Identity Protection USER entities ranked by identity risk score (highest first), with risk factors. Requires Identity Protection Entities READ and GraphQL WRITE scopes.optional after, limit, min_severity
crowdstrike-falcon_get_ioa_rule_detailsGet full details of one or more Custom IOA rules in CrowdStrike Falcon by their IDs, including field values, disposition, pattern severity, and version. Get rule IDs from list_ioa_rules first.required ids
crowdstrike-falcon_get_ioa_rule_group_detailsGet full details of one or more Custom IOA rule groups in CrowdStrike Falcon by their IDs, including the rules contained in each group and the group’s version (needed for subsequent updates).required ids
crowdstrike-falcon_get_ioa_rule_type_detailsGet the full field definitions for one or more Custom IOA rule types in CrowdStrike Falcon.required ids
crowdstrike-falcon_get_it_automation_policy_detailsGet detailed configuration for specific IT Automation policy IDs, including execution toggles (script/Python/OS Query), timeouts, and CPU / memory / concurrency resource limits. Get policy IDs from list_it_automation_policies first.required ids
crowdstrike-falcon_get_policy_host_countsGet the applied, pending, and total assigned host counts for a single CrowdStrike Falcon policy.required policy_type, policy_id
crowdstrike-falcon_get_prevention_policy_detailsGet detailed information for specific prevention policy IDs. Retrieves comprehensive prevention policy details including settings, configurations, platform information, and policy metadata.required ids
crowdstrike-falcon_get_response_policy_detailsGet detailed configuration for specific Real Time Response policy IDs, including the per-capability settings (e.g. RealTimeResponse, RealTimeResponseAdmin, custom scripts, file uploads). Get policy IDs from list_response_policies first.required ids
crowdstrike-falcon_get_sensor_policy_detailsGet full configuration details for specific sensor update policy IDs. Returns the complete settings block including sensor build version, channel/variant assignments, uninstall protection, and the update scheduler.required ids
crowdstrike-falcon_get_submission_statusCheck the status of one or more CrowdStrike Falcon Sandbox submissions. Analysis typically completes within 15 minutes. Requires the falconx-sandbox:read API scope.required ids
crowdstrike-falcon_get_zero_trust_assessmentGet CrowdStrike Falcon Zero Trust Assessment (ZTA) posture data for one or more hosts by agent ID (AID). Returns the 1-100 security posture score the Falcon sensor computes from sensor and OS configuration.required ids
crowdstrike-falcon_kill_identity_sessionsTerminate active authentication sessions for a CrowdStrike Falcon Identity Protection entity, enforced via the Falcon sensor.required entity_id
crowdstrike-falcon_list_alertsQuery CrowdStrike Falcon alerts across all security products using FQL filters.optional filter_query, include_hidden, limit, offset, q, sort
crowdstrike-falcon_list_cloud_ml_policiesList CrowdStrike Falcon prevention policies along with their Cloud ML and Sensor ML machine-learning settings.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_cloud_security_policiesList CrowdStrike Falcon Cloud Security (CSPM / Falcon Horizon) policy settings.optional cloud_platform, service
crowdstrike-falcon_list_content_update_policiesList CrowdStrike Falcon content update policies using FQL filters.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_device_control_policiesList CrowdStrike Falcon device control (USB) policies using FQL filters. Device control policies govern how USB mass-storage and other peripheral device classes are allowed, blocked, or made read-only on endpoints.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_falcon_container_policiesList all CrowdStrike Falcon Container image assessment policies.—
crowdstrike-falcon_list_identity_protection_policy_rulesList CrowdStrike Falcon Identity Protection policy rules.optional enabled, name, simulation_mode
crowdstrike-falcon_list_ioa_platformsList the platforms available for Custom IOA (Indicator of Attack) rule groups in CrowdStrike Falcon (e.g. ‘windows’, ‘mac’, ‘linux’).optional limit, offset
crowdstrike-falcon_list_ioa_rule_groupsSearch and list Custom IOA rule groups in CrowdStrike Falcon with optional FQL filtering. Returns full group details including name, platform, enabled state, and the rules contained in each group.optional filter_query, limit, offset, q, sort
crowdstrike-falcon_list_ioa_rule_typesList the Custom IOA rule type IDs available in CrowdStrike Falcon (e.g. process creation, network connection, file creation, registry operation, domain name). Call this when building a Custom IOA rule to discover which rule types exist.optional limit, offset
crowdstrike-falcon_list_ioa_rulesSearch and list Custom IOA rules in CrowdStrike Falcon with optional FQL filtering. Returns full rule details including name, rule type, pattern severity, disposition, field values, and enabled state.optional filter_query, limit, offset, q, sort
crowdstrike-falcon_list_iocsSearch and list custom IOCs (Indicators of Compromise) in CrowdStrike FalconFalcon with FQL filtering. Returns full indicator details including type, value, action, severity, and metadata.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_it_automation_policiesList CrowdStrike Falcon IT Automation policies. IT Automation policies govern how automation tasks run on hosts — script/Python/OS Query execution toggles, execution timeouts, and CPU / memory / concurrency resource limits.optional limit, offset, platform, sort
crowdstrike-falcon_list_policy_membersList the hosts (full device records) governed by a single CrowdStrike Falcon policy, i.e. the policy’s members. Supports prevention, sensor_update, device_control, firewall, response, and content_update policies.required policy_type, policy_id
optional filter_query, limit, offset, sort
crowdstrike-falcon_list_prevention_policiesList CrowdStrike Falcon prevention policies using FQL filters. Prevention policies define security settings for endpoints, including malware protection, behavioral analysis, and threat prevention configurations.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_response_policiesList CrowdStrike Falcon Real Time Response (RTR) policies using FQL filters.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_sensor_policiesList CrowdStrike Falcon sensor update policies using FQL filters. Sensor update policies control how and when CrowdStrike Falcon sensors are updated on endpoints, including version management and update scheduling.optional filter_query, limit, offset, sort
crowdstrike-falcon_list_submissionsSearch and list CrowdStrike Falcon Sandbox submissions with FQL filtering. Returns submission status records (state, created_timestamp, sha256, verdict, environment).optional filter_query, limit, offset, sort
crowdstrike-falcon_perform_host_actionTake various actions on the hosts in your environment. Contain or lift containment on a host. Hide or unhide a host. Suppress or unsuppress detections.required action, ids
crowdstrike-falcon_rtr_delete_sessionDelete (close) a CrowdStrike Falcon RTR session by its session ID (requires real-time-response READ scope). Always close sessions when remediation is complete to free the host’s RTR slot.required session_id
crowdstrike-falcon_rtr_execute_admin_commandExecute a state-changing (active-responder/admin) RTR command on a host within an active session (requires Real Time Response Admin WRITE scope). Use for remediation that modifies the host.required session_id, base_command, command_string
crowdstrike-falcon_rtr_execute_commandExecute a read-only RTR command on a host within an active session (requires real-time-response READ scope). Use for investigation/forensics — these commands do not change host state.required session_id, base_command, command_string
crowdstrike-falcon_rtr_get_command_statusPoll the status and output of a previously-issued RTR command using its cloud_request_id (requires real-time-response READ scope). RTR commands are asynchronous, so this is how you retrieve results.required cloud_request_id
optional admin, sequence_id
crowdstrike-falcon_rtr_get_fileRetrieve a file from a host into the CrowdStrike cloud using the RTR ‘get’ command (requires Real Time Response Admin WRITE scope). Used to collect forensic artifacts (logs, malware samples) from a compromised host.required session_id, file_path
crowdstrike-falcon_rtr_init_sessionInitialize a CrowdStrike Falcon Real Time Response (RTR) session against a single managed host (requires real-time-response READ scope). An active session is required before any RTR command can run.required device_id
optional queue_offline
crowdstrike-falcon_rtr_list_put_filesList the put-file IDs registered in the CrowdStrike cloud that are available to deploy with rtr_put_file (the put_file_name argument). Use this to discover valid put-files before deploying one.optional filter_query, limit, offset, sort
crowdstrike-falcon_rtr_list_scriptsList the custom-script IDs available to run with rtr_run_script (the cloud_file argument). Use this to discover valid pre-approved scripts before executing one. Requires the ‘Real time response (admin): WRITE’ scope.optional filter_query, limit, offset, sort
crowdstrike-falcon_rtr_put_fileUpload a file (remediation tool, updated config, cleanup script) onto the remote endpoint via CrowdStrike cloud staging.required session_id
optional comment, description, file_path, put_file_name
crowdstrike-falcon_rtr_run_scriptRun a script on a host via the RTR ‘runscript’ admin command (requires Real Time Response Admin WRITE scope). Provide exactly one of an inline script (raw_script) or the name of a previously-uploaded custom/cloud script (cloud_file).required session_id
optional cloud_file, raw_script
crowdstrike-falcon_search_devicesSearch for devices with full details returned (combines query and details in one call)optional filter_query, limit, offset, sort
crowdstrike-falcon_search_ngsiemExecute a CrowdStrike Query Language (CQL) query against CrowdStrike Next-Gen SIEM (NG-SIEM) advanced event search and return the matching event records.required query_string
optional end, limit, repository, start, timeout_seconds, timezone
crowdstrike-falcon_submit_sampleSubmit a sample for sandbox analysis (sha256, url, or signed source_url).optional action_script, command_line, comment, document_password, environment_id, file_name, network_settings, sha256, source_url, submit_name, url
crowdstrike-falcon_trigger_identity_mfaRequire multi-factor authentication for one or more CrowdStrike Falcon Identity Protection identities by creating a real-time enforcement policy rule (action MFA) scoped to those source users.required rule_name, source_user_entity_ids
optional simulation_mode, trigger
crowdstrike-falcon_update_alertsPerform actions on alerts identified by composite ID(s) in the request. Actions can update status, assignments, comments, and tags. Status values are strings (new, in_progress, reopened, closed).required ids
optional add_tags, assign_to_name, assign_to_user_id, assign_to_uuid, comment, remove_tags, remove_tags_by_prefix, status, unassign
crowdstrike-falcon_update_cloud_ml_policyConfigure the Cloud ML and/or Sensor ML machine-learning slider levels within a CrowdStrike Falcon prevention policy.required policy_id
optional cloud_ml_detection, cloud_ml_prevention, sensor_ml_detection, sensor_ml_prevention
crowdstrike-falcon_update_cloud_security_policyUpdate a CrowdStrike Falcon Cloud Security (CSPM) policy setting. Enable or disable the policy, override its severity, and optionally scope the change to specific cloud accounts or regions.required policy_id
optional account_ids, enabled, regions, severity, tag_excluded
crowdstrike-falcon_update_content_update_policyUpdate a CrowdStrike Falcon content update policy. Enable or disable the entire policy and/or modify its name, description, and settings.required policy_id
optional description, enabled, name, settings
crowdstrike-falcon_update_device_control_policyUpdate a CrowdStrike Falcon device control (USB) policy. Enable or disable the entire policy and/or modify its name, description, and settings.required policy_id
optional description, enabled, name, settings
crowdstrike-falcon_update_falcon_container_policyUpdate a CrowdStrike Falcon Container image assessment policy. Toggle the policy on/off and/or modify its name, description, and rule set.required policy_id
optional description, enabled, name, policy_data
crowdstrike-falcon_update_iocUpdate an existing custom IOC in CrowdStrike Falcon. Modify the action, severity, description, expiration, platforms, source, or tags of an indicator. Get the IOC ID from list_iocs first.required ioc_id
optional action, description, expiration, platforms, severity, source, tags
crowdstrike-falcon_update_it_automation_policyUpdate a CrowdStrike Falcon IT Automation policy. Toggle the policy on/off and/or modify its name, description, and execution config.required policy_id
optional config, description, enabled, name
crowdstrike-falcon_update_prevention_policyEnable or disable entire CrowdStrike Falcon prevention POLICIES (platform-level policies like “Phase 2 - interim protection”, “Detections”) by their IDs.required policy_id
optional description, enabled, name, settings
crowdstrike-falcon_update_response_policyUpdate a CrowdStrike Falcon Real Time Response policy. Enable or disable the entire policy and/or modify its name, description, and settings.required policy_id
optional description, enabled, name, settings
crowdstrike-falcon_update_sensor_policyUpdate a CrowdStrike Falcon sensor update policy. Enable or disable the entire policy and/or modify its name, description, and settings (sensor build/version, update scheduler, uninstall protection, variant assignments).required policy_id
optional description, enabled, name, settings

7 tools. Connect with API key.

ToolDescriptionArguments
cyble-vision_add_comment_to_alertAdd a comment to a Cyble Vision alert (useful for analyst notes, triage status, or linking the alert to a ticket).required alert_id, comment
cyble-vision_get_cve_detailsFetch enriched details for a specific CVE from Cyble Vision’s vulnerability database — CVSS v2/v3 scores, impact metrics, affected configurations, references, and remediation context.required cve
cyble-vision_get_ip_attack_surfaceFetch Cyble Vision’s attack-surface profile for a single IP address tied to a company — open ports, services, certificates, tags, observed vulnerabilities, and risk score.required company_id, ip_address
cyble-vision_list_companies——
cyble-vision_list_security_advisories—optional countries, end_date, limit, order, sort_by, start_date, tags, vulnerabilities
cyble-vision_search_alerts—optional end_date, exclude_status, limit, service, service_raw, severity, sort_by, sort_order, start_date, status, tagged_alert, with_data_message
cyble-vision_search_threat_indicators—optional end_date, indicator_type, ioc, limit, order, sort_by, start_date

18 tools. Available as 2 connections: ExtraHop RevealX 360 (OAuth 2.0 client credentials), ExtraHop (Self-Managed) (API key).

ToolDescriptionArguments
extrahop_create_investigationCreate a new investigation for agent-driven case management, optionally seeding it with associated detection IDs.required name
optional assessment, assignee, detection_ids, notes, status
extrahop_download_packets_to_kindo_librarySearch stored packets and download the matching capture (PCAP by default) into the Kindo file library for forensic evidence. Filter by time range, IP, port, and Berkeley Packet Filter (BPF) syntax.required from_time
optional bpf, ip1, ip2, limit_bytes, limit_search_duration, output, port1, port2, until
extrahop_get_detectionGet full detail for a single detection by ID, including MITRE tactics/techniques, offender/victim participants, timeline, risk score, and status.required detection_id
extrahop_get_deviceGet full detail for a single device by its numeric ID.required device_id
extrahop_get_investigationGet full detail for a single investigation, including its detections.required investigation_id
extrahop_list_detection_investigationsList all investigations that a specific detection has been added to.required detection_id
extrahop_list_detection_typesList all detection types (formats) known to the system, including display names and MITRE categories, for triage context.—
extrahop_list_device_activityList the protocol activity (client/server roles) observed for a device, for network-peer and blast-radius context.required device_id
extrahop_list_device_group_membersList the devices that belong to a specific device group.required device_group_id
optional active_from, active_until
extrahop_list_device_groupsList all device groups for asset inventory and grouping context.—
extrahop_list_investigationsList investigations. Optionally filter by creation/update time or restrict to user-created investigations.optional created_after, is_user_created, updated_after
extrahop_list_related_detectionsList detections related to a specific detection, for correlation.required detection_id
optional from_time, until
extrahop_query_metricsQuery network and protocol performance metrics for one or more objects over a time window, for anomaly and performance context. Example: metric_category=‘http_server’, metric_name=‘rsp’ for HTTP response counts.required object_type, object_ids, metric_category, metric_name, from_time
optional cycle, until
extrahop_search_detectionsSearch ExtraHop NDR detections with filtering by time range, category, status, risk score, type, and assignee. Returns detection summaries including risk score, MITRE mapping, and participants. Requires the NDR module privilege.optional assignee, categories, from_time, limit, offset, recommended, resolutions, risk_score_min, sort_direction, sort_field, statuses, types, until
extrahop_search_devicesSearch discovered devices by IP, MAC, role, hostname, vendor, tag, discovery ID, criticality, or activity status for asset inventory and blast-radius context. Returns matching device records.optional active_from, active_until, discovery_id, hostname, ip, is_active, is_critical, limit, mac, name, offset, role, tag, vendor
extrahop_search_recordsQuery transaction-level records (HTTP, DNS, DB, SSL/TLS, DHCP, etc.) for investigation and evidence. Filter with a simple field/operator/operand triple or a raw ExtraHop Query Language (EQL) string.required from_time
optional eql, filter_field, filter_operand, filter_operator, limit, offset, record_types, sort_direction, sort_field, until
extrahop_update_detectionUpdate a detection’s assignee, status, resolution, or associated ticket ID. Only non-null fields are changed. Note: status ‘new’ is only accepted when third-party ticket tracking is enabled.required detection_id
optional assignee, resolution, status, ticket_id
extrahop_update_investigationUpdate an investigation’s fields and/or associate detections with it. Note: ‘detection_ids’ REPLACES the full list of associated detections — include existing IDs to keep them.required investigation_id
optional assessment, assignee, detection_ids, name, notes, status

10 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
google-cloud-security_analyze_iam_access—optional cursor, include_inherited, limit, principal, resource
google-cloud-security_apply_remediation—required resource, action
optional confirm, dry_run, enabled
google-cloud-security_delete_resource—required resource
optional confirm, dry_run, force_empty_bucket
google-cloud-security_find_public_exposure—optional cursor, limit, projects, severity
google-cloud-security_gcp_api_request—required service, path, method
optional confirm, dry_run, max_items, parameters, project, query
google-cloud-security_get_resource—required resource_id
optional include
google-cloud-security_list_projects——
google-cloud-security_list_resources—optional cursor, limit, projects, public_only, services
google-cloud-security_modify_network_access—required resource, action
optional cidr, confirm, dry_run, ports, protocol
google-cloud-security_set_iam_binding—required resource, action, member, role
optional confirm, dry_run

55 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
google-secops_activate_parserActivate a log parser in Google SecOpsrequired log_type, parser_id
google-secops_create_dashboardCreate a new dashboard in Google SecOpsrequired name
optional access_type, description
google-secops_create_data_tableCreate a new data table in Google SecOpsrequired name, header
optional description
google-secops_create_data_table_rowsAdd rows to a data table in Google SecOpsrequired data_table_id, rows
google-secops_create_feedCreate a new data feed in Google SecOpsrequired display_name, details
google-secops_create_parserCreate a new log parser in Google SecOpsrequired log_type, parser_code
optional validated_on_empty_logs
google-secops_create_reference_listCreate a new reference list in Google SecOpsrequired name, entries
optional content_type, description
google-secops_create_ruleCreate a new YARA-L detection rule in Google SecOpsrequired rule_text
google-secops_deactivate_parserDeactivate a log parser in Google SecOpsrequired log_type, parser_id
google-secops_delete_data_tableDelete a data table in Google SecOpsrequired data_table_id
google-secops_delete_ruleDelete a detection rule from Google SecOpsrequired rule_id
google-secops_disable_feedDisable a data feed in Google SecOpsrequired feed_id
google-secops_enable_feedEnable a data feed in Google SecOpsrequired feed_id
google-secops_enable_ruleEnable or disable a detection rule in Google SecOpsrequired rule_id
optional enabled
google-secops_get_casesGet case details by IDs from Google SecOpsrequired case_ids
google-secops_get_curated_ruleGet a specific curated detection rule by ID in Google SecOpsrequired rule_id
google-secops_get_curated_rule_by_nameSearch for a curated detection rule by name in Google SecOpsrequired name
google-secops_get_curated_rule_setGet details of a curated rule set in Google SecOpsrequired rule_set_id
google-secops_get_dashboardGet dashboard details in Google SecOpsrequired dashboard_id
google-secops_get_data_tableGet data table details in Google SecOpsrequired data_table_id
google-secops_get_feedGet feed details in Google SecOpsrequired feed_id
google-secops_get_log_typesList all available log types in Google SecOps—
google-secops_get_parserGet parser details in Google SecOpsrequired log_type, parser_id
google-secops_get_reference_listGet reference list details in Google SecOpsrequired reference_list_id
optional view
google-secops_get_ruleGet a specific detection rule from Google SecOpsrequired rule_id
google-secops_get_security_alertsRetrieve security alerts from Google SecOps within a time rangerequired start_time, end_time
optional max_alerts
google-secops_get_statsGet statistics for a UDM query in Google SecOpsrequired query, start_time, end_time
optional max_events
google-secops_get_threat_intelAI-powered threat intelligence query using Google SecOps Geminirequired query
google-secops_ingest_logIngest a raw log entry into Google SecOpsrequired log_type, log_message
google-secops_ingest_udm_eventsIngest UDM-formatted events into Google SecOpsrequired udm_events
google-secops_list_curated_rule_setsList curated rule set collections in Google SecOpsoptional page_size, page_token
google-secops_list_curated_rulesList pre-built curated detection rules in Google SecOpsoptional page_size, page_token
google-secops_list_dashboardsList all dashboards in Google SecOpsoptional page_size
google-secops_list_data_tablesList all data tables in Google SecOps—
google-secops_list_feedsList all data feeds in Google SecOpsoptional page_size, page_token
google-secops_list_iocsList Indicator of Compromise (IOC) matches from Google SecOpsrequired start_time, end_time
optional max_matches
google-secops_list_parsersList parsers for a specific log type in Google SecOpsrequired log_type
google-secops_list_reference_listsList all reference lists in Google SecOpsoptional view
google-secops_list_rule_detectionsList detections generated by a specific rule in Google SecOpsrequired rule_id, start_time, end_time
google-secops_list_rule_errorsList execution errors for a detection rule in Google SecOpsrequired rule_id
google-secops_list_security_rulesList all detection rules in Google SecOpsoptional page_size, page_token
google-secops_run_parserTest a parser against sample logs in Google SecOpsrequired log_type, parser_code, logs
optional parse_statedump, parser_extension_code, statedump_allowed
google-secops_search_curated_detectionsFind detections generated by a curated rule in Google SecOpsrequired rule_id, start_time, end_time
google-secops_search_rule_alertsSearch for rule-based alerts in Google SecOpsrequired start_time, end_time
google-secops_search_rulesSearch detection rules by regex pattern in Google SecOpsrequired query
google-secops_search_security_eventsSearch security events using natural language in Google SecOpsrequired text, start_time, end_time
optional max_events
google-secops_search_udmSearch security events using UDM (Unified Data Model) query language in Google SecOpsrequired query, start_time, end_time
optional max_events
google-secops_summarize_entityGet an entity summary with alerts and prevalence data from Google SecOpsrequired value, start_time, end_time
google-secops_translate_nl_to_udmTranslate natural language text to a UDM query in Google SecOpsrequired text
google-secops_update_curated_rule_set_deploymentEnable or disable a curated rule set deployment in Google SecOpsrequired category_id, rule_set_id, precision, enabled
optional alerting
google-secops_update_feedUpdate feed configuration in Google SecOpsrequired feed_id
optional details, display_name
google-secops_update_reference_listUpdate reference list entries in Google SecOpsrequired reference_list_id, entries
optional description
google-secops_update_ruleUpdate a detection rule’s YARA-L text in Google SecOpsrequired rule_id, rule_text
google-secops_validate_queryValidate UDM query syntax in Google SecOpsrequired query
google-secops_validate_ruleValidate YARA-L rule syntax in Google SecOpsrequired rule_text

8 tools. Connect with Basic auth.

ToolDescriptionArguments
graylog_create_streamCreate a new streamrequired title
optional description, index_set_id, matching_type, remove_matches_from_default_stream
graylog_create_stream_ruleCreate a rule for a streamrequired streamId, type, field, value
optional description, inverted
graylog_get_processing_statusGet current message processing status—
graylog_get_streamGet details of a specific stream by IDrequired streamId
graylog_get_system_infoGet Graylog system information including version, node ID, and cluster details—
graylog_list_streamsList all available streams—
graylog_search_messagesSearch for messages using Lucene query syntax with relative time rangerequired query, range
optional decorate, fields, filter, limit, offset, sort
graylog_search_messages_absoluteSearch for messages using Lucene query syntax with absolute time rangerequired query, from, to
optional decorate, fields, filter, limit, offset, sort

16 tools. Connect with API key.

ToolDescriptionArguments
ibm-qradar_add_offense_noteAdd a text note to a IBM QRadar offense for investigation tracking.required offense_id, note_text
ibm-qradar_add_reference_set_entryAdd a value to a IBM QRadar reference data set (e.g., add a malicious IP to a blocklist).required name, value
ibm-qradar_delete_reference_set_entryRemove a value from a IBM QRadar reference data set.required name, value
ibm-qradar_get_ariel_searchCheck the status of an existing Ariel search and optionally retrieve its results if complete.required search_id
optional include_results
ibm-qradar_get_assetGet detailed information about a IBM QRadar asset by its numeric ID.required asset_id
ibm-qradar_get_offenseGet full details of a specific IBM QRadar offense by its numeric ID. Returns all offense fields including source IPs, categories, magnitude, and assigned user.required offense_id
ibm-qradar_get_reference_setGet the contents of a specific reference data set by name. Returns entries in the set (e.g., list of blocked IPs), paginated by limit.required name
optional limit
ibm-qradar_get_system_infoGet IBM QRadar system information including version and build number.—
ibm-qradar_list_closing_reasonsList available offense closing reasons. Use the returned IDs when closing an offense via update_offense.optional limit
ibm-qradar_list_log_sourcesList configured IBM QRadar log sources with their status, type, and protocol information.optional filter_query, limit
ibm-qradar_list_offense_notesList notes attached to a specific IBM QRadar offense.required offense_id
optional limit
ibm-qradar_list_offensesList IBM QRadar offenses (security incidents) with optional filtering. Returns offenses sorted by most recent. Use the filter parameter for IBM QRadar filter expressions like ‘status=OPEN’ or ‘magnitude >= 5’.optional fields, filter_query, limit, status
ibm-qradar_list_reference_setsList IBM QRadar reference data sets (used for IOC management, blocklists, whitelists). Returns set names, types, and element counts.optional limit
ibm-qradar_run_ariel_searchExecute an AQL (Ariel Query Language) search and return results. The search is submitted, polled until completion, and results are returned.required query_expression
ibm-qradar_search_assetsSearch IBM QRadar assets via the asset model REST API. Use the filter parameter for IBM QRadar filter expressions, e.g. ‘interfaces contains ip_addresses contains value = “10.0.0.1“‘.optional fields, filter_query, limit
ibm-qradar_update_offenseUpdate an offense — close it, hide it, reassign it, or change its status. To close an offense you must provide a closing_reason_id (use list_closing_reasons to find valid IDs).required offense_id
optional assigned_to, closing_reason_id, follow_up, status

18 tools. Available as 2 connections: Microsoft Defender (OAuth 2.0), Microsoft Defender for Endpoint (GCC High) (OAuth 2.0).

ToolDescriptionArguments
microsoft-defender_create_indicatorCreate or update a Microsoft Defender threat indicator (IP, URL, domain, or file hash) with a specified actionrequired indicator_value, indicator_type, action, title
optional description, expiration_time, generate_alert, severity
microsoft-defender_delete_indicatorDelete a Microsoft Defender threat indicator by IDrequired indicator_id
microsoft-defender_get_alertGet a single Microsoft Defender alert by ID with full detailrequired alert_id
microsoft-defender_get_incidentGet a Microsoft Defender incident by ID including associated alertsrequired incident_id
microsoft-defender_get_indicatorGet a specific Microsoft Defender threat indicator by IDrequired indicator_id
microsoft-defender_get_investigationGet a Microsoft Defender automated investigation by IDrequired investigation_id
microsoft-defender_get_machineGet a single Microsoft Defender endpoint device by IDrequired machine_id
microsoft-defender_isolate_machineIsolate a device from the network. Use Full for complete network cutoff or Selective for limited isolationrequired machine_id, comment
optional isolation_type
microsoft-defender_list_alertsList Microsoft Defender alerts with filtering by status, severity, and OData expressionsoptional filter_query, severity, skip, status, top
microsoft-defender_list_incidentsList Microsoft Defender security incidents with filtering by status, assignment, and OData expressionsoptional assigned_to, filter_query, skip, status, top
microsoft-defender_list_indicatorsList Microsoft Defender threat indicators with OData filtering by type, action, and other propertiesoptional filter_query, skip, top
microsoft-defender_list_investigationsList Microsoft Defender automated investigations with OData filtering by state and machineoptional filter_query, skip, top
microsoft-defender_list_machinesList Microsoft Defender endpoint devices with OData filtering by DNS name, OS platform, risk score, and health statusoptional filter_query, skip, top
microsoft-defender_run_advanced_queryExecute a KQL (Kusto Query Language) query against Microsoft Defender data for advanced threat huntingrequired query
microsoft-defender_run_antivirus_scanInitiate an antivirus scan on a device. Use Quick for a fast scan or Full for a comprehensive scanrequired machine_id, comment
optional scan_type
microsoft-defender_unisolate_machineRelease a device from network isolation, restoring its network connectivityrequired machine_id, comment
microsoft-defender_update_alertUpdate a Microsoft Defender alert’s status, assignment, classification, or determinationrequired alert_id
optional assigned_to, classification, comment, determination, status
microsoft-defender_update_incidentUpdate a Microsoft Defender incident’s status, assignment, classification, tags, or determinationrequired incident_id
optional assigned_to, classification, comment, determination, status, tags

16 tools. Available as 4 connections: Microsoft Graph Security (OAuth 2.0), Microsoft Graph Security (Application) (OAuth 2.0 client credentials), Microsoft Graph Security (GCC High) (OAuth 2.0), Microsoft Defender XDR (GCC High, Application) (OAuth 2.0 client credentials).

ToolDescriptionArguments
microsoft-graph-security_confirm_risky_users_compromisedConfirm one or more users as compromised, setting their risk level to highrequired user_ids
microsoft-graph-security_confirm_risky_users_safeConfirm one or more users as safe, setting their risk level to nonerequired user_ids
microsoft-graph-security_create_alert_commentAdd a comment to an existing security alertrequired alert_id, comment
microsoft-graph-security_create_incident_commentAdd a comment to an existing security incidentrequired incident_id, comment
microsoft-graph-security_dismiss_risky_usersDismiss (reset) the risk of one or more users, setting their risk level to nonerequired user_ids
microsoft-graph-security_get_alertGet a single security alert by ID, including evidence artifacts and MITRE ATT&CK techniquesrequired alert_id
microsoft-graph-security_get_incidentGet a single security incident by ID, optionally expanding related alertsrequired incident_id
optional expand_alerts
microsoft-graph-security_get_risky_userGet a single risky user by ID from Microsoft Entra ID Identity Protectionrequired risky_user_id
microsoft-graph-security_list_alertsList security alerts from Microsoft 365 Defender with filtering by severity, status, classification, service source, assignee, and date rangeoptional assigned_to, classification, created_after, created_before, service_source, severity, skip, status, top
microsoft-graph-security_list_incidentsList security incidents from Microsoft 365 Defender with filtering by severity, status, classification, assignee, and date rangeoptional assigned_to, classification, created_after, created_before, severity, skip, status, top
microsoft-graph-security_list_risky_usersList risky users from Microsoft Entra ID Identity Protection with filtering by risk level, risk state, and user principal nameoptional risk_level, risk_state, skip, top, user_principal_name
microsoft-graph-security_list_secure_score_control_profilesList individual security control profiles with their scores and improvement actionsoptional skip, top
microsoft-graph-security_list_secure_scoresList tenant security scores (daily snapshots) from Microsoft Secure Scoreoptional skip, top
microsoft-graph-security_run_hunting_queryExecute a KQL query against Microsoft 365 Defender raw data (up to 30 days, max 100K rows)required query
optional timespan
microsoft-graph-security_update_alertUpdate a security alert’s status, assignee, classification, and determinationrequired alert_id
optional assigned_to, classification, determination, status
microsoft-graph-security_update_incidentUpdate a security incident’s status, assignee, classification, determination, and custom tagsrequired incident_id
optional assigned_to, classification, custom_tags, determination, status

12 tools. Available as 2 connections: Microsoft Sentinel (Management) (OAuth 2.0), Microsoft Sentinel (Management, Government) (OAuth 2.0).

ToolDescriptionArguments
microsoft-sentinel-management_add_incident_commentAdd an analyst comment to a Microsoft Sentinel incident, for recording investigation notes and handoffs on the incident timeline. Each call appends a new comment. Returns an acknowledgement {‘id’, ‘incident_id’, ‘created’}.required incident_id, message
microsoft-sentinel-management_create_bookmarkCreate a Microsoft Sentinel hunting bookmark to preserve a notable KQL query result during an investigation. Requires a display name and the KQL query text; notes are optional context. Each call creates a new bookmark.required display_name, query
optional notes
microsoft-sentinel-management_get_incidentGet the details of a single Microsoft Sentinel incident by its ID (the ‘id’ field from list_incidents), including its description, severity, status, owner, labels, classification, and MITRE tactics/techniques.required incident_id
microsoft-sentinel-management_get_watchlistGet a single Microsoft Sentinel watchlist by its alias (the ‘alias’ field from list_watchlists), including its source, provider, search key, and authorship. Returns metadata only — call list_watchlist_items for the rows.required watchlist_alias
microsoft-sentinel-management_list_bookmarksList Microsoft Sentinel hunting bookmarks in the workspace. Bookmarks preserve interesting query results found during threat hunting so analysts can revisit and share them.optional cursor, top
microsoft-sentinel-management_list_incident_alertsList the security alerts grouped into a Microsoft Sentinel incident — the underlying detections that make up the case.required incident_id
optional cursor, top
microsoft-sentinel-management_list_incident_entitiesList the entities (accounts, hosts, IPs, files, URLs, etc.) related to a Microsoft Sentinel incident — use it to scope an investigation to the affected assets and identities.required incident_id
optional top
microsoft-sentinel-management_list_incidentsList Microsoft Sentinel incidents for the connected workspace, newest first. Incidents group related alerts into a single investigatable case.optional cursor, severity, status, top
microsoft-sentinel-management_list_threat_intelligence_indicatorsList threat-intelligence indicators (IOCs) in the Microsoft Sentinel workspace — IPs, domains, URLs, file hashes, and more, with their confidence, validity window, and threat types.optional cursor, top
microsoft-sentinel-management_list_watchlist_itemsList the individual rows of a Microsoft Sentinel watchlist.required watchlist_alias
optional cursor, top
microsoft-sentinel-management_list_watchlistsList Microsoft Sentinel watchlists in the workspace. Watchlists are curated reference datasets (e.g. high-value assets, allowed IPs, terminated employees) used to correlate and enrich detections.optional cursor, top
microsoft-sentinel-management_update_incidentUpdate a Microsoft Sentinel incident: change its title, severity, status, or close it. Only the fields you provide are changed; the rest are preserved.required incident_id
optional classification, classification_comment, classification_reason, severity, status, title

8 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
mitre-attack_list_tacticsList all MITRE ATT&CK tactics for a matrix in kill-chain order.optional matrix
mitre-attack_list_techniques_for_tactic—required tactic
optional include_deprecated, include_revoked, include_subtechniques, limit, matrix, offset
mitre-attack_lookup_campaignLook up a MITRE ATT&CK campaign by ATT&CK ID (e.g. ‘C0028’) or name. Searches all matrices.optional campaign_id, include_deprecated, include_revoked, query
mitre-attack_lookup_groupLook up a MITRE ATT&CK threat group (intrusion set) by ATT&CK ID (e.g. ‘G0007’), name, or alias (e.g. ‘APT28’, ‘Fancy Bear’, ‘STRONTIUM’). Searches all matrices.optional group_id, include_deprecated, include_revoked, query
mitre-attack_lookup_mitigationLook up a MITRE ATT&CK mitigation (course of action) by ATT&CK ID (e.g. ‘M1056’) or keyword. Returns the mitigation profile plus an inline summary of every technique the mitigation is mapped to.optional include_deprecated, include_revoked, matrix, mitigation_id, query
mitre-attack_lookup_softwareLook up MITRE ATT&CK software (malware or tool) by ATT&CK ID (e.g. ‘S0002’) or name. Searches all matrices.optional include_deprecated, include_revoked, query, software_id
mitre-attack_lookup_techniqueLook up a MITRE ATT&CK technique (or sub-technique) by ATT&CK ID (e.g. ‘T1059’ or ‘T1059.001’) or keyword.optional include_deprecated, include_revoked, matrix, query, technique_id
mitre-attack_search_attackFree-text search across the MITRE ATT&CK knowledge base. Searches names, descriptions, aliases, and ATT&CK IDs of techniques, tactics, mitigations, threat groups, software, campaigns, data sources, data components, and ICS assets.required query
optional include_deprecated, include_revoked, limit, matrix, object_types, offset

0 tools. Connect with API key.

19 tools. Connect with API key.

ToolDescriptionArguments
palo-alto-cortex-xdr_allowlist_filesAdd file hashes to the Cortex XDR allowlist to exclude them from security scanningrequired hash_list
optional comment, incident_id
palo-alto-cortex-xdr_blocklist_filesAdd file hashes to the Cortex XDR blocklist to prevent execution across all endpointsrequired hash_list
optional comment, incident_id
palo-alto-cortex-xdr_get_action_statusCheck the status of a response action (isolate, scan, script execution, etc.)required action_id
palo-alto-cortex-xdr_get_audit_management_logsRetrieve Cortex XDR audit management logs with filtering by admin email, type, result, and timestampoptional email, log_type, result, search_from, search_to, sort_field, sort_order, timestamp_gte, timestamp_lte
palo-alto-cortex-xdr_get_incidentGet detailed incident data including alerts, network artifacts, and file artifacts for a specific incidentrequired incident_id
optional alerts_limit
palo-alto-cortex-xdr_get_script_execution_resultsGet the results of a previously executed script using the action IDrequired action_id
palo-alto-cortex-xdr_get_xql_resultsRetrieve results of a previously started XQL query using the query IDrequired query_id
optional limit
palo-alto-cortex-xdr_insert_alertsInsert externally-detected alerts into Cortex XDR for correlation and investigationrequired alerts
palo-alto-cortex-xdr_isolate_endpointIsolate an endpoint from the network to contain a threat (endpoint remains manageable via Cortex XDR)required endpoint_id
optional incident_id
palo-alto-cortex-xdr_list_alertsList Cortex XDR alerts with filtering by alert ID, source, severity, and creation timeoptional alert_id_list, alert_source, creation_time_gte, creation_time_lte, search_from, search_to, severity, sort_field, sort_order
palo-alto-cortex-xdr_list_endpointsList Cortex XDR endpoints with filtering by status, hostname, IP, platform, isolation status, and moreoptional alias, endpoint_id_list, endpoint_status, group_name, hostname, ip_list, isolate, platform, search_from, search_to, sort_field, sort_order, username
palo-alto-cortex-xdr_list_incidentsList Cortex XDR incidents with filtering by status, severity, creation/modification time, and descriptionoptional creation_time_gte, creation_time_lte, description, incident_id_list, modification_time_gte, search_from, search_to, severity, sort_field, sort_order, status
palo-alto-cortex-xdr_list_scriptsList available scripts in the Cortex XDR script library with optional filteringoptional description, is_high_risk, linux_supported, macos_supported, name, search_from, search_to, windows_supported
palo-alto-cortex-xdr_quarantine_fileQuarantine a file on an endpoint by path and SHA256 hash to prevent executionrequired endpoint_id, file_path, file_hash
optional incident_id
palo-alto-cortex-xdr_run_scriptExecute a script from the Cortex XDR library on one or more endpointsrequired script_uid, endpoint_id_list
optional incident_id, parameters_values, timeout
palo-alto-cortex-xdr_scan_endpointsInitiate a malware scan on specified endpoints or all endpointsoptional all_endpoints, dist_name, endpoint_id_list
palo-alto-cortex-xdr_start_xql_queryStart an XQL (XDR Query Language) query for advanced threat hunting and data analysisrequired query
optional tenants, time_frame
palo-alto-cortex-xdr_unisolate_endpointRestore network connectivity for a previously isolated endpointrequired endpoint_id
optional incident_id
palo-alto-cortex-xdr_update_incidentUpdate an incident’s status, severity, assignee, or add a resolve commentrequired incident_id
optional assigned_user_mail, assigned_user_pretty_name, resolve_comment, severity, status

8 tools. Connect with Basic auth.

ToolDescriptionArguments
proofpoint_delete_quarantine_messageDelete a quarantined message by moving it to the deleted folder. Identified by quarantine folder and local GUID. This is destructive.required folder, local_guid
optional deleted_folder
proofpoint_forward_quarantine_messageForward a copy of a quarantined message to another recipient for review, without releasing it to the original recipients.required folder, local_guid, to
proofpoint_get_end_userGet an end-user’s Proofpoint profile, including their safe-sender and blocked-sender lists. Identified by email address or user id.required email_or_uid
proofpoint_list_quarantine_messagesList messages currently held in a Proofpoint quarantine folder. Filter by sender, recipient, subject, date range, or folder.optional end_date, folder, limit, message_status, recipient, sender, start_date, subject
proofpoint_move_quarantine_messageMove a quarantined message from one quarantine folder to another. Identified by source folder and local GUID.required folder, local_guid, target_folder
proofpoint_release_quarantine_messageRelease a quarantined message back to its recipients. The message is identified by its quarantine folder and local GUID. This delivers the held email — use after confirming it is safe.required folder, local_guid
optional rescan
proofpoint_resubmit_quarantine_messageResubmit a quarantined message back through the filtering modules for re-evaluation. Identified by quarantine folder and local GUID.required folder, local_guid
proofpoint_search_messagesSearch processed email through Proofpoint Smart Search. Filter by envelope sender/recipient, time window, subject, message-id, or final disposition to trace a message and inspect its spam/phishing/virus verdict.optional disposition, end_date, limit, message_id, recipient, sender, start_date, subject, virus

15 tools. Connect with API key.

ToolDescriptionArguments
rapid7-insightidr_add_threat_indicatorsAdd IP, hash, domain, or URL indicators to an InsightIDR threatrequired key
optional domain_names, hashes, ips, urls
rapid7-insightidr_create_commentAdd a comment to an InsightIDR investigationrequired target, body
rapid7-insightidr_create_investigationCreate a new manual InsightIDR investigation with title, priority, and statusrequired title
optional assignee_email, disposition, priority, status
rapid7-insightidr_get_investigationGet details of a specific InsightIDR investigation by ID or RRNrequired investigation_id
rapid7-insightidr_list_commentsList comments for a specific InsightIDR investigationrequired target
optional index, size
rapid7-insightidr_list_detection_rulesList InsightIDR detection rules with pagination. Note: requires appropriate SIEM tier permissions. Raises a not-found error if your API key lacks detection rule access.optional index, size
rapid7-insightidr_list_investigation_alertsList alerts associated with a specific InsightIDR investigationrequired investigation_id
optional index, size
rapid7-insightidr_list_investigationsList InsightIDR investigations with filtering by status, priority, assignee, and time rangeoptional assignee_email, end_time, index, priorities, size, sort, sources, start_time, statuses
rapid7-insightidr_list_logsList all available log sources in InsightIDR—
rapid7-insightidr_list_usersSearch and list InsightIDR user accountsoptional index, search, size
rapid7-insightidr_query_logExecute a LEQL query against a specific InsightIDR log sourcerequired log_id, query
optional end_time, start_time, time_range
rapid7-insightidr_search_alertsSearch InsightIDR alerts with filtering by status and time range. Note: requires the Managed Detection and Response (MDR) add-on. Raises a not-found error if your account does not have MDR access.optional end_time, index, search, size, start_time, statuses
rapid7-insightidr_search_investigationsSearch InsightIDR investigations by text query with time range filteringoptional end_time, index, search, size, sort, start_time
rapid7-insightidr_update_alertUpdate an InsightIDR alert’s status, disposition, priority, or assignment. Note: requires the Managed Detection and Response (MDR) add-on. Raises a not-found error if your account does not have MDR access.required alert_id
optional assignee_email, disposition, priority, status
rapid7-insightidr_update_investigationUpdate an InsightIDR investigation’s title, status, priority, disposition, or assigneerequired investigation_id
optional assignee_email, disposition, priority, status, title

14 tools. Connect with API key.

ToolDescriptionArguments
recorded-future_enrich_domainEnrich a domain with Recorded Future threat intelligence including risk score, risk rules, evidence details, and related entity linksrequired domain
optional fields
recorded-future_enrich_entitiesBulk enrich multiple entities (IPs, domains, URLs, hashes, vulnerabilities) at once using the SOAR API. More efficient than individual enrichment calls when checking multiple indicators.optional domain, file_hash, ip, url, vulnerability
recorded-future_enrich_hashEnrich a file hash (MD5, SHA-1, or SHA-256) with Recorded Future threat intelligence including risk score, risk rules, and malware associationsrequired file_hash
optional fields
recorded-future_enrich_ipEnrich an IP address with Recorded Future threat intelligence including risk score, risk rules, evidence details, and related entity linksrequired ip
optional fields
recorded-future_enrich_urlEnrich a URL with Recorded Future threat intelligence including risk score, risk rules, and evidence detailsrequired url
optional fields
recorded-future_enrich_vulnerabilityEnrich a vulnerability (CVE ID or name) with Recorded Future threat intelligence including risk score, risk rules, evidence, and exploit availabilityrequired vulnerability_id
optional fields
recorded-future_get_alertGet detailed information about a specific triggered alert by ID, including hits, entities, documents, risk scores, and AI insightsrequired alert_id
optional fields
recorded-future_get_playbook_alertGet detailed information about a specific playbook alert by ID, including evidence summary, targets, priority, and category detailsrequired alert_id
recorded-future_get_threat_map_actorsGet threat actor map data for the organization, showing threat actors with intent and opportunity scores, categories, and watchlist matches. Useful for understanding the threat landscape targeting your organization.required actors, categories, watchlists
recorded-future_get_threat_map_malwareGet malware threat map data for the organization, showing malware families with severity scores, categories, and watchlist matches. Useful for understanding malware threats targeting your organization.required malware, categories, watchlists
recorded-future_search_alert_rulesSearch Recorded Future alert rules by name. Returns rule titles and IDs for use with alert search filtering.optional freetext, limit
recorded-future_search_alertsSearch triggered alerts in Recorded Future with filtering by timeframe, alert rule, and pagination. Returns alert summaries including title, rule, status, and hit counts.optional alert_rule, fields, limit, offset, triggered
recorded-future_search_detection_rulesSearch Recorded Future detection rules (Sigma, Yara, Snort) with filtering by type, related entities, and date range. Returns rules with content for import into security tools.optional after, before, entities, limit, types
recorded-future_search_playbook_alertsSearch Recorded Future playbook alerts with filtering by status, priority, category, and time ranges. Returns actionable security alerts with triage information.optional categories, created_from_relative, entities, limit, priorities, statuses, updated_from_relative

22 tools. Connect with API key.

ToolDescriptionArguments
reliaquest-greymatter_acknowledge_incidentAcknowledge a Grey Matter incident by providing acknowledgement method and auto-assignment preference. Use the base64-encoded incident IDrequired input
reliaquest-greymatter_add_incident_commentAdd a comment to a Grey Matter incident by providing the comment text and incident ID. Use the base64-encoded incident IDrequired input
optional after, filter, first, order
reliaquest-greymatter_assign_incidentAssign a Grey Matter incident to a specific user by providing the assignee ID and incident ID. FIRST use list_users to find the user ID by email/name, THEN assign the incident. Use the base64-encoded incident IDrequired input
reliaquest-greymatter_close_incidentClose a Grey Matter incident by providing the close code, close note, incident ID, and optional final state. Use the base64-encoded incident IDrequired request
reliaquest-greymatter_get_auditsRetrieve user activity audits with comprehensive filtering and pagination support. For time-based queries, use exec tool to get current date first.optional after, filter, first, order
reliaquest-greymatter_get_customer_detectionRetrieve a specific Grey Matter customer detection with activity logs and rule details. For date filtering, use exec tool to get current date first.required id, by
optional after, filter, first, order
reliaquest-greymatter_get_incidentRetrieve a specific Grey Matter incident by ID or ticket number with all related data. For date filtering, use exec tool to get current date first.required by
optional after, after4, filter, filter5, first, first4, order, order4
reliaquest-greymatter_get_indicatorRetrieve a specific Grey Matter indicator by Global ID or name/type combinationrequired by
reliaquest-greymatter_get_playbook_runRetrieve a specific Grey Matter playbook run with execution results, user details, and complete audit trailrequired id
optional after, after1, after2, after3, after4, after5, after6, after7, filter, filter1, filter2, filter3, filter4, filter5, first, first1, first2, first3, first4, first5, first6, first7, order, order1, order2, order3, order4, order5
reliaquest-greymatter_get_playbook_run_filter_dataGet available filter values for playbook runs including tempRuleIds, ticketNumbers, and usersoptional after, after1, after2, filter, filter1, filter2, first, first1, first2, order, order1, order2
reliaquest-greymatter_get_recommended_playbooksGet recommended Grey Matter playbooks based on artifacts and temporary rule ID. Use single artifact object with field and values array, not array of artifacts.required filter
reliaquest-greymatter_get_userRetrieve a specific Grey Matter user by ID with comprehensive access groups, pods, and roles informationrequired id
optional after, after1, after2, filter, filter1, filter2, first, first1, first2, order, order1, order2
reliaquest-greymatter_list_customer_detectionsFetch all Grey Matter customer detections matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z).optional after, filter, first, order
reliaquest-greymatter_list_customer_playbooksGet all Grey Matter customer playbooks with their configurations and supported integrations—
reliaquest-greymatter_list_detection_rulesFetch all Grey Matter detection rules matching filter criteria with comprehensive filtering, ordering, and pagination support.optional after, detectionRuleOrder, filter, first
reliaquest-greymatter_list_incidentsFetch all Grey Matter incidents matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z).optional after, first, incidentFilter, incidentOrder
reliaquest-greymatter_list_indicatorsFetch all Grey Matter indicators matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z).optional after, filter, first, order
reliaquest-greymatter_list_playbook_runsGet Grey Matter playbook runs with comprehensive filtering, pagination, and sorting options. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z).optional after, filter, first, orderBy
reliaquest-greymatter_list_playbooksGet all available Grey Matter playbooks with their metadata, field definitions, and supported technologies—
reliaquest-greymatter_list_usersRetrieve users for the current customer organization with pagination support. Returns customer info and paginated user list including id, email, fullName, and serviceNowId.optional after, first
reliaquest-greymatter_run_playbookExecute a Grey Matter playbook with specified configuration, integration IDs, and variables. Used to trigger automated response actions.required input
reliaquest-greymatter_update_incident_stateUpdate the state of a Grey Matter incident by providing a comment explaining the change, incident ID, and new state. Use the base64-encoded incident ID, not the ticket number. Returns incident state details and success status.required input

22 tools. Connect with API key.

ToolDescriptionArguments
sentinelone_get_alertGet detailed information about a specific alert by ID. Args: alert_id: The unique identifier of the alert. Returns: Detailed alert information in JSON format. Raises: RuntimeError: If there’s an error retrieving the alert.required alert_id
sentinelone_get_alert_historyGet the complete audit history and timeline for an alert. Args: alert_id: The unique identifier of the alert. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional).required alert_id
optional after, first
sentinelone_get_alert_notesGet all notes and comments associated with an alert. Args: alert_id: The unique identifier of the alert. Returns: List of notes in JSON format with author and timestamp information.required alert_id
sentinelone_get_inventory_itemGet detailed information about a specific inventory item by ID. Args: item_id: The unique identifier of the inventory item. Returns: Detailed inventory item information in JSON format. Raises: ValueError: If item_id is invalid or empty.required item_id
sentinelone_get_misconfigurationGet detailed information about a specific misconfiguration by ID. Args: misconfiguration_id: The unique identifier of the misconfiguration. Returns: Detailed misconfiguration information in JSON format.required misconfiguration_id
sentinelone_get_misconfiguration_historyGet the audit history for a misconfiguration. Args: misconfiguration_id: The unique identifier of the misconfiguration. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional).required misconfiguration_id
optional after, first
sentinelone_get_misconfiguration_notesGet all notes associated with a misconfiguration. Args: misconfiguration_id: The unique identifier of the misconfiguration. Returns: List of notes in JSON format.required misconfiguration_id
sentinelone_get_timestamp_rangeGet both current timestamp and offset timestamp for time range queries. This tool returns both the current time and a calculated offset time, designed specifically for PowerQuery time range queries.optional days, direction, hours, minutes, months, reference_time, seconds, weeks, years
sentinelone_get_vulnerabilityGet detailed information about a specific vulnerability by ID. Args: vulnerability_id: The unique identifier of the vulnerability. Returns: Detailed vulnerability information in JSON format.required vulnerability_id
sentinelone_get_vulnerability_historyGet the audit history for a vulnerability. Args: vulnerability_id: The unique identifier of the vulnerability. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional).required vulnerability_id
optional after, first
sentinelone_get_vulnerability_notesGet all notes associated with a vulnerability. Args: vulnerability_id: The unique identifier of the vulnerability. Returns: List of notes in JSON format. Raises: RuntimeError: If there’s an error retrieving vulnerability notes.required vulnerability_id
sentinelone_iso_to_unix_timestampConvert an ISO 8601 datetime string to UNIX timestamp in milliseconds. Args: iso_datetime: ISO 8601 formatted datetime string. Returns: UNIX timestamp in milliseconds as a string.required iso_datetime
sentinelone_list_alertsList alerts with pagination and filtering capabilities. Args: first: Number of alerts to retrieve (1-100, default: 10). after: Cursor for pagination (optional).optional after, fields, first, view_type
sentinelone_list_inventory_itemsList inventory items with pagination and optional surface filtering. Args: limit: Number of items to retrieve (1-1000, default: 50). skip: Number of items to skip for pagination (default: 0).optional limit, skip, surface
sentinelone_list_misconfigurationsList misconfigurations with pagination and view filtering. Args: first: Number of misconfigurations to retrieve (1-100, default: 10). after: Cursor for pagination (optional).optional after, fields, first, view_type
sentinelone_list_vulnerabilitiesList vulnerabilities with pagination. Args: first: Number of vulnerabilities to retrieve (1-100, default: 10). after: Cursor for pagination (optional). fields: Optional JSON string containing an array of field names to return.optional after, fields, first
sentinelone_powerqueryRun a SentinelOne PowerQuery in AISIEM and return the results. Args: query: The PowerQuery string to execute start_datetime: Start time in ISO 8601 format.required query, start_datetime, end_datetime
sentinelone_purple_aiAsk Purple AI a question. Purple AI is a tool to answer cyber security questions. Args: query: The question to ask Purple AI. Returns: The response from Purple AI as a string. Raises: RuntimeError: If settings are not properly configured.required query
sentinelone_search_alertsSearch alerts using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys.optional after, fields, filters, first, view_type
sentinelone_search_inventory_itemsSearch inventory items using REST API filters. Note: This tool does not support surface filtering. For surface-specific queries (ENDPOINT, CLOUD, IDENTITY, NETWORK_DISCOVERY), use list_inventory_items instead.optional filters, limit, skip
sentinelone_search_misconfigurationsSearch misconfigurations using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys.optional after, fields, filters, first, view_type
sentinelone_search_vulnerabilitiesSearch vulnerabilities using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys.optional after, fields, filters, first

26 tools. Connect with API key.

ToolDescriptionArguments
splunk_add_investigation_noteAdd a free-form note to a Splunk ES Mission Control v2 record via the unified notes endpoint (POST /servicesNS/nobody/missioncontrol/public/v2/investigations/{id}/notes).required investigation_id, content
optional notable_time, title
splunk_cancel_jobCancel a running search jobrequired sid
splunk_create_findingCreate a new manual finding in Splunk Enterprise Security / Mission Control (the ES 8.0+ term for what used to be a ‘notable event’).required title, description, security_domain, entity, entity_type, finding_score
optional disposition, fields, owner, status, urgency
splunk_create_investigationCreate a new investigation (case) in Splunk Enterprise Security via the Mission Control v2 REST API.required name
optional description, incident_origin, owner, sensitivity, status, urgency
splunk_create_saved_searchCreate a new saved searchrequired name, search
optional cron_schedule, description, earliest_time, is_scheduled, latest_time
splunk_create_search_jobCreate a search job that runs asynchronouslyrequired query
optional earliest_time, latest_time, search_mode
splunk_delete_saved_searchDelete an existing saved search by namerequired name
optional app, owner
splunk_export_resultsExport search results in a specific formatrequired query
optional earliest_time, latest_time, max_results, output_mode
splunk_get_indexGet details of a specific indexrequired name
splunk_get_investigationRetrieve full details of a specific investigation (case) by ID from Splunk Enterprise Security, including status, description, collaborators, tags, and timestamps.required investigation_id
splunk_get_job_resultsRetrieve results from a completed search jobrequired sid
optional count, offset, output_mode
splunk_get_job_statusGet the status and progress of a search jobrequired sid
splunk_get_saved_searchGet details of a specific saved searchrequired name
optional app, owner
splunk_get_server_infoGet Splunk server information and status—
splunk_link_findings_to_investigationLink existing Mission Control v2 findings to an investigation in a single bulk request (POST /investigations/{guid}/findings).required investigation_id, finding_ids
optional finding_times
splunk_list_findingsList Splunk ES findings via Mission Control v2 (GET /findings).optional count, earliest, latest, offset
splunk_list_indexesList all indexes accessible to the useroptional count, datatype, offset
splunk_list_investigationsList investigations (cases) from Splunk ES Mission Control v2.optional count, disposition, earliest, latest, offset, owner, sensitivity, status, urgency
splunk_list_jobsList all search jobs for the current useroptional count, offset, sort_dir, sort_key
splunk_list_saved_searchesList all saved searches accessible to the useroptional app, count, offset, owner
splunk_notable_update[Legacy — do not use for structured updates on ES 8.x] On Splunk Enterprise Security 8.x, status / owner / urgency / disposition updates through this tool silently no-op even when the endpoint returns 2xx.optional app, comment, disposition, new_owner, owner, rule_uids, search_id, status_id, urgency
splunk_run_saved_searchDispatch a saved search and return the job SID for trackingrequired name
optional app, earliest_time, latest_time, owner, trigger_actions
splunk_run_searchExecute a Splunk search query and return resultsrequired query
optional earliest_time, latest_time, max_results, output_mode
splunk_update_finding[PRIMARY tool for finding status / owner / urgency / disposition updates on Splunk ES 8.x] Use this instead of notable_update whenever the user asks to change a finding’s status, owner, urgency or disposition.required finding_id
optional disposition, notable_time, owner, status, urgency
splunk_update_investigationPartially update an investigation (case) in Splunk ES Mission Control v2. Only the provided fields are sent to the server; unspecified fields are left untouched.required investigation_id
optional description, disposition, name, owner, sensitivity, status, urgency
splunk_update_saved_searchUpdate an existing saved searchrequired name
optional app, cron_schedule, description, disabled, is_scheduled, owner, search

12 tools. Connect with Basic auth.

ToolDescriptionArguments
sumo-logic_cloud_siem_add_comment_to_insightAdd a comment to a Cloud SIEM Insight for collaboration.required insightId, comment
sumo-logic_cloud_siem_add_tags_to_insightAdd tags to a Cloud SIEM Insight for better organization.required insightId, tagName
sumo-logic_cloud_siem_enrich_entitiesEnrich entity information with additional context from Cloud SIEM.required entityType, entityValue
sumo-logic_cloud_siem_get_entity_detailsGet detailed information about a specific Cloud SIEM Entity (user, hostname, IP address, etc.) by ID.required id
optional expand
sumo-logic_cloud_siem_get_insight_detailsGet detailed information about a specific Cloud SIEM Insight by ID.required id, recordSummaryFields
optional exclude
sumo-logic_cloud_siem_list_insightsGet a list of Cloud SIEM Insights with optional filtering. Note: This API will not return more than 10,000 Insights for a given query. Use the query parameter to filter results.required recordSummaryFields
optional exclude, limit, offset, q
sumo-logic_cloud_siem_pingTest connectivity to Sumo Logic Cloud SIEM.—
sumo-logic_cloud_siem_search_entity_signalsSearch for signals related to a specific entity in Cloud SIEM.required entityValue
optional endTime, limit, minSeverity, offset, startTime
sumo-logic_cloud_siem_update_insight_assigneeAssign or reassign a Cloud SIEM Insight to a specific user or team.required insightId, assigneeType, assigneeValue
sumo-logic_cloud_siem_update_insight_statusUpdate the status of a Cloud SIEM Insight. When closing an insight you must also provide a resolution; omit the resolution for any other status.required insightId, status
optional resolution
sumo-logic_query_metricsQuery metrics data from Sumo Logic.required query, from, to
sumo-logic_search_logsSearch logs in Sumo Logic with a custom query. Results are limited to prevent overwhelming responses.required query, from, to
optional limit

18 tools. Connect with API key.

ToolDescriptionArguments
swimlane_create_commentAdd a comment or investigation note to a Swimlane recordrequired app_id, record_id, message
swimlane_create_recordCreate a new record in a Swimlane application using human-readable field namesrequired app_id, values
swimlane_delete_recordDelete a record from a Swimlane application by IDrequired app_id, record_id
swimlane_execute_taskTrigger a Swimlane orchestration task to run immediately (e.g., enrichment, response action)required task_id
swimlane_find_record_by_fieldFind records in a Swimlane application whose named field matches a value (e.g. find the record where ‘Client Name’ is ‘Acme’).required app_id, field_name, value
optional limit
swimlane_get_appGet a single Swimlane application by id, name, or acronym, including its full field schema (the UI layout tree is omitted for size).required query
swimlane_get_groupGet a single Swimlane group by ID or namerequired query
swimlane_get_recordGet a single Swimlane record by record_id OR tracking_id (e.g. ‘INC-42’), never both. app_id must be the application’s internal id — resolve a name or acronym with get_app first.required app_id
optional record_id, tracking_id
swimlane_get_taskGet an orchestration task (automation step) by ID, including status and metadatarequired task_id
swimlane_get_userGet a single Swimlane user by display name or username. Use swimlane_search_users to discover users first, then look up by their displayName or userName. Swimlane user IDs cannot be used for direct lookup.required query
swimlane_get_workflowGet a Swimlane workflow/playbook definition by ID (read-only, for triage context). Requires application admin permissions — the personal access token must belong to a user with the Administration role on the workflow’s parent application.required workflow_id
swimlane_list_appsList Swimlane applications (form definitions) as compact summaries: id, name, acronym, description, field count, dates. Use get_app for one app’s full field schema — the summaries deliberately omit it.optional cursor, limit
swimlane_list_attachmentsList file attachment metadata on a Swimlane record (no file content)required app_id, record_id
swimlane_list_commentsList comments and investigation notes on a Swimlane recordrequired app_id, record_id
swimlane_list_groupsList all Swimlane user groups—
swimlane_list_recordsList records in a Swimlane application with field names resolved to human-readable labelsrequired app_id
optional limit
swimlane_search_usersSearch Swimlane users by display name. Provide a partial name to search (e.g. ‘admin’). Wildcards like ’*’ are not supported. To list all users, pass an empty string.required query
swimlane_update_recordUpdate fields on an existing Swimlane record using human-readable field names.required app_id, values
optional record_id, tracking_id

24 tools. Available as 2 connections: ThreatConnect (API key), ThreatConnect (HMAC) (credentials in connection settings).

ToolDescriptionArguments
threatconnect_create_associationCreate an association between two ThreatConnect objects. Links indicators to groups, groups to cases, indicators to cases, etc. Source and target types can be: indicators, groups, or cases.required source_type, source_id, target_type, target_id
optional owner
threatconnect_create_caseCreate a new incident response case with name, status (Open/Closed), severity (Low/Medium/High/Critical), and optional assignee.required name, status, severity
optional assignee, description, tags
threatconnect_create_groupCreate a new group (Incident, Adversary, Campaign, Threat, Malware, Document, Report, etc.) with optional tags and status.required group_type, name
optional event_date, owner, status, tags
threatconnect_create_indicatorCreate a new threat indicator. Supports Address (IP), Host (domain), File (hash), URL, EmailAddress, ASN, CIDR, Mutex, and more. Set confidence (0-100) and rating (1.0-5.0) for threat scoring.required indicator_type
optional active, address, confidence, host_name, ip, md5, owner, rating, sha1, sha256, summary, tags, text
threatconnect_create_tagCreate a new tag for organizing indicators, groups, and cases.required name
threatconnect_create_taskCreate a new task within a case. Specify case ID, name, and optionally an assignee, due date, and status.required name, case_id
optional assignee, description, due_date, status
threatconnect_delete_groupDelete a group by ID.required group_id
threatconnect_delete_indicatorDelete a threat indicator by numeric ID or summary value.required indicator_id
optional owner
threatconnect_get_caseGet a single case by ID with full details including tasks, artifacts, and notes.required case_id
optional fields
threatconnect_get_groupGet a single group by ID with full details including associations, tags, and attributes.required group_id
optional fields
threatconnect_get_indicatorGet a single indicator by numeric ID or summary value (IP address, hostname, file hash, URL, email address).required indicator_id
optional fields, owner
threatconnect_get_victimGet a single victim by ID with details including assets and associations.required victim_id
optional fields
threatconnect_list_casesList incident response cases with optional TQL filtering by status, severity, assignee, and date range.optional fields, owner, result_limit, result_start, tql
threatconnect_list_groupsList threat intelligence groups (Incidents, Adversaries, Campaigns, Threats, Malware, etc.) with optional TQL filtering.optional fields, group_type, owner, result_limit, result_start, tql
threatconnect_list_indicatorsList threat indicators (IOCs) with optional TQL filtering. Supports filtering by type (Address, Host, File, URL, etc.), rating, confidence, date range, and owner.optional fields, indicator_type, owner, result_limit, result_start, tql
threatconnect_list_ownersList accessible organizations and communities (owners). Owners represent data partitions for threat intelligence sharing.optional result_limit, result_start
threatconnect_list_security_labelsList security labels (e.g., TLP:RED, TLP:GREEN) used for classification and access control.optional owner, result_limit, result_start, tql
threatconnect_list_tagsList tags with optional TQL filtering and owner scoping.optional owner, result_limit, result_start, tql
threatconnect_list_tasksList tasks with optional TQL filtering by case, status, and assignee.optional owner, result_limit, result_start, tql
threatconnect_list_victimsList victims with optional TQL filtering. Victims represent targeted entities (people, organizations) in threat scenarios.optional fields, owner, result_limit, result_start, tql
threatconnect_update_caseUpdate an existing case’s status, severity, resolution, assignee, description, or tags.required case_id
optional assignee, description, name, resolution, severity, status, tags
threatconnect_update_groupUpdate an existing group’s name, status, or tags.required group_id
optional name, status, tags
threatconnect_update_indicatorUpdate an existing indicator’s confidence, rating, active status, or tags. Identify the indicator by numeric ID or summary value.required indicator_id
optional active, confidence, owner, rating, tags
threatconnect_update_taskUpdate a task’s name, status, assignee, due date, or description.required task_id
optional assignee, description, due_date, name, status

13 tools. Connect with Basic auth.

ToolDescriptionArguments
trellix-hx_get_alertGet full details for a specific Trellix HX alert by numeric ID. Returns the matched indicator, condition, event type, event values (process command lines, file hashes, network connections), timestamps, and resolution status.required alert_id
trellix-hx_get_alert_groupGet details for a specific Trellix HX alert group (correlated incident). Returns the assessment summary, source, first/last event timestamps, acknowledgement status, and event statistics. Required role: api_analyst.required group_id
trellix-hx_get_hostGet full details for a specific Trellix HX managed endpoint by agent ID. Returns OS information, agent version, check-in timestamps, containment state, and alert statistics. Required role: api_analyst.required agent_id
trellix-hx_get_host_containmentGet the containment status and history for a specific Trellix HX host. Returns state (normal/contain/containing/releasing/contain_fail/release_fail), timestamps, requesting actor, and containing actor. Required role: api_analyst.required agent_id
trellix-hx_get_indicatorGet details for a specific Trellix HX indicator (IOC), optionally including match conditions (file hashes, registry keys, network IOCs, process names, etc.) when include_conditions=true (the default).required category_uri_name, indicator_uri_name
optional include_conditions
trellix-hx_get_search_resultsRetrieve match results (hits) from a Trellix HX enterprise search.required search_id
optional limit, offset
trellix-hx_list_alert_groupsList correlated alert groups (incidents) in Trellix HX. Alert groups correlate multiple related raw alerts into a single incident with an assessment summary.optional limit, offset
trellix-hx_list_alertsList security alerts from Trellix HX with optional filtering. Returns alert ID, matched indicator, event type, timestamps, source, resolution status, and event values (command lines, file hashes, etc.).optional host_id, limit, offset, reported_after, resolution, source
trellix-hx_list_file_acquisitionsList file acquisition jobs in Trellix HX. File acquisitions collect specific files from endpoints for forensic analysis. Returns acquisition ID, requested file path and name, state, MD5 hash, and associated host.optional host_id, limit, offset
trellix-hx_list_hostsList managed endpoint hosts in Trellix HX with optional filtering. Returns agent ID, hostname, IP address, OS, agent version, containment state, last check-in timestamps, and alert counts. Required role: api_analyst.optional containment_state, has_active_threats, has_alerts, hostname, ip_address, limit, offset, os_platform, search
trellix-hx_list_indicatorsList threat indicators (IOCs) configured in the Trellix HX appliance. Returns indicator ID, name, category, platforms, active-since date, and statistics (alerted agents, active conditions). Required role: api_analyst.optional category, has_alerts, limit, offset, search_term
trellix-hx_list_searchesList enterprise IOC sweep searches in Trellix HX. Enterprise searches perform asynchronous IOC sweeps across host sets. Returns search ID, state (RUNNING/COMPLETE/STOPPED/FAILED), host set, creation actor, and settings.optional host_set_id, limit, offset, state
trellix-hx_list_triage_acquisitionsList triage acquisition jobs in Trellix HX. Triage acquisitions collect endpoint triage packages for forensic analysis. Returns acquisition ID, state, host, request actor, timestamps, and any associated indicator.optional host_id, limit, offset, state

23 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
vectra-ai_create_assignmentCreate new assignment.required assignment_data
vectra-ai_create_entity_noteAdd an investigation note to an entity (host or account). Returns: str: Confirmation message with note details.required entity_id, entity_type, note
vectra-ai_delete_assignmentGet specific assignment by ID.required assignment_id
vectra-ai_get_account_detailsGet complete detailed information about a specific account entity. This tool returns account details including detections, scoring information, associated accounts, access history, detection summaries, external data, and more.required account_id
optional exclude_fields, fields, include_access_history, include_detection_summaries, include_external, src_linked_account
vectra-ai_get_assignment_detail_by_idRetrieve details of a specific investigation assignment. Returns: str: JSON string with details of the assignment. Raises: Exception: If fetching assignment details fails.required assignment_id
vectra-ai_get_assignment_for_entityRetrieve investigation assignment for a specific account. Returns: str: JSON string with assignment details for the account. Raises: Exception: If fetching assignment fails.required entity_ids, entity_type
vectra-ai_get_detection_countGet the total count of detections matching the specified criteria. Returns: str: Count of detections matching the criteria.optional detection_category, detection_name, end_date, is_targeting_key_asset, src_ip, start_date, state
vectra-ai_get_detection_detailsGet complete detailed information for a particular detection. Returns: str: JSON string with detection details. Raises: Exception: If fetching detection details fails.required detection_id
vectra-ai_get_detection_pcapGet Vectra Match statistics.required detection_id
vectra-ai_get_detection_summaryGet a concise summary of a detection including its ID, name, category, last timestamp, triage status, state, entity type, and detection summary.required detection_id
vectra-ai_get_host_detailsGet complete detailed information about a specific host entity. Returns: str: Formatted string with detailed information about the host entity.required host_id
vectra-ai_list_assignmentsList all investigation assignments with optional filtering by timestamp and resolved state. Returns: str: JSON string with list of assignments.optional created_after, resolved
vectra-ai_list_assignments_for_userList all investigation assignments assigned to a user/analyst. Returns: str: JSON string with list of assignments.required user_id
optional resolved
vectra-ai_list_detection_idsList detection IDs with filtering and sorting options. Use this to get a list of detection IDs based on various criteria. Returns: str: JSON string with list of detection IDs.optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state
vectra-ai_list_detections_with_basic_infoList detections with basic information and filtering options. Use this to get a quick overview of detections without detailed information. Returns: str: JSON string with list of detections ids.optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state
vectra-ai_list_detections_with_detailsList detections with filtering and sorting options. Use this to get a detailed list of detections based on various criteria. Returns: str: JSON string with list of detections.optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state
vectra-ai_list_entitiesList entities (hosts & accounts) in Vectra platform based on various filters. This tool returns entities with all their detailed information. Returns: str: Formatted string with list of detections.required entity_type
optional host_ip, is_prioritized, limit, name, ordering, state, tags
vectra-ai_list_entity_detectionsList all detections with full details for a specific entity. Returns: str: JSON string with list of detections for the entity.required entity_id
optional state
vectra-ai_list_lockdown_entitiesList entities that are currently in lockdown. Returns: str: JSON string with list of entities in lockdown.—
vectra-ai_list_platform_usersList users in the Vectra platform. Returns: str: JSON string with list of users.optional email, last_login_after, limit, role
vectra-ai_lookup_entity_info_by_nameRetrieve information about an entity (account or host) by its name. Search is case-insensitive and can match partial names.required entity_name
vectra-ai_lookup_host_by_ipRetrieve information about a host entity by its IP address. Returns: str: Formatted string with host information including name, ID, type, last detection timestamp, prioritization status, urgency score, state, and IP address.required host_ip
vectra-ai_mark_detection_fixedMarks or unmark detection as fixed.required detection_ids, fixed_status

7 tools. Connect with API key.

ToolDescriptionArguments
virustotal_get_analysisRetrieve the status and results of a VirusTotal analysis by its id (returned by submit_url_scan or reanalyse_file). The attributes.status field is ‘queued’, ‘in-progress’, or ‘completed’. The meta field identifies the scanned file or URL.required analysis_id
virustotal_get_domain_reportGet the VirusTotal report for a domain. Returns detection stats, reputation, WHOIS, DNS records, categories, and related certificates.required domain
virustotal_get_file_reportGet the VirusTotal analysis report for a file by its hash (MD5, SHA-1, or SHA-256). Returns antivirus detection stats, engine results, reputation, file metadata, and relationships.required file_hash
virustotal_get_ip_reportGet the VirusTotal report for an IPv4 or IPv6 address. Returns detection stats, reputation, ASN/owner, country, and related certificates.required ip_address
virustotal_get_url_reportGet the VirusTotal analysis report for a URL. Returns detection stats, engine verdicts, categories, and reputation. Raises a not-found error if the URL has never been submitted; use submit_url_scan first to analyse a new URL.required url
virustotal_reanalyse_fileRequest a fresh VirusTotal analysis of a file already present in the dataset, identified by its hash (MD5/SHA-1/SHA-256). Returns an analysis object whose id can be polled with get_analysis to retrieve updated detection results.required file_hash
virustotal_submit_url_scanSubmit a URL to VirusTotal for scanning. Returns an analysis object whose id can be polled with get_analysis to retrieve the results once the scan completes.required url

45 tools. Connect with Basic auth.

ToolDescriptionArguments
wazuh_assign_agent_to_groupAdd an agent to a group. An agent can belong to multiple groups.required group_id, agent_id
wazuh_clear_syscheck_resultsClear all stored FIM results for an agent. The next scan will start fresh.required agent_id
wazuh_create_groupCreate a new agent group in the Wazuh manager.required group_id
wazuh_delete_agentDelete a single Wazuh agent by its ID. Refuses wildcard / multi-ID input.required agent_id
optional purge
wazuh_get_agentGet detailed information about a specific Wazuh agent by its ID (zero-padded string, e.g., ‘001’).required agent_id
wazuh_get_agent_configGet the active configuration of a specific component on a Wazuh agent.required agent_id, component, configuration
wazuh_get_agent_statsGet statistical information from a Wazuh agent daemon.required agent_id
optional component
wazuh_get_agent_summaryGet a summary of agent counts grouped by connection status (active, disconnected, never_connected, pending, total).—
wazuh_get_cdb_listGet the contents of a specific CDB list file via GET /lists/files/{filename}. Returns the file’s key/value entries — use list_cdb_lists for the metadata listing across all CDB list files.required filename
wazuh_get_cluster_healthGet a health check of the Wazuh cluster, showing node connectivity and sync status.—
wazuh_get_cluster_statusGet Wazuh cluster status (enabled/disabled, running/stopped).—
wazuh_get_decoderGet details of a specific Wazuh decoder by name.required decoder_name
wazuh_get_group_agentsList all agents that belong to a specific group.required group_id
optional limit, offset
wazuh_get_manager_infoGet Wazuh manager version, compilation date, and installation path.—
wazuh_get_manager_logsGet recent Wazuh manager log messages for troubleshooting.optional level, limit, offset, q, sort, tag
wazuh_get_manager_statsGet Wazuh manager daemon statistics (events processed, alerts generated).—
wazuh_get_manager_statusGet the status of all Wazuh manager daemons (running/stopped).—
wazuh_get_ruleGet details of a specific Wazuh rule by its numeric ID.required rule_id
wazuh_get_sca_checksGet detailed SCA check results for a specific policy on an agent, showing pass/fail status for each check.required agent_id, policy_id
optional limit, offset, q, result
wazuh_get_sca_summaryGet a high-level SCA compliance summary for an agent. Returns the list of evaluated policies with their pass/fail/score totals — same endpoint as list_sca_policies, provided as an alias for discoverability.required agent_id
wazuh_get_syscollector_hardwareGet hardware inventory information for an agent (CPU, RAM, board serial).required agent_id
wazuh_get_syscollector_osGet operating system information for an agent (OS name, version, architecture).required agent_id
wazuh_list_agentsList Wazuh agents with optional filtering by status, OS, group, or WQL query. Returns agent ID, name, IP, status, OS info, and group membership.optional group, limit, offset, q, search, sort, status
wazuh_list_cdb_listsList CDB (Constant Database) lists used for threat intelligence lookups in rules.optional filename, limit, offset, search, sort
wazuh_list_cluster_nodesList all nodes in the Wazuh cluster with their status and type (master/worker).optional limit, offset, search, sort
wazuh_list_decoder_filesList all decoder files loaded in the Wazuh manager.optional limit, offset, search, sort
wazuh_list_decodersList Wazuh decoders with optional filtering by filename or status.optional filename, limit, offset, q, search, sort, status
wazuh_list_groupsList all agent groups configured in the Wazuh manager.optional limit, offset, search, sort
wazuh_list_mitre_tacticsList MITRE ATT&CK tactics known to the Wazuh manager.optional limit, offset, q, search, sort
wazuh_list_mitre_techniquesList MITRE ATT&CK techniques known to the Wazuh manager, useful for mapping alerts to the MITRE framework.optional limit, offset, q, search, sort
wazuh_list_rule_filesList all rule files loaded in the Wazuh manager.optional limit, offset, search, sort
wazuh_list_rule_groupsList all available rule groups in the Wazuh manager.optional limit, offset, search, sort
wazuh_list_rulesList Wazuh rules with optional filtering by level, group, filename, or status.optional filename, group, level, limit, offset, q, search, sort, status
wazuh_list_sca_policiesList Security Configuration Assessment (SCA) policies evaluated on an agent, showing compliance scores.required agent_id
wazuh_list_syscheck_resultsGet File Integrity Monitoring (FIM) scan results for an agent, showing file changes detected.required agent_id
optional event_type, file, limit, offset, q, search, sort
wazuh_list_syscollector_packagesList installed packages/software on an agent with optional filtering.required agent_id
optional limit, offset, q, search, sort
wazuh_list_syscollector_portsList open network ports on an agent.required agent_id
optional limit, offset, q, sort
wazuh_list_syscollector_processesList running processes on an agent.required agent_id
optional limit, offset, q, search, sort
wazuh_remove_agent_from_groupRemove an agent from a specific group.required group_id, agent_id
wazuh_restart_agentsRestart one or more Wazuh agents by their IDs. This forces agents to reload their configuration.required agents_list
wazuh_restart_managerRestart the Wazuh manager. This will briefly interrupt agent connections.—
wazuh_run_active_responseExecute an active response command on one or more agents (e.g., block an IP, restart a service).required command, agents_list
optional alert, arguments
wazuh_run_logtestTest a log sample against the current rules and decoders. Useful for validating rule behavior before deployment.required event, log_format
optional location, token
wazuh_run_syscheck_scanTrigger a File Integrity Monitoring (FIM) scan on one or more agents.required agents_list
wazuh_upgrade_agentsUpgrade one or more Wazuh agents to the latest available version.required agents_list