Threat detection and response
Endpoint, network, and SIEM platforms an agent can query for detections, and act on to contain them. 32 integrations, 645 tools.
Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.
Abnormal Security
Section titled “Abnormal Security”19 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
abnormal-security_get_abuse_campaign | Get details of a specific abuse campaign including reported messages and threat analysis | required campaign_id |
abnormal-security_get_case | Get details of a specific account takeover case including severity, affected user, and timeline | required case_id |
abnormal-security_get_employee | Get employee information including display name, job title, VIP status, and threat history | required email_address |
abnormal-security_get_employee_identity | Get behavioral identity analysis (Genome data) for an employee from Abnormal’s AI engine | required email_address |
abnormal-security_get_threat | Get full details of a specific threat including messages, attack type, sender info, and remediation status | required threat_id |
abnormal-security_get_threat_action_status | Check the status of an async threat remediation action | required threat_id, action_id |
abnormal-security_get_vendor_details | Get vendor risk details, domain information, and risk score for a specific vendor domain | required vendor_domain |
abnormal-security_list_abuse_campaigns | List reported phishing and abuse campaigns from the AI Security Mailbox | optional filter_query, page_number, page_size |
abnormal-security_list_audit_logs | List portal audit logs with filtering by action type, category, and time range (max 90 days) | optional action, category, filter_query, page_number, page_size |
abnormal-security_list_cases | List account takeover (ATO) cases with time range filtering. Requires Account Takeover license. | optional filter_query, page_number, page_size |
abnormal-security_list_detection_reports | List Detection 360 misclassification reports (missed attacks and false positives) | optional filter_query, page_number, page_size |
abnormal-security_list_threats | List detected email threats with filtering by time range, attack type, sender, recipient, and detection source | optional attack_strategy, attack_type, attack_vector, filter_query, page_number, page_size, recipient, sender, source, subject |
abnormal-security_list_vendor_cases | List vendor-related compromise cases detected by Abnormal Security | optional filter_query, page_number, page_size |
abnormal-security_list_vendors | List vendors monitored by Abnormal Security with time range filtering | optional filter_query, page_number, page_size |
abnormal-security_manage_case | Update the status of an account takeover case (acknowledge, mark not actionable, etc.) | required case_id, action |
abnormal-security_remediate_messages | Bulk remediate email messages found via search (delete or move to a target folder) | required action, message_idsoptional remediation_reason, target_folder |
abnormal-security_remediate_threat | Remediate a threat (move messages to junk/quarantine) or unremediate (restore messages to inbox) | required threat_id, action |
abnormal-security_search_messages | Search email messages by sender, recipient, subject, and time range across Abnormal and Quarantine sources | optional end_time, filter_operator, page_number, page_size, recipient_email, sender_email, sender_name, start_time, subject |
abnormal-security_submit_detection_report | Submit a Detection 360 misclassification report for a missed attack or false positive | required inquiry_type, reported_message_idoptional description |
Akamai Guardicore
Section titled “Akamai Guardicore”16 tools. Available as 2 connections: Akamai Guardicore (Basic Auth) (Basic auth), Akamai Guardicore (Refresh Token) (API key).
| Tool | Description | Arguments |
|---|---|---|
akamai-guardicore_get_asset | Search for a single asset by ID, IP address, or hostname. Provide one of: asset_id (starts with ':vm'), ip_address, or name. Returns the first match from a fuzzy search. | optional asset_id, ip_address, name |
akamai-guardicore_get_asset_by_id | Get full details of a specific asset by its unique UUID (e.g., ‘33d2f2e8-6221-4c87-bae1-52ca509ffe91’). Returns complete asset data including IPs, agent details, labels, orchestration info, and metadata. | required asset_id |
akamai-guardicore_get_connection_trends | Get aggregated network connection graph data grouped by label dimensions. Requires a saved map ID (use list_saved_maps to find one). Computes connection patterns between asset groups over a time range using the Reveal visibility graph. | required saved_map_id, from_time, to_timeoptional group_by |
akamai-guardicore_get_incident | Get detailed information about a specific security incident by ID. Returns full incident data including affected assets, events, tags, recommendations, severity, and policy violations. | required incident_id |
akamai-guardicore_get_label | Get detailed information about a specific visibility label by its ID. Returns the label definition including key, value, criteria, and associated assets. | required label_id |
akamai-guardicore_get_label_group | Get detailed information about a specific label group by its ID. | required group_id |
akamai-guardicore_get_network_connections | Retrieve network connection data for visibility into traffic between assets. Filter by time range, source, and destination IP. Shows process-level communication details. | required from_time, to_timeoptional destination, limit, offset, source |
akamai-guardicore_list_agents | List installed Akamai Guardicore agents across the environment. Returns agent details including status, version, hostname, and associated asset information. | optional agent_type, limit, offset, search |
akamai-guardicore_list_assets | Search and list assets (endpoints/VMs) in the Akamai Guardicore environment. Filter by IP address, hostname, or search string. Returns asset details including IPs, status, labels, and metadata. | optional limit, offset, search |
akamai-guardicore_list_incidents | List security incidents within a time range. Filter by severity (Low/Medium/High), incident type, source, destination, or tag. Returns incident summaries with affected assets, timing, and severity. | required from_time, to_timeoptional destination, incident_type, limit, offset, severity, source, tag |
akamai-guardicore_list_label_groups | List all label groups used for organizing labels into higher-level groupings. Label groups define segmentation boundaries and policy scopes. | optional limit, offset |
akamai-guardicore_list_labels | List all visibility labels used for organizing assets into logical groupings such as geographical areas, business units, applications, and roles. | optional limit, offset |
akamai-guardicore_list_policy_rules | List segmentation policy rules in the Akamai Guardicore environment. Filter by asset ID to see rules affecting a specific asset. Returns rule definitions including source/destination criteria, actions, and associated labels. | optional asset_id, limit, offset, search |
akamai-guardicore_list_projects | List segmentation projects in the Akamai Guardicore environment. Projects organize segmentation policies and rules into logical groupings. | optional limit, offset |
akamai-guardicore_list_saved_maps | List saved network visibility maps from the Reveal section. Excludes futile and incident-type maps. Returns map definitions including name, filters, time ranges, and layout configurations. | optional limit, offset |
akamai-guardicore_manage_label | Add a label to assets or delete an existing label. Use action=‘add’ with asset_ids to assign a label to specific assets, or action=‘delete’ to permanently remove a label definition (affecting all assets). | required action, label_key, label_valueoptional asset_ids |
AWS GuardDuty
Section titled “AWS GuardDuty”53 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
aws-guardduty_accept_administrator_invitation | Accept a GuardDuty administrator invitation from a member account. Requires the detector ID, administrator account ID, and invitation ID. | required detector_id, administrator_id, invitation_id |
aws-guardduty_archive_findings | Archive AWS GuardDuty findings to suppress them from the active findings list. Archived findings are retained and can be retrieved with archived=true filter, but are hidden from the default view. | required detector_id, finding_ids |
aws-guardduty_create_filter | Create a new finding filter for a GuardDuty detector. Filters can auto-archive findings matching specific criteria (e.g., low severity, specific finding types, or certain resource types). | required detector_id, name, finding_criteriaoptional action, description, rank |
aws-guardduty_create_members | Add AWS accounts as GuardDuty member accounts. Provide account IDs and emails. After creating members, you must invite them and they must accept. | required detector_id, account_details |
aws-guardduty_create_sample_findings | Generate sample AWS GuardDuty findings for testing and validation purposes. Sample findings simulate real GuardDuty findings and can be used to test alerting pipelines, verify integrations, and explore finding formats. | required detector_idoptional finding_types |
aws-guardduty_decline_invitations | Decline GuardDuty membership invitations from administrator accounts. Provide the account IDs of the administrators whose invitations to decline. | required account_ids |
aws-guardduty_delete_detector | Delete a GuardDuty detector. WARNING: This stops ALL GuardDuty monitoring in this region and deletes all findings. This action is irreversible. | required detector_id |
aws-guardduty_delete_filter | Delete a GuardDuty finding filter by name. Findings previously suppressed by this filter will no longer be auto-archived. | required detector_id, filter_name |
aws-guardduty_delete_invitations | Delete GuardDuty membership invitations. Removes the invitation records for the specified administrator accounts. | required account_ids |
aws-guardduty_delete_ip_set | Delete a GuardDuty IP set. The trusted IP list will no longer suppress findings for those IPs. | required detector_id, ip_set_id |
aws-guardduty_delete_malware_protection_plan | Delete a GuardDuty malware protection plan. S3 objects will no longer be scanned for malware under this plan. | required malware_protection_plan_id |
aws-guardduty_delete_members | Remove AWS accounts from GuardDuty membership. The accounts will no longer be monitored by the administrator. | required detector_id, account_ids |
aws-guardduty_delete_publishing_destination | Delete a GuardDuty publishing destination. Findings will no longer be exported to this destination. | required detector_id, destination_id |
aws-guardduty_delete_threat_intel_set | Delete a GuardDuty threat intelligence set. The threat intel data will no longer be used for detection. | required detector_id, threat_intel_set_id |
aws-guardduty_describe_malware_scans | Describe GuardDuty malware scan results with optional filtering. Returns scan details including status, resource scanned, threats found, scan start/end times, and trigger type. Useful for malware incident response. | required detector_idoptional filter_criteria, max_results, next_token, sort_criteria |
aws-guardduty_describe_publishing_destination | Get details for a specific GuardDuty publishing destination, including its type (S3), status, destination ARN, KMS key ARN, and publishing failure information if applicable. | required detector_id, destination_id |
aws-guardduty_disassociate_members | Disassociate member accounts from the GuardDuty administrator. The member accounts remain but are no longer actively monitored. | required detector_id, account_ids |
aws-guardduty_get_administrator_account | Get the GuardDuty administrator account for a member detector. In multi-account setups, returns the administrator account ID, invitation ID, and relationship status. | required detector_id |
aws-guardduty_get_coverage_statistics | Get aggregated GuardDuty coverage statistics showing resource counts by coverage status and resource type. Provides a quick overview of monitoring coverage without listing individual resources. | required detector_id, statistics_typeoptional filter_criteria |
aws-guardduty_get_detector | Get configuration details for a specific AWS GuardDuty detector, including its status (ENABLED/DISABLED), data sources configuration (CloudTrail, DNS logs, VPC Flow Logs, S3, EKS, Malware Protection), finding publishing frequency, and… | required detector_id |
aws-guardduty_get_filter | Get details for a specific GuardDuty finding filter, including its name, action (NOOP or ARCHIVE), description, rank, and finding criteria. Filters define rules for auto-archiving or suppressing findings. | required detector_id, filter_name |
aws-guardduty_get_findings | Retrieve comprehensive details for specific AWS GuardDuty findings by ID. | required detector_id, finding_ids |
aws-guardduty_get_findings_statistics | Get aggregated statistics about AWS GuardDuty findings, counting findings by severity level (LOW, MEDIUM, HIGH, CRITICAL). Useful for dashboards and getting a quick overview of the security posture without fetching all findings. | required detector_idoptional finding_criteria |
aws-guardduty_get_invitations_count | Get the count of pending GuardDuty membership invitations for the current account. | — |
aws-guardduty_get_ip_set | Get details for a specific AWS GuardDuty IP set, including its name, format (TXT, STIX, etc.), S3 location, and activation status. IP sets contain trusted IP addresses that suppress findings. | required detector_id, ip_set_id |
aws-guardduty_get_malware_protection_plan | Get details for a specific GuardDuty malware protection plan, including protected resource configuration, actions on malware detection, and plan status. | required malware_protection_plan_id |
aws-guardduty_get_malware_scan | Get details for a specific GuardDuty malware scan by scan ID, including status, resource scanned, timing, and scan results. | required scan_id |
aws-guardduty_get_malware_scan_settings | Get the malware scan settings for a GuardDuty detector, including EBS snapshot preservation settings and scan resource inclusion/exclusion tags. Shows how malware protection is configured for the detector. | required detector_id |
aws-guardduty_get_members | Get details for specific GuardDuty member accounts by AWS account ID. Returns member account information including email, relationship status, invitation timestamp, and detector ID. | required detector_id, account_ids |
aws-guardduty_get_remaining_free_trial_days | Get the remaining free trial days for GuardDuty data sources. Shows how many free trial days remain for each feature/data source per account. Useful for cost planning. | required detector_id, account_ids |
aws-guardduty_get_threat_intel_set | Get details for a specific AWS GuardDuty threat intelligence set, including its name, format, location (S3 URL), and activation status. Threat intel sets contain known malicious IP addresses used for detection. | required detector_id, threat_intel_set_id |
aws-guardduty_get_usage_statistics | Get GuardDuty usage statistics for cost monitoring and capacity planning. Returns usage data grouped by account, data source, resource, or features. Useful for understanding GuardDuty costs and data volumes. | required detector_id, usage_statistic_typeoptional max_results, next_token, usage_criteria |
aws-guardduty_invite_members | Send GuardDuty membership invitations to AWS accounts. The accounts must first be added with create_members. Optionally include a custom message and disable email notifications. | required detector_id, account_idsoptional disable_email_notification, message |
aws-guardduty_list_coverage | List GuardDuty coverage details showing which resources are being monitored and their coverage status. Helps identify gaps in monitoring across EC2, ECS, EKS clusters, and other AWS resources. | required detector_idoptional filter_criteria, max_results, next_token, sort_criteria |
aws-guardduty_list_detectors | List all AWS GuardDuty detector IDs in the configured region. A detector is the GuardDuty service instance that monitors your AWS environment. Most accounts have one detector per region. | optional max_results, next_token |
aws-guardduty_list_filters | List all finding filter names for a GuardDuty detector. Filters auto-archive or suppress findings matching specific criteria. Returns filter names to use with get_filter for details. | required detector_idoptional max_results, next_token |
aws-guardduty_list_findings | List AWS GuardDuty finding IDs with optional filters by severity, finding type, resource type, and archived status. Returns paginated finding IDs — pass them to get_findings to retrieve full details. | required detector_idoptional archived, finding_type, max_results, next_token, resource_type, severity_min, sort_by, sort_order |
aws-guardduty_list_invitations | List all GuardDuty membership invitations sent to the current account. Returns invitation details including sender account, status, and timestamp. | optional max_results, next_token |
aws-guardduty_list_ip_sets | List all IP set IDs associated with a GuardDuty detector. IP sets are lists of trusted or known malicious IP addresses used by GuardDuty for detection. Returns IDs to use with get_ip_set for details. | required detector_idoptional max_results, next_token |
aws-guardduty_list_malware_protection_plans | List all GuardDuty malware protection plans. Malware protection plans define which S3 buckets are scanned for malware when new objects are uploaded. | optional next_token |
aws-guardduty_list_malware_scans | List GuardDuty malware scans across the account with optional filtering and sorting. This API is account-scoped and does not take detector_id. | optional filter_criteria, max_results, next_token, sort_criteria |
aws-guardduty_list_members | List member accounts associated with a GuardDuty administrator detector. In multi-account setups, this shows all member accounts being monitored. Returns account details including relationship status. | required detector_idoptional max_results, next_token, only_associated |
aws-guardduty_list_publishing_destinations | List publishing destinations configured for a GuardDuty detector. Publishing destinations are S3 buckets where GuardDuty exports findings. Returns destination IDs, types, and status. | required detector_idoptional max_results, next_token |
aws-guardduty_list_tags_for_resource | List tags associated with a GuardDuty resource (detector, filter, IP set, threat intel set). Provide the resource ARN. Returns key-value tag pairs. | required resource_arn |
aws-guardduty_list_threat_intel_sets | List all threat intelligence set IDs associated with a GuardDuty detector. Threat intel sets are custom lists of known malicious IP addresses that GuardDuty uses to generate findings. Returns IDs to use with get_threat_intel_set. | required detector_idoptional max_results, next_token |
aws-guardduty_start_monitoring_members | Re-enable GuardDuty monitoring for member accounts that were previously stopped. Findings will resume being generated. | required detector_id, account_ids |
aws-guardduty_stop_monitoring_members | Stop GuardDuty monitoring for specific member accounts. Findings will no longer be generated for these accounts. | required detector_id, account_ids |
aws-guardduty_tag_resource | Add tags to a GuardDuty resource. Tags are key-value pairs used for resource organization, cost allocation, and access control. Provide the resource ARN and a dict of tag key-value pairs. | required resource_arn, tags |
aws-guardduty_unarchive_findings | Unarchive previously archived AWS GuardDuty findings, restoring them to the active findings list. Use when a finding was incorrectly archived or requires further investigation. | required detector_id, finding_ids |
aws-guardduty_untag_resource | Remove tags from a GuardDuty resource by tag key. Provide the resource ARN and a list of tag keys to remove. | required resource_arn, tag_keys |
aws-guardduty_update_detector | Update a GuardDuty detector’s configuration. Can enable/disable the detector or change finding publishing frequency. Disabling a detector stops GuardDuty monitoring in that region. | required detector_idoptional enable, finding_publishing_frequency |
aws-guardduty_update_filter | Update an existing GuardDuty finding filter. You can change the action, description, rank, or finding criteria. Use this to adjust suppression rules as your security posture evolves. | required detector_id, filter_nameoptional action, description, finding_criteria, rank |
aws-guardduty_update_findings_feedback | Submit feedback on AWS GuardDuty findings to indicate whether they are USEFUL (true positives) or NOT_USEFUL (false positives). This feedback helps AWS improve GuardDuty’s machine learning models. | required detector_id, finding_ids, feedbackoptional comments |
AWS Security
Section titled “AWS Security”10 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
aws-security_analyze_iam_access | — | optional cursor, include_inherited, limit, principal, resource |
aws-security_apply_remediation | — | required resource, actionoptional apply_immediately, certificate_arn, confirm, dry_run, enabled, port, rotation_lambda_arn, security_group_ids |
aws-security_aws_api_request | — | required service, actionoptional account, confirm, dry_run, max_items, parameters, query, region |
aws-security_delete_resource | — | required resourceoptional confirm, dry_run, final_snapshot_id, force_empty_bucket, recovery_window_days, skip_final_snapshot, url_config_only |
aws-security_find_public_exposure | — | optional accounts, cursor, limit, regions, severity |
aws-security_get_resource | — | required resource_idoptional include |
aws-security_list_accounts | — | — |
aws-security_list_resources | — | optional accounts, cursor, limit, public_only, regions, services |
aws-security_modify_network_access | — | required resource, actionoptional cidr, confirm, dry_run, ports, protocol |
aws-security_set_policy | — | required resource, actionoptional confirm, dry_run, policy, policy_arn, policy_name, statement_id |
Cisco Secure Network Analytics
Section titled “Cisco Secure Network Analytics”13 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
cisco-secure-network-analytics_create_host_group | Create a new host group (tag) in Cisco SNA. Host groups organize IP address ranges for traffic analysis and alarm scoping. | required name, parent_id, rangesoptional description, location, tenant_id |
cisco-secure-network-analytics_get_alarm_associated_flows | Retrieve the constituent network flows that triggered a multi-peer SNA alarm. Available on SNA 7.5.3 and later. Returns 404 with a version hint on older Managers. | required alarm_idoptional max_records, tenant_id |
cisco-secure-network-analytics_get_flow_query_results | Fetch the results of a completed SNA flow query job. Use after search_flows returns TIMEOUT, or to re-fetch results for a job that previously completed. The job must be in COMPLETED state. | required job_idoptional tenant_id |
cisco-secure-network-analytics_get_flow_query_status | Return the current status of an async SNA flow query job. Possible statuses: QUEUED, IN_PROGRESS, COMPLETED, FAILED. Use after search_flows returns a TIMEOUT response. | required job_idoptional tenant_id |
cisco-secure-network-analytics_list_flow_exporters | List NetFlow/IPFIX exporters feeding this SNA Manager, including health status, exporter IP, and last-seen timestamp. Use this to answer ‘is this network device sending flow data?’ or to diagnose gaps in flow coverage. | optional tenant_id |
cisco-secure-network-analytics_list_host_groups | List host groups (called ‘tags’ in the SNA REST API, ‘host groups’ in the UI) for a given scope. | optional scope, shape, tenant_id |
cisco-secure-network-analytics_list_security_event_types | List all security event type templates available on this SNA Manager. | optional tenant_id |
cisco-secure-network-analytics_list_tenants | List all tenants (also called domains) visible to the authenticated user on this Cisco Secure Network Analytics Manager. Most enterprise deployments have a single tenant. | optional tenant_id |
cisco-secure-network-analytics_render_security_event_details | Substitute event-specific field values (baseline, tolerance, threshold, etc.) into a security event type template to produce a human-readable description of why the event fired. | required template_id, fieldsoptional tenant_id |
cisco-secure-network-analytics_search_flows | Search network flows on Cisco SNA using an async query job. Starts a flow query, polls for completion (up to 90 s), and returns results. | required start_time, end_timeoptional application_id, host_group_id, record_limit, source_ip, target_ip, tenant_id |
cisco-secure-network-analytics_search_security_events | Search Cisco SNA security events (alarms) using an async query job. Starts the job, polls for completion (up to 90 s), and returns results. | required start_time, end_timeoptional alarm_category_id, host_ips, security_event_type_ids, tenant_id |
cisco-secure-network-analytics_top_traffic_report | Generate a top-N traffic report for a Cisco SNA tenant. Aggregates traffic across the specified dimension and returns the top results. | required dimension, start_time, end_timeoptional host_group_id, limit, tenant_id |
cisco-secure-network-analytics_update_host_group | Update an existing host group (tag) in Cisco SNA. SNA’s PUT is a full replace — this tool fetches the current host group, merges your changes, and PUTs back, so you only need to specify what you want to change. | required host_group_idoptional description, name, ranges, ranges_action, tenant_id |
Cofense Triage
Section titled “Cofense Triage”17 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
cofense-triage_add_report_comment | Add an analyst comment to a report. Comments create an auditable trail of investigation activities, findings, and decisions. Requires Triage Operator role or higher. | required reportId, bodyoptional bodyFormat, tags |
cofense-triage_categorize_report | Categorize or re-categorize a phishing report. This is a critical operation that classifies the report and may trigger automated workflows (notifications, integrations, metrics). Requires Triage Operator role or higher. | required reportId, categoryIdoptional categorizationTags, outboundTemplateId |
cofense-triage_download_attachment | Download a specific attachment file from a report. Returns base64-encoded binary data with filename and content type. Use with caution - attachments may contain malware. Consider downloading in a sandboxed environment. | required attachmentId |
cofense-triage_download_attachment_payload | Download the raw payload content (binary data as base64). This represents the actual file content shared across potentially multiple attachments with the same hash. | required payloadId |
cofense-triage_download_report_original | Download the original email in RFC822 (.eml) format. Returns the complete email source including all headers, body, and MIME parts as base64-encoded data. Useful for forensic analysis or forwarding to external tools. | required reportId |
cofense-triage_download_report_preview | Download a rendered preview image of the email (PNG or JPG format). Returns base64-encoded image data. Useful for quick visual triage without opening the original email. | required reportIdoptional format |
cofense-triage_get_attachment_payload | Get payload metadata including file hashes (MD5, SHA256), MIME type, and risk score. Useful for threat intelligence lookups without downloading the actual file. | required payloadId |
cofense-triage_get_category | Get detailed information about a specific category by its ID, including name, description, color, score, and malicious flag. | required categoryId |
cofense-triage_get_report | Get detailed information about a specific phishing report by its ID. Returns the full report resource including all attributes and relationship identifiers. | required reportId |
cofense-triage_get_report_with_context | Get a comprehensive view of a report including all related context: URLs, domains, hostnames, email headers, attachments, payloads, comments, rules, threat indicators, cluster information, and categorization. | required reportIdoptional includeRelations |
cofense-triage_list_categories | List all available report categories in Triage. Categories classify reports as malicious (phishing, malware, spam) or benign (legitimate, training). Used to discover valid category IDs before categorizing reports. | optional malicious, nameContains, page, pageSize |
cofense-triage_list_headers_for_report | List all RFC-822 email headers from a report (e.g., From, To, Subject, Received, Message-ID, X-headers). Returns key-value pairs useful for analyzing email routing, authentication (SPF/DKIM/DMARC), and identifying spoofing attempts. | required reportId |
cofense-triage_list_integration_results_for_report | Aggregate all third-party security tool verdicts for URLs and files in a report. Returns integration submission results from tools like VirusTotal, sandboxes, URL reputation services, etc. | required reportIdoptional targetKinds |
cofense-triage_list_iocs_for_report | List all indicators of compromise (IOCs) extracted from a report. Returns URLs, domains, hostnames, and threat indicators in a consolidated response. | required reportId |
cofense-triage_list_report_attachments | List all attachments from a report. Returns metadata including filename, size, content type, and linkage to attachment payload (hash information). Essential for identifying suspicious files. | required reportId |
cofense-triage_list_report_comments | List all comments on a report. Comments contain analyst notes, investigation findings, and collaboration discussion. Supports pagination. | required reportIdoptional page, pageSize |
cofense-triage_list_reports | List and filter phishing reports from Cofense Triage. Supports pagination (max 200 per page), filtering by subject, sender, tags, date range, category, and priority. | optional categoryId, fromAddress, matchPriority, page, pageSize, receivedAfter, receivedBefore, sort, subjectContains, tagsAny |
CrowdStrike Falcon
Section titled “CrowdStrike Falcon”81 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
crowdstrike-falcon_aggregate_alerts | Get aggregate counts and analytics of alerts across all CrowdStrike Falconsecurity products. Provides powerful analytics for threat intelligence, trend analysis, and security metrics. | required fieldoptional aggregation_type, date_ranges, filter_query, include_hidden, interval, name, size, sort |
crowdstrike-falcon_block_identity_authentication | Block authentication for one or more CrowdStrike Falcon Identity Protection identities by creating a real-time enforcement policy rule (action BLOCK) scoped to those source users. Enforced at the domain controller by the Falcon sensor. | required rule_name, source_user_entity_idsoptional simulation_mode, trigger |
crowdstrike-falcon_create_identity_protection_policy_rule | Create a CrowdStrike Falcon Identity Protection policy rule. Defines a conditional access / risk response for identity activity. | required name, action, triggeroptional activity, destination, enabled, simulation_mode, source_endpoint, source_user |
crowdstrike-falcon_create_ioa_rule | Create a new Custom IOA rule inside an existing rule group in CrowdStrike Falcon. | required rulegroup_id, ruletype_id, name, pattern_severity, disposition_id, field_valuesoptional comment, description |
crowdstrike-falcon_create_ioa_rule_group | Create a new Custom IOA rule group in CrowdStrike Falcon. A rule group is a per-platform container that holds individual IOA rules. Create the group first, then add rules to it with create_ioa_rule. | required name, platformoptional comment, description |
crowdstrike-falcon_create_ioc | Create a custom Indicator of Compromise (IOC) in CrowdStrike Falcon. Supports IP addresses, domains, and file hashes with configurable detection/prevention actions. | required ioc_type, value, action, platformsoptional applied_globally, description, expiration, host_groups, severity, source, tags |
crowdstrike-falcon_delete_identity_protection_policy_rules | Delete one or more CrowdStrike Falcon Identity Protection policy rules by ID. This permanently removes the rules. Get rule IDs from list_identity_protection_policy_rules first. WARNING: This action is irreversible. | required ids |
crowdstrike-falcon_delete_ioc | Delete one or more custom IOCs from CrowdStrike Falcon by their IDs. This permanently removes the indicators. Get IOC IDs from list_iocs first. WARNING: This action is irreversible. | required ids |
crowdstrike-falcon_disable_identity_account | Disable an on-prem Active Directory account for a CrowdStrike Falcon Identity Protection entity, enforced through the Falcon sensor on the domain controller (no separate AD connector required). | required entity_id |
crowdstrike-falcon_find_shadow_admins | List CrowdStrike Falcon Identity Protection entities that are members of the built-in Active Directory Administrator role (BuiltinAdministratorRole). Does NOT enumerate custom, delegated, or nested-group admin roles. | optional after, limit |
crowdstrike-falcon_find_stale_accounts | Return Active-Directory-backed CrowdStrike Falcon Identity Protection USER entities with account/password age metadata (enabled state, last-update time, password last-change) so stale or dormant accounts can be identified. | optional after, limit |
crowdstrike-falcon_force_identity_password_reset | Force a password reset for a CrowdStrike Falcon Identity Protection entity’s on-prem AD account, enforced via the Falcon sensor on the domain controller. | required entity_id |
crowdstrike-falcon_get_alert_details | Get comprehensive details for specific alerts across all CrowdStrike Falconsecurity products. Returns full context including process trees, MITRE ATT&CK mappings, IOCs, device information, and threat intelligence. | required idsoptional include_hidden |
crowdstrike-falcon_get_alerts_combined | Retrieve all Alerts that match a particular FQL filter in a single API call using cursor-based pagination. Returns alerts and an ‘after’ token for the next page when more results are available. | optional after, filter_query, limit, sort |
crowdstrike-falcon_get_analysis_report | Retrieve CrowdStrike Falcon Sandbox analysis reports by ID. Returns verdict, extracted IOCs, behavioral indicators, MITRE ATT&CK mappings, and process activity. Requires the falconx-sandbox:read API scope. | required idsoptional summary |
crowdstrike-falcon_get_cloud_security_policy_details | Get detailed information for specific Cloud Security (CSPM) policy IDs, including the policy statement, remediation guidance, and current severity/enabled configuration. Get policy IDs from list_cloud_security_policies first. | required ids |
crowdstrike-falcon_get_content_update_policy_details | Get detailed configuration for specific content update policy IDs, including the ring assignment settings (ring and delay hours) per content category. Get policy IDs from list_content_update_policies first. | required ids |
crowdstrike-falcon_get_device_control_policy_details | Get detailed configuration for specific device control policy IDs, including the per-device-class enforcement actions and exceptions. Get policy IDs from list_device_control_policies first. | required ids |
crowdstrike-falcon_get_device_details | Get detailed information for specific device IDs including hardware, OS, network, and policy information | required ids |
crowdstrike-falcon_get_device_login_history | Get recent login history for devices including user sessions and authentication details | required ids |
crowdstrike-falcon_get_device_network_history | Get network address history for devices including IP and MAC address changes | required ids |
crowdstrike-falcon_get_device_online_state | Get the current online status for specific devices (online, offline, unknown) | required ids |
crowdstrike-falcon_get_environment_score | Get an environment-wide security risk score and summary (supersedes CrowdScore) computed from alert aggregations. | optional filter_query |
crowdstrike-falcon_get_identity_auth_history | Retrieve account details for a specific CrowdStrike Falcon Identity Protection identity, resolved by email or entity ID. | optional email, entity_id, limit |
crowdstrike-falcon_get_identity_protection_policy_rule_details | Get detailed configuration for specific Identity Protection policy rule IDs, including the trigger, action, simulation mode, and source/destination/activity matching criteria. Get rule IDs from list_identity_protection_policy_rules first. | required ids |
crowdstrike-falcon_get_identity_risk_scores | Return CrowdStrike Falcon Identity Protection USER entities ranked by identity risk score (highest first), with risk factors. Requires Identity Protection Entities READ and GraphQL WRITE scopes. | optional after, limit, min_severity |
crowdstrike-falcon_get_ioa_rule_details | Get full details of one or more Custom IOA rules in CrowdStrike Falcon by their IDs, including field values, disposition, pattern severity, and version. Get rule IDs from list_ioa_rules first. | required ids |
crowdstrike-falcon_get_ioa_rule_group_details | Get full details of one or more Custom IOA rule groups in CrowdStrike Falcon by their IDs, including the rules contained in each group and the group’s version (needed for subsequent updates). | required ids |
crowdstrike-falcon_get_ioa_rule_type_details | Get the full field definitions for one or more Custom IOA rule types in CrowdStrike Falcon. | required ids |
crowdstrike-falcon_get_it_automation_policy_details | Get detailed configuration for specific IT Automation policy IDs, including execution toggles (script/Python/OS Query), timeouts, and CPU / memory / concurrency resource limits. Get policy IDs from list_it_automation_policies first. | required ids |
crowdstrike-falcon_get_policy_host_counts | Get the applied, pending, and total assigned host counts for a single CrowdStrike Falcon policy. | required policy_type, policy_id |
crowdstrike-falcon_get_prevention_policy_details | Get detailed information for specific prevention policy IDs. Retrieves comprehensive prevention policy details including settings, configurations, platform information, and policy metadata. | required ids |
crowdstrike-falcon_get_response_policy_details | Get detailed configuration for specific Real Time Response policy IDs, including the per-capability settings (e.g. RealTimeResponse, RealTimeResponseAdmin, custom scripts, file uploads). Get policy IDs from list_response_policies first. | required ids |
crowdstrike-falcon_get_sensor_policy_details | Get full configuration details for specific sensor update policy IDs. Returns the complete settings block including sensor build version, channel/variant assignments, uninstall protection, and the update scheduler. | required ids |
crowdstrike-falcon_get_submission_status | Check the status of one or more CrowdStrike Falcon Sandbox submissions. Analysis typically completes within 15 minutes. Requires the falconx-sandbox:read API scope. | required ids |
crowdstrike-falcon_get_zero_trust_assessment | Get CrowdStrike Falcon Zero Trust Assessment (ZTA) posture data for one or more hosts by agent ID (AID). Returns the 1-100 security posture score the Falcon sensor computes from sensor and OS configuration. | required ids |
crowdstrike-falcon_kill_identity_sessions | Terminate active authentication sessions for a CrowdStrike Falcon Identity Protection entity, enforced via the Falcon sensor. | required entity_id |
crowdstrike-falcon_list_alerts | Query CrowdStrike Falcon alerts across all security products using FQL filters. | optional filter_query, include_hidden, limit, offset, q, sort |
crowdstrike-falcon_list_cloud_ml_policies | List CrowdStrike Falcon prevention policies along with their Cloud ML and Sensor ML machine-learning settings. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_cloud_security_policies | List CrowdStrike Falcon Cloud Security (CSPM / Falcon Horizon) policy settings. | optional cloud_platform, service |
crowdstrike-falcon_list_content_update_policies | List CrowdStrike Falcon content update policies using FQL filters. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_device_control_policies | List CrowdStrike Falcon device control (USB) policies using FQL filters. Device control policies govern how USB mass-storage and other peripheral device classes are allowed, blocked, or made read-only on endpoints. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_falcon_container_policies | List all CrowdStrike Falcon Container image assessment policies. | — |
crowdstrike-falcon_list_identity_protection_policy_rules | List CrowdStrike Falcon Identity Protection policy rules. | optional enabled, name, simulation_mode |
crowdstrike-falcon_list_ioa_platforms | List the platforms available for Custom IOA (Indicator of Attack) rule groups in CrowdStrike Falcon (e.g. ‘windows’, ‘mac’, ‘linux’). | optional limit, offset |
crowdstrike-falcon_list_ioa_rule_groups | Search and list Custom IOA rule groups in CrowdStrike Falcon with optional FQL filtering. Returns full group details including name, platform, enabled state, and the rules contained in each group. | optional filter_query, limit, offset, q, sort |
crowdstrike-falcon_list_ioa_rule_types | List the Custom IOA rule type IDs available in CrowdStrike Falcon (e.g. process creation, network connection, file creation, registry operation, domain name). Call this when building a Custom IOA rule to discover which rule types exist. | optional limit, offset |
crowdstrike-falcon_list_ioa_rules | Search and list Custom IOA rules in CrowdStrike Falcon with optional FQL filtering. Returns full rule details including name, rule type, pattern severity, disposition, field values, and enabled state. | optional filter_query, limit, offset, q, sort |
crowdstrike-falcon_list_iocs | Search and list custom IOCs (Indicators of Compromise) in CrowdStrike FalconFalcon with FQL filtering. Returns full indicator details including type, value, action, severity, and metadata. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_it_automation_policies | List CrowdStrike Falcon IT Automation policies. IT Automation policies govern how automation tasks run on hosts — script/Python/OS Query execution toggles, execution timeouts, and CPU / memory / concurrency resource limits. | optional limit, offset, platform, sort |
crowdstrike-falcon_list_policy_members | List the hosts (full device records) governed by a single CrowdStrike Falcon policy, i.e. the policy’s members. Supports prevention, sensor_update, device_control, firewall, response, and content_update policies. | required policy_type, policy_idoptional filter_query, limit, offset, sort |
crowdstrike-falcon_list_prevention_policies | List CrowdStrike Falcon prevention policies using FQL filters. Prevention policies define security settings for endpoints, including malware protection, behavioral analysis, and threat prevention configurations. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_response_policies | List CrowdStrike Falcon Real Time Response (RTR) policies using FQL filters. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_sensor_policies | List CrowdStrike Falcon sensor update policies using FQL filters. Sensor update policies control how and when CrowdStrike Falcon sensors are updated on endpoints, including version management and update scheduling. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_list_submissions | Search and list CrowdStrike Falcon Sandbox submissions with FQL filtering. Returns submission status records (state, created_timestamp, sha256, verdict, environment). | optional filter_query, limit, offset, sort |
crowdstrike-falcon_perform_host_action | Take various actions on the hosts in your environment. Contain or lift containment on a host. Hide or unhide a host. Suppress or unsuppress detections. | required action, ids |
crowdstrike-falcon_rtr_delete_session | Delete (close) a CrowdStrike Falcon RTR session by its session ID (requires real-time-response READ scope). Always close sessions when remediation is complete to free the host’s RTR slot. | required session_id |
crowdstrike-falcon_rtr_execute_admin_command | Execute a state-changing (active-responder/admin) RTR command on a host within an active session (requires Real Time Response Admin WRITE scope). Use for remediation that modifies the host. | required session_id, base_command, command_string |
crowdstrike-falcon_rtr_execute_command | Execute a read-only RTR command on a host within an active session (requires real-time-response READ scope). Use for investigation/forensics — these commands do not change host state. | required session_id, base_command, command_string |
crowdstrike-falcon_rtr_get_command_status | Poll the status and output of a previously-issued RTR command using its cloud_request_id (requires real-time-response READ scope). RTR commands are asynchronous, so this is how you retrieve results. | required cloud_request_idoptional admin, sequence_id |
crowdstrike-falcon_rtr_get_file | Retrieve a file from a host into the CrowdStrike cloud using the RTR ‘get’ command (requires Real Time Response Admin WRITE scope). Used to collect forensic artifacts (logs, malware samples) from a compromised host. | required session_id, file_path |
crowdstrike-falcon_rtr_init_session | Initialize a CrowdStrike Falcon Real Time Response (RTR) session against a single managed host (requires real-time-response READ scope). An active session is required before any RTR command can run. | required device_idoptional queue_offline |
crowdstrike-falcon_rtr_list_put_files | List the put-file IDs registered in the CrowdStrike cloud that are available to deploy with rtr_put_file (the put_file_name argument). Use this to discover valid put-files before deploying one. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_rtr_list_scripts | List the custom-script IDs available to run with rtr_run_script (the cloud_file argument). Use this to discover valid pre-approved scripts before executing one. Requires the ‘Real time response (admin): WRITE’ scope. | optional filter_query, limit, offset, sort |
crowdstrike-falcon_rtr_put_file | Upload a file (remediation tool, updated config, cleanup script) onto the remote endpoint via CrowdStrike cloud staging. | required session_idoptional comment, description, file_path, put_file_name |
crowdstrike-falcon_rtr_run_script | Run a script on a host via the RTR ‘runscript’ admin command (requires Real Time Response Admin WRITE scope). Provide exactly one of an inline script (raw_script) or the name of a previously-uploaded custom/cloud script (cloud_file). | required session_idoptional cloud_file, raw_script |
crowdstrike-falcon_search_devices | Search for devices with full details returned (combines query and details in one call) | optional filter_query, limit, offset, sort |
crowdstrike-falcon_search_ngsiem | Execute a CrowdStrike Query Language (CQL) query against CrowdStrike Next-Gen SIEM (NG-SIEM) advanced event search and return the matching event records. | required query_stringoptional end, limit, repository, start, timeout_seconds, timezone |
crowdstrike-falcon_submit_sample | Submit a sample for sandbox analysis (sha256, url, or signed source_url). | optional action_script, command_line, comment, document_password, environment_id, file_name, network_settings, sha256, source_url, submit_name, url |
crowdstrike-falcon_trigger_identity_mfa | Require multi-factor authentication for one or more CrowdStrike Falcon Identity Protection identities by creating a real-time enforcement policy rule (action MFA) scoped to those source users. | required rule_name, source_user_entity_idsoptional simulation_mode, trigger |
crowdstrike-falcon_update_alerts | Perform actions on alerts identified by composite ID(s) in the request. Actions can update status, assignments, comments, and tags. Status values are strings (new, in_progress, reopened, closed). | required idsoptional add_tags, assign_to_name, assign_to_user_id, assign_to_uuid, comment, remove_tags, remove_tags_by_prefix, status, unassign |
crowdstrike-falcon_update_cloud_ml_policy | Configure the Cloud ML and/or Sensor ML machine-learning slider levels within a CrowdStrike Falcon prevention policy. | required policy_idoptional cloud_ml_detection, cloud_ml_prevention, sensor_ml_detection, sensor_ml_prevention |
crowdstrike-falcon_update_cloud_security_policy | Update a CrowdStrike Falcon Cloud Security (CSPM) policy setting. Enable or disable the policy, override its severity, and optionally scope the change to specific cloud accounts or regions. | required policy_idoptional account_ids, enabled, regions, severity, tag_excluded |
crowdstrike-falcon_update_content_update_policy | Update a CrowdStrike Falcon content update policy. Enable or disable the entire policy and/or modify its name, description, and settings. | required policy_idoptional description, enabled, name, settings |
crowdstrike-falcon_update_device_control_policy | Update a CrowdStrike Falcon device control (USB) policy. Enable or disable the entire policy and/or modify its name, description, and settings. | required policy_idoptional description, enabled, name, settings |
crowdstrike-falcon_update_falcon_container_policy | Update a CrowdStrike Falcon Container image assessment policy. Toggle the policy on/off and/or modify its name, description, and rule set. | required policy_idoptional description, enabled, name, policy_data |
crowdstrike-falcon_update_ioc | Update an existing custom IOC in CrowdStrike Falcon. Modify the action, severity, description, expiration, platforms, source, or tags of an indicator. Get the IOC ID from list_iocs first. | required ioc_idoptional action, description, expiration, platforms, severity, source, tags |
crowdstrike-falcon_update_it_automation_policy | Update a CrowdStrike Falcon IT Automation policy. Toggle the policy on/off and/or modify its name, description, and execution config. | required policy_idoptional config, description, enabled, name |
crowdstrike-falcon_update_prevention_policy | Enable or disable entire CrowdStrike Falcon prevention POLICIES (platform-level policies like “Phase 2 - interim protection”, “Detections”) by their IDs. | required policy_idoptional description, enabled, name, settings |
crowdstrike-falcon_update_response_policy | Update a CrowdStrike Falcon Real Time Response policy. Enable or disable the entire policy and/or modify its name, description, and settings. | required policy_idoptional description, enabled, name, settings |
crowdstrike-falcon_update_sensor_policy | Update a CrowdStrike Falcon sensor update policy. Enable or disable the entire policy and/or modify its name, description, and settings (sensor build/version, update scheduler, uninstall protection, variant assignments). | required policy_idoptional description, enabled, name, settings |
Cyble Vision
Section titled “Cyble Vision”7 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
cyble-vision_add_comment_to_alert | Add a comment to a Cyble Vision alert (useful for analyst notes, triage status, or linking the alert to a ticket). | required alert_id, comment |
cyble-vision_get_cve_details | Fetch enriched details for a specific CVE from Cyble Vision’s vulnerability database — CVSS v2/v3 scores, impact metrics, affected configurations, references, and remediation context. | required cve |
cyble-vision_get_ip_attack_surface | Fetch Cyble Vision’s attack-surface profile for a single IP address tied to a company — open ports, services, certificates, tags, observed vulnerabilities, and risk score. | required company_id, ip_address |
cyble-vision_list_companies | — | — |
cyble-vision_list_security_advisories | — | optional countries, end_date, limit, order, sort_by, start_date, tags, vulnerabilities |
cyble-vision_search_alerts | — | optional end_date, exclude_status, limit, service, service_raw, severity, sort_by, sort_order, start_date, status, tagged_alert, with_data_message |
cyble-vision_search_threat_indicators | — | optional end_date, indicator_type, ioc, limit, order, sort_by, start_date |
ExtraHop RevealX 360
Section titled “ExtraHop RevealX 360”18 tools. Available as 2 connections: ExtraHop RevealX 360 (OAuth 2.0 client credentials), ExtraHop (Self-Managed) (API key).
| Tool | Description | Arguments |
|---|---|---|
extrahop_create_investigation | Create a new investigation for agent-driven case management, optionally seeding it with associated detection IDs. | required nameoptional assessment, assignee, detection_ids, notes, status |
extrahop_download_packets_to_kindo_library | Search stored packets and download the matching capture (PCAP by default) into the Kindo file library for forensic evidence. Filter by time range, IP, port, and Berkeley Packet Filter (BPF) syntax. | required from_timeoptional bpf, ip1, ip2, limit_bytes, limit_search_duration, output, port1, port2, until |
extrahop_get_detection | Get full detail for a single detection by ID, including MITRE tactics/techniques, offender/victim participants, timeline, risk score, and status. | required detection_id |
extrahop_get_device | Get full detail for a single device by its numeric ID. | required device_id |
extrahop_get_investigation | Get full detail for a single investigation, including its detections. | required investigation_id |
extrahop_list_detection_investigations | List all investigations that a specific detection has been added to. | required detection_id |
extrahop_list_detection_types | List all detection types (formats) known to the system, including display names and MITRE categories, for triage context. | — |
extrahop_list_device_activity | List the protocol activity (client/server roles) observed for a device, for network-peer and blast-radius context. | required device_id |
extrahop_list_device_group_members | List the devices that belong to a specific device group. | required device_group_idoptional active_from, active_until |
extrahop_list_device_groups | List all device groups for asset inventory and grouping context. | — |
extrahop_list_investigations | List investigations. Optionally filter by creation/update time or restrict to user-created investigations. | optional created_after, is_user_created, updated_after |
extrahop_list_related_detections | List detections related to a specific detection, for correlation. | required detection_idoptional from_time, until |
extrahop_query_metrics | Query network and protocol performance metrics for one or more objects over a time window, for anomaly and performance context. Example: metric_category=‘http_server’, metric_name=‘rsp’ for HTTP response counts. | required object_type, object_ids, metric_category, metric_name, from_timeoptional cycle, until |
extrahop_search_detections | Search ExtraHop NDR detections with filtering by time range, category, status, risk score, type, and assignee. Returns detection summaries including risk score, MITRE mapping, and participants. Requires the NDR module privilege. | optional assignee, categories, from_time, limit, offset, recommended, resolutions, risk_score_min, sort_direction, sort_field, statuses, types, until |
extrahop_search_devices | Search discovered devices by IP, MAC, role, hostname, vendor, tag, discovery ID, criticality, or activity status for asset inventory and blast-radius context. Returns matching device records. | optional active_from, active_until, discovery_id, hostname, ip, is_active, is_critical, limit, mac, name, offset, role, tag, vendor |
extrahop_search_records | Query transaction-level records (HTTP, DNS, DB, SSL/TLS, DHCP, etc.) for investigation and evidence. Filter with a simple field/operator/operand triple or a raw ExtraHop Query Language (EQL) string. | required from_timeoptional eql, filter_field, filter_operand, filter_operator, limit, offset, record_types, sort_direction, sort_field, until |
extrahop_update_detection | Update a detection’s assignee, status, resolution, or associated ticket ID. Only non-null fields are changed. Note: status ‘new’ is only accepted when third-party ticket tracking is enabled. | required detection_idoptional assignee, resolution, status, ticket_id |
extrahop_update_investigation | Update an investigation’s fields and/or associate detections with it. Note: ‘detection_ids’ REPLACES the full list of associated detections — include existing IDs to keep them. | required investigation_idoptional assessment, assignee, detection_ids, name, notes, status |
Google Cloud Security
Section titled “Google Cloud Security”10 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
google-cloud-security_analyze_iam_access | — | optional cursor, include_inherited, limit, principal, resource |
google-cloud-security_apply_remediation | — | required resource, actionoptional confirm, dry_run, enabled |
google-cloud-security_delete_resource | — | required resourceoptional confirm, dry_run, force_empty_bucket |
google-cloud-security_find_public_exposure | — | optional cursor, limit, projects, severity |
google-cloud-security_gcp_api_request | — | required service, path, methodoptional confirm, dry_run, max_items, parameters, project, query |
google-cloud-security_get_resource | — | required resource_idoptional include |
google-cloud-security_list_projects | — | — |
google-cloud-security_list_resources | — | optional cursor, limit, projects, public_only, services |
google-cloud-security_modify_network_access | — | required resource, actionoptional cidr, confirm, dry_run, ports, protocol |
google-cloud-security_set_iam_binding | — | required resource, action, member, roleoptional confirm, dry_run |
Google Security Operations
Section titled “Google Security Operations”55 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
google-secops_activate_parser | Activate a log parser in Google SecOps | required log_type, parser_id |
google-secops_create_dashboard | Create a new dashboard in Google SecOps | required nameoptional access_type, description |
google-secops_create_data_table | Create a new data table in Google SecOps | required name, headeroptional description |
google-secops_create_data_table_rows | Add rows to a data table in Google SecOps | required data_table_id, rows |
google-secops_create_feed | Create a new data feed in Google SecOps | required display_name, details |
google-secops_create_parser | Create a new log parser in Google SecOps | required log_type, parser_codeoptional validated_on_empty_logs |
google-secops_create_reference_list | Create a new reference list in Google SecOps | required name, entriesoptional content_type, description |
google-secops_create_rule | Create a new YARA-L detection rule in Google SecOps | required rule_text |
google-secops_deactivate_parser | Deactivate a log parser in Google SecOps | required log_type, parser_id |
google-secops_delete_data_table | Delete a data table in Google SecOps | required data_table_id |
google-secops_delete_rule | Delete a detection rule from Google SecOps | required rule_id |
google-secops_disable_feed | Disable a data feed in Google SecOps | required feed_id |
google-secops_enable_feed | Enable a data feed in Google SecOps | required feed_id |
google-secops_enable_rule | Enable or disable a detection rule in Google SecOps | required rule_idoptional enabled |
google-secops_get_cases | Get case details by IDs from Google SecOps | required case_ids |
google-secops_get_curated_rule | Get a specific curated detection rule by ID in Google SecOps | required rule_id |
google-secops_get_curated_rule_by_name | Search for a curated detection rule by name in Google SecOps | required name |
google-secops_get_curated_rule_set | Get details of a curated rule set in Google SecOps | required rule_set_id |
google-secops_get_dashboard | Get dashboard details in Google SecOps | required dashboard_id |
google-secops_get_data_table | Get data table details in Google SecOps | required data_table_id |
google-secops_get_feed | Get feed details in Google SecOps | required feed_id |
google-secops_get_log_types | List all available log types in Google SecOps | — |
google-secops_get_parser | Get parser details in Google SecOps | required log_type, parser_id |
google-secops_get_reference_list | Get reference list details in Google SecOps | required reference_list_idoptional view |
google-secops_get_rule | Get a specific detection rule from Google SecOps | required rule_id |
google-secops_get_security_alerts | Retrieve security alerts from Google SecOps within a time range | required start_time, end_timeoptional max_alerts |
google-secops_get_stats | Get statistics for a UDM query in Google SecOps | required query, start_time, end_timeoptional max_events |
google-secops_get_threat_intel | AI-powered threat intelligence query using Google SecOps Gemini | required query |
google-secops_ingest_log | Ingest a raw log entry into Google SecOps | required log_type, log_message |
google-secops_ingest_udm_events | Ingest UDM-formatted events into Google SecOps | required udm_events |
google-secops_list_curated_rule_sets | List curated rule set collections in Google SecOps | optional page_size, page_token |
google-secops_list_curated_rules | List pre-built curated detection rules in Google SecOps | optional page_size, page_token |
google-secops_list_dashboards | List all dashboards in Google SecOps | optional page_size |
google-secops_list_data_tables | List all data tables in Google SecOps | — |
google-secops_list_feeds | List all data feeds in Google SecOps | optional page_size, page_token |
google-secops_list_iocs | List Indicator of Compromise (IOC) matches from Google SecOps | required start_time, end_timeoptional max_matches |
google-secops_list_parsers | List parsers for a specific log type in Google SecOps | required log_type |
google-secops_list_reference_lists | List all reference lists in Google SecOps | optional view |
google-secops_list_rule_detections | List detections generated by a specific rule in Google SecOps | required rule_id, start_time, end_time |
google-secops_list_rule_errors | List execution errors for a detection rule in Google SecOps | required rule_id |
google-secops_list_security_rules | List all detection rules in Google SecOps | optional page_size, page_token |
google-secops_run_parser | Test a parser against sample logs in Google SecOps | required log_type, parser_code, logsoptional parse_statedump, parser_extension_code, statedump_allowed |
google-secops_search_curated_detections | Find detections generated by a curated rule in Google SecOps | required rule_id, start_time, end_time |
google-secops_search_rule_alerts | Search for rule-based alerts in Google SecOps | required start_time, end_time |
google-secops_search_rules | Search detection rules by regex pattern in Google SecOps | required query |
google-secops_search_security_events | Search security events using natural language in Google SecOps | required text, start_time, end_timeoptional max_events |
google-secops_search_udm | Search security events using UDM (Unified Data Model) query language in Google SecOps | required query, start_time, end_timeoptional max_events |
google-secops_summarize_entity | Get an entity summary with alerts and prevalence data from Google SecOps | required value, start_time, end_time |
google-secops_translate_nl_to_udm | Translate natural language text to a UDM query in Google SecOps | required text |
google-secops_update_curated_rule_set_deployment | Enable or disable a curated rule set deployment in Google SecOps | required category_id, rule_set_id, precision, enabledoptional alerting |
google-secops_update_feed | Update feed configuration in Google SecOps | required feed_idoptional details, display_name |
google-secops_update_reference_list | Update reference list entries in Google SecOps | required reference_list_id, entriesoptional description |
google-secops_update_rule | Update a detection rule’s YARA-L text in Google SecOps | required rule_id, rule_text |
google-secops_validate_query | Validate UDM query syntax in Google SecOps | required query |
google-secops_validate_rule | Validate YARA-L rule syntax in Google SecOps | required rule_text |
Graylog
Section titled “Graylog”8 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
graylog_create_stream | Create a new stream | required titleoptional description, index_set_id, matching_type, remove_matches_from_default_stream |
graylog_create_stream_rule | Create a rule for a stream | required streamId, type, field, valueoptional description, inverted |
graylog_get_processing_status | Get current message processing status | — |
graylog_get_stream | Get details of a specific stream by ID | required streamId |
graylog_get_system_info | Get Graylog system information including version, node ID, and cluster details | — |
graylog_list_streams | List all available streams | — |
graylog_search_messages | Search for messages using Lucene query syntax with relative time range | required query, rangeoptional decorate, fields, filter, limit, offset, sort |
graylog_search_messages_absolute | Search for messages using Lucene query syntax with absolute time range | required query, from, tooptional decorate, fields, filter, limit, offset, sort |
IBM QRadar SIEM
Section titled “IBM QRadar SIEM”16 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
ibm-qradar_add_offense_note | Add a text note to a IBM QRadar offense for investigation tracking. | required offense_id, note_text |
ibm-qradar_add_reference_set_entry | Add a value to a IBM QRadar reference data set (e.g., add a malicious IP to a blocklist). | required name, value |
ibm-qradar_delete_reference_set_entry | Remove a value from a IBM QRadar reference data set. | required name, value |
ibm-qradar_get_ariel_search | Check the status of an existing Ariel search and optionally retrieve its results if complete. | required search_idoptional include_results |
ibm-qradar_get_asset | Get detailed information about a IBM QRadar asset by its numeric ID. | required asset_id |
ibm-qradar_get_offense | Get full details of a specific IBM QRadar offense by its numeric ID. Returns all offense fields including source IPs, categories, magnitude, and assigned user. | required offense_id |
ibm-qradar_get_reference_set | Get the contents of a specific reference data set by name. Returns entries in the set (e.g., list of blocked IPs), paginated by limit. | required nameoptional limit |
ibm-qradar_get_system_info | Get IBM QRadar system information including version and build number. | — |
ibm-qradar_list_closing_reasons | List available offense closing reasons. Use the returned IDs when closing an offense via update_offense. | optional limit |
ibm-qradar_list_log_sources | List configured IBM QRadar log sources with their status, type, and protocol information. | optional filter_query, limit |
ibm-qradar_list_offense_notes | List notes attached to a specific IBM QRadar offense. | required offense_idoptional limit |
ibm-qradar_list_offenses | List IBM QRadar offenses (security incidents) with optional filtering. Returns offenses sorted by most recent. Use the filter parameter for IBM QRadar filter expressions like ‘status=OPEN’ or ‘magnitude >= 5’. | optional fields, filter_query, limit, status |
ibm-qradar_list_reference_sets | List IBM QRadar reference data sets (used for IOC management, blocklists, whitelists). Returns set names, types, and element counts. | optional limit |
ibm-qradar_run_ariel_search | Execute an AQL (Ariel Query Language) search and return results. The search is submitted, polled until completion, and results are returned. | required query_expression |
ibm-qradar_search_assets | Search IBM QRadar assets via the asset model REST API. Use the filter parameter for IBM QRadar filter expressions, e.g. ‘interfaces contains ip_addresses contains value = “10.0.0.1“‘. | optional fields, filter_query, limit |
ibm-qradar_update_offense | Update an offense — close it, hide it, reassign it, or change its status. To close an offense you must provide a closing_reason_id (use list_closing_reasons to find valid IDs). | required offense_idoptional assigned_to, closing_reason_id, follow_up, status |
Microsoft Defender
Section titled “Microsoft Defender”18 tools. Available as 2 connections: Microsoft Defender (OAuth 2.0), Microsoft Defender for Endpoint (GCC High) (OAuth 2.0).
| Tool | Description | Arguments |
|---|---|---|
microsoft-defender_create_indicator | Create or update a Microsoft Defender threat indicator (IP, URL, domain, or file hash) with a specified action | required indicator_value, indicator_type, action, titleoptional description, expiration_time, generate_alert, severity |
microsoft-defender_delete_indicator | Delete a Microsoft Defender threat indicator by ID | required indicator_id |
microsoft-defender_get_alert | Get a single Microsoft Defender alert by ID with full detail | required alert_id |
microsoft-defender_get_incident | Get a Microsoft Defender incident by ID including associated alerts | required incident_id |
microsoft-defender_get_indicator | Get a specific Microsoft Defender threat indicator by ID | required indicator_id |
microsoft-defender_get_investigation | Get a Microsoft Defender automated investigation by ID | required investigation_id |
microsoft-defender_get_machine | Get a single Microsoft Defender endpoint device by ID | required machine_id |
microsoft-defender_isolate_machine | Isolate a device from the network. Use Full for complete network cutoff or Selective for limited isolation | required machine_id, commentoptional isolation_type |
microsoft-defender_list_alerts | List Microsoft Defender alerts with filtering by status, severity, and OData expressions | optional filter_query, severity, skip, status, top |
microsoft-defender_list_incidents | List Microsoft Defender security incidents with filtering by status, assignment, and OData expressions | optional assigned_to, filter_query, skip, status, top |
microsoft-defender_list_indicators | List Microsoft Defender threat indicators with OData filtering by type, action, and other properties | optional filter_query, skip, top |
microsoft-defender_list_investigations | List Microsoft Defender automated investigations with OData filtering by state and machine | optional filter_query, skip, top |
microsoft-defender_list_machines | List Microsoft Defender endpoint devices with OData filtering by DNS name, OS platform, risk score, and health status | optional filter_query, skip, top |
microsoft-defender_run_advanced_query | Execute a KQL (Kusto Query Language) query against Microsoft Defender data for advanced threat hunting | required query |
microsoft-defender_run_antivirus_scan | Initiate an antivirus scan on a device. Use Quick for a fast scan or Full for a comprehensive scan | required machine_id, commentoptional scan_type |
microsoft-defender_unisolate_machine | Release a device from network isolation, restoring its network connectivity | required machine_id, comment |
microsoft-defender_update_alert | Update a Microsoft Defender alert’s status, assignment, classification, or determination | required alert_idoptional assigned_to, classification, comment, determination, status |
microsoft-defender_update_incident | Update a Microsoft Defender incident’s status, assignment, classification, tags, or determination | required incident_idoptional assigned_to, classification, comment, determination, status, tags |
Microsoft Graph Security
Section titled “Microsoft Graph Security”16 tools. Available as 4 connections: Microsoft Graph Security (OAuth 2.0), Microsoft Graph Security (Application) (OAuth 2.0 client credentials), Microsoft Graph Security (GCC High) (OAuth 2.0), Microsoft Defender XDR (GCC High, Application) (OAuth 2.0 client credentials).
| Tool | Description | Arguments |
|---|---|---|
microsoft-graph-security_confirm_risky_users_compromised | Confirm one or more users as compromised, setting their risk level to high | required user_ids |
microsoft-graph-security_confirm_risky_users_safe | Confirm one or more users as safe, setting their risk level to none | required user_ids |
microsoft-graph-security_create_alert_comment | Add a comment to an existing security alert | required alert_id, comment |
microsoft-graph-security_create_incident_comment | Add a comment to an existing security incident | required incident_id, comment |
microsoft-graph-security_dismiss_risky_users | Dismiss (reset) the risk of one or more users, setting their risk level to none | required user_ids |
microsoft-graph-security_get_alert | Get a single security alert by ID, including evidence artifacts and MITRE ATT&CK techniques | required alert_id |
microsoft-graph-security_get_incident | Get a single security incident by ID, optionally expanding related alerts | required incident_idoptional expand_alerts |
microsoft-graph-security_get_risky_user | Get a single risky user by ID from Microsoft Entra ID Identity Protection | required risky_user_id |
microsoft-graph-security_list_alerts | List security alerts from Microsoft 365 Defender with filtering by severity, status, classification, service source, assignee, and date range | optional assigned_to, classification, created_after, created_before, service_source, severity, skip, status, top |
microsoft-graph-security_list_incidents | List security incidents from Microsoft 365 Defender with filtering by severity, status, classification, assignee, and date range | optional assigned_to, classification, created_after, created_before, severity, skip, status, top |
microsoft-graph-security_list_risky_users | List risky users from Microsoft Entra ID Identity Protection with filtering by risk level, risk state, and user principal name | optional risk_level, risk_state, skip, top, user_principal_name |
microsoft-graph-security_list_secure_score_control_profiles | List individual security control profiles with their scores and improvement actions | optional skip, top |
microsoft-graph-security_list_secure_scores | List tenant security scores (daily snapshots) from Microsoft Secure Score | optional skip, top |
microsoft-graph-security_run_hunting_query | Execute a KQL query against Microsoft 365 Defender raw data (up to 30 days, max 100K rows) | required queryoptional timespan |
microsoft-graph-security_update_alert | Update a security alert’s status, assignee, classification, and determination | required alert_idoptional assigned_to, classification, determination, status |
microsoft-graph-security_update_incident | Update a security incident’s status, assignee, classification, determination, and custom tags | required incident_idoptional assigned_to, classification, custom_tags, determination, status |
Microsoft Sentinel (Management)
Section titled “Microsoft Sentinel (Management)”12 tools. Available as 2 connections: Microsoft Sentinel (Management) (OAuth 2.0), Microsoft Sentinel (Management, Government) (OAuth 2.0).
| Tool | Description | Arguments |
|---|---|---|
microsoft-sentinel-management_add_incident_comment | Add an analyst comment to a Microsoft Sentinel incident, for recording investigation notes and handoffs on the incident timeline. Each call appends a new comment. Returns an acknowledgement {‘id’, ‘incident_id’, ‘created’}. | required incident_id, message |
microsoft-sentinel-management_create_bookmark | Create a Microsoft Sentinel hunting bookmark to preserve a notable KQL query result during an investigation. Requires a display name and the KQL query text; notes are optional context. Each call creates a new bookmark. | required display_name, queryoptional notes |
microsoft-sentinel-management_get_incident | Get the details of a single Microsoft Sentinel incident by its ID (the ‘id’ field from list_incidents), including its description, severity, status, owner, labels, classification, and MITRE tactics/techniques. | required incident_id |
microsoft-sentinel-management_get_watchlist | Get a single Microsoft Sentinel watchlist by its alias (the ‘alias’ field from list_watchlists), including its source, provider, search key, and authorship. Returns metadata only — call list_watchlist_items for the rows. | required watchlist_alias |
microsoft-sentinel-management_list_bookmarks | List Microsoft Sentinel hunting bookmarks in the workspace. Bookmarks preserve interesting query results found during threat hunting so analysts can revisit and share them. | optional cursor, top |
microsoft-sentinel-management_list_incident_alerts | List the security alerts grouped into a Microsoft Sentinel incident — the underlying detections that make up the case. | required incident_idoptional cursor, top |
microsoft-sentinel-management_list_incident_entities | List the entities (accounts, hosts, IPs, files, URLs, etc.) related to a Microsoft Sentinel incident — use it to scope an investigation to the affected assets and identities. | required incident_idoptional top |
microsoft-sentinel-management_list_incidents | List Microsoft Sentinel incidents for the connected workspace, newest first. Incidents group related alerts into a single investigatable case. | optional cursor, severity, status, top |
microsoft-sentinel-management_list_threat_intelligence_indicators | List threat-intelligence indicators (IOCs) in the Microsoft Sentinel workspace — IPs, domains, URLs, file hashes, and more, with their confidence, validity window, and threat types. | optional cursor, top |
microsoft-sentinel-management_list_watchlist_items | List the individual rows of a Microsoft Sentinel watchlist. | required watchlist_aliasoptional cursor, top |
microsoft-sentinel-management_list_watchlists | List Microsoft Sentinel watchlists in the workspace. Watchlists are curated reference datasets (e.g. high-value assets, allowed IPs, terminated employees) used to correlate and enrich detections. | optional cursor, top |
microsoft-sentinel-management_update_incident | Update a Microsoft Sentinel incident: change its title, severity, status, or close it. Only the fields you provide are changed; the rest are preserved. | required incident_idoptional classification, classification_comment, classification_reason, severity, status, title |
MITRE ATT&CK
Section titled “MITRE ATT&CK”8 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
mitre-attack_list_tactics | List all MITRE ATT&CK tactics for a matrix in kill-chain order. | optional matrix |
mitre-attack_list_techniques_for_tactic | — | required tacticoptional include_deprecated, include_revoked, include_subtechniques, limit, matrix, offset |
mitre-attack_lookup_campaign | Look up a MITRE ATT&CK campaign by ATT&CK ID (e.g. ‘C0028’) or name. Searches all matrices. | optional campaign_id, include_deprecated, include_revoked, query |
mitre-attack_lookup_group | Look up a MITRE ATT&CK threat group (intrusion set) by ATT&CK ID (e.g. ‘G0007’), name, or alias (e.g. ‘APT28’, ‘Fancy Bear’, ‘STRONTIUM’). Searches all matrices. | optional group_id, include_deprecated, include_revoked, query |
mitre-attack_lookup_mitigation | Look up a MITRE ATT&CK mitigation (course of action) by ATT&CK ID (e.g. ‘M1056’) or keyword. Returns the mitigation profile plus an inline summary of every technique the mitigation is mapped to. | optional include_deprecated, include_revoked, matrix, mitigation_id, query |
mitre-attack_lookup_software | Look up MITRE ATT&CK software (malware or tool) by ATT&CK ID (e.g. ‘S0002’) or name. Searches all matrices. | optional include_deprecated, include_revoked, query, software_id |
mitre-attack_lookup_technique | Look up a MITRE ATT&CK technique (or sub-technique) by ATT&CK ID (e.g. ‘T1059’ or ‘T1059.001’) or keyword. | optional include_deprecated, include_revoked, matrix, query, technique_id |
mitre-attack_search_attack | Free-text search across the MITRE ATT&CK knowledge base. Searches names, descriptions, aliases, and ATT&CK IDs of techniques, tactics, mitigations, threat groups, software, campaigns, data sources, data components, and ICS assets. | required queryoptional include_deprecated, include_revoked, limit, matrix, object_types, offset |
Obsidian Security
Section titled “Obsidian Security”0 tools. Connect with API key.
Palo Alto Cortex XDR
Section titled “Palo Alto Cortex XDR”19 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
palo-alto-cortex-xdr_allowlist_files | Add file hashes to the Cortex XDR allowlist to exclude them from security scanning | required hash_listoptional comment, incident_id |
palo-alto-cortex-xdr_blocklist_files | Add file hashes to the Cortex XDR blocklist to prevent execution across all endpoints | required hash_listoptional comment, incident_id |
palo-alto-cortex-xdr_get_action_status | Check the status of a response action (isolate, scan, script execution, etc.) | required action_id |
palo-alto-cortex-xdr_get_audit_management_logs | Retrieve Cortex XDR audit management logs with filtering by admin email, type, result, and timestamp | optional email, log_type, result, search_from, search_to, sort_field, sort_order, timestamp_gte, timestamp_lte |
palo-alto-cortex-xdr_get_incident | Get detailed incident data including alerts, network artifacts, and file artifacts for a specific incident | required incident_idoptional alerts_limit |
palo-alto-cortex-xdr_get_script_execution_results | Get the results of a previously executed script using the action ID | required action_id |
palo-alto-cortex-xdr_get_xql_results | Retrieve results of a previously started XQL query using the query ID | required query_idoptional limit |
palo-alto-cortex-xdr_insert_alerts | Insert externally-detected alerts into Cortex XDR for correlation and investigation | required alerts |
palo-alto-cortex-xdr_isolate_endpoint | Isolate an endpoint from the network to contain a threat (endpoint remains manageable via Cortex XDR) | required endpoint_idoptional incident_id |
palo-alto-cortex-xdr_list_alerts | List Cortex XDR alerts with filtering by alert ID, source, severity, and creation time | optional alert_id_list, alert_source, creation_time_gte, creation_time_lte, search_from, search_to, severity, sort_field, sort_order |
palo-alto-cortex-xdr_list_endpoints | List Cortex XDR endpoints with filtering by status, hostname, IP, platform, isolation status, and more | optional alias, endpoint_id_list, endpoint_status, group_name, hostname, ip_list, isolate, platform, search_from, search_to, sort_field, sort_order, username |
palo-alto-cortex-xdr_list_incidents | List Cortex XDR incidents with filtering by status, severity, creation/modification time, and description | optional creation_time_gte, creation_time_lte, description, incident_id_list, modification_time_gte, search_from, search_to, severity, sort_field, sort_order, status |
palo-alto-cortex-xdr_list_scripts | List available scripts in the Cortex XDR script library with optional filtering | optional description, is_high_risk, linux_supported, macos_supported, name, search_from, search_to, windows_supported |
palo-alto-cortex-xdr_quarantine_file | Quarantine a file on an endpoint by path and SHA256 hash to prevent execution | required endpoint_id, file_path, file_hashoptional incident_id |
palo-alto-cortex-xdr_run_script | Execute a script from the Cortex XDR library on one or more endpoints | required script_uid, endpoint_id_listoptional incident_id, parameters_values, timeout |
palo-alto-cortex-xdr_scan_endpoints | Initiate a malware scan on specified endpoints or all endpoints | optional all_endpoints, dist_name, endpoint_id_list |
palo-alto-cortex-xdr_start_xql_query | Start an XQL (XDR Query Language) query for advanced threat hunting and data analysis | required queryoptional tenants, time_frame |
palo-alto-cortex-xdr_unisolate_endpoint | Restore network connectivity for a previously isolated endpoint | required endpoint_idoptional incident_id |
palo-alto-cortex-xdr_update_incident | Update an incident’s status, severity, assignee, or add a resolve comment | required incident_idoptional assigned_user_mail, assigned_user_pretty_name, resolve_comment, severity, status |
Proofpoint Email Protection
Section titled “Proofpoint Email Protection”8 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
proofpoint_delete_quarantine_message | Delete a quarantined message by moving it to the deleted folder. Identified by quarantine folder and local GUID. This is destructive. | required folder, local_guidoptional deleted_folder |
proofpoint_forward_quarantine_message | Forward a copy of a quarantined message to another recipient for review, without releasing it to the original recipients. | required folder, local_guid, to |
proofpoint_get_end_user | Get an end-user’s Proofpoint profile, including their safe-sender and blocked-sender lists. Identified by email address or user id. | required email_or_uid |
proofpoint_list_quarantine_messages | List messages currently held in a Proofpoint quarantine folder. Filter by sender, recipient, subject, date range, or folder. | optional end_date, folder, limit, message_status, recipient, sender, start_date, subject |
proofpoint_move_quarantine_message | Move a quarantined message from one quarantine folder to another. Identified by source folder and local GUID. | required folder, local_guid, target_folder |
proofpoint_release_quarantine_message | Release a quarantined message back to its recipients. The message is identified by its quarantine folder and local GUID. This delivers the held email — use after confirming it is safe. | required folder, local_guidoptional rescan |
proofpoint_resubmit_quarantine_message | Resubmit a quarantined message back through the filtering modules for re-evaluation. Identified by quarantine folder and local GUID. | required folder, local_guid |
proofpoint_search_messages | Search processed email through Proofpoint Smart Search. Filter by envelope sender/recipient, time window, subject, message-id, or final disposition to trace a message and inspect its spam/phishing/virus verdict. | optional disposition, end_date, limit, message_id, recipient, sender, start_date, subject, virus |
Rapid7 InsightIDR
Section titled “Rapid7 InsightIDR”15 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
rapid7-insightidr_add_threat_indicators | Add IP, hash, domain, or URL indicators to an InsightIDR threat | required keyoptional domain_names, hashes, ips, urls |
rapid7-insightidr_create_comment | Add a comment to an InsightIDR investigation | required target, body |
rapid7-insightidr_create_investigation | Create a new manual InsightIDR investigation with title, priority, and status | required titleoptional assignee_email, disposition, priority, status |
rapid7-insightidr_get_investigation | Get details of a specific InsightIDR investigation by ID or RRN | required investigation_id |
rapid7-insightidr_list_comments | List comments for a specific InsightIDR investigation | required targetoptional index, size |
rapid7-insightidr_list_detection_rules | List InsightIDR detection rules with pagination. Note: requires appropriate SIEM tier permissions. Raises a not-found error if your API key lacks detection rule access. | optional index, size |
rapid7-insightidr_list_investigation_alerts | List alerts associated with a specific InsightIDR investigation | required investigation_idoptional index, size |
rapid7-insightidr_list_investigations | List InsightIDR investigations with filtering by status, priority, assignee, and time range | optional assignee_email, end_time, index, priorities, size, sort, sources, start_time, statuses |
rapid7-insightidr_list_logs | List all available log sources in InsightIDR | — |
rapid7-insightidr_list_users | Search and list InsightIDR user accounts | optional index, search, size |
rapid7-insightidr_query_log | Execute a LEQL query against a specific InsightIDR log source | required log_id, queryoptional end_time, start_time, time_range |
rapid7-insightidr_search_alerts | Search InsightIDR alerts with filtering by status and time range. Note: requires the Managed Detection and Response (MDR) add-on. Raises a not-found error if your account does not have MDR access. | optional end_time, index, search, size, start_time, statuses |
rapid7-insightidr_search_investigations | Search InsightIDR investigations by text query with time range filtering | optional end_time, index, search, size, sort, start_time |
rapid7-insightidr_update_alert | Update an InsightIDR alert’s status, disposition, priority, or assignment. Note: requires the Managed Detection and Response (MDR) add-on. Raises a not-found error if your account does not have MDR access. | required alert_idoptional assignee_email, disposition, priority, status |
rapid7-insightidr_update_investigation | Update an InsightIDR investigation’s title, status, priority, disposition, or assignee | required investigation_idoptional assignee_email, disposition, priority, status, title |
Recorded Future
Section titled “Recorded Future”14 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
recorded-future_enrich_domain | Enrich a domain with Recorded Future threat intelligence including risk score, risk rules, evidence details, and related entity links | required domainoptional fields |
recorded-future_enrich_entities | Bulk enrich multiple entities (IPs, domains, URLs, hashes, vulnerabilities) at once using the SOAR API. More efficient than individual enrichment calls when checking multiple indicators. | optional domain, file_hash, ip, url, vulnerability |
recorded-future_enrich_hash | Enrich a file hash (MD5, SHA-1, or SHA-256) with Recorded Future threat intelligence including risk score, risk rules, and malware associations | required file_hashoptional fields |
recorded-future_enrich_ip | Enrich an IP address with Recorded Future threat intelligence including risk score, risk rules, evidence details, and related entity links | required ipoptional fields |
recorded-future_enrich_url | Enrich a URL with Recorded Future threat intelligence including risk score, risk rules, and evidence details | required urloptional fields |
recorded-future_enrich_vulnerability | Enrich a vulnerability (CVE ID or name) with Recorded Future threat intelligence including risk score, risk rules, evidence, and exploit availability | required vulnerability_idoptional fields |
recorded-future_get_alert | Get detailed information about a specific triggered alert by ID, including hits, entities, documents, risk scores, and AI insights | required alert_idoptional fields |
recorded-future_get_playbook_alert | Get detailed information about a specific playbook alert by ID, including evidence summary, targets, priority, and category details | required alert_id |
recorded-future_get_threat_map_actors | Get threat actor map data for the organization, showing threat actors with intent and opportunity scores, categories, and watchlist matches. Useful for understanding the threat landscape targeting your organization. | required actors, categories, watchlists |
recorded-future_get_threat_map_malware | Get malware threat map data for the organization, showing malware families with severity scores, categories, and watchlist matches. Useful for understanding malware threats targeting your organization. | required malware, categories, watchlists |
recorded-future_search_alert_rules | Search Recorded Future alert rules by name. Returns rule titles and IDs for use with alert search filtering. | optional freetext, limit |
recorded-future_search_alerts | Search triggered alerts in Recorded Future with filtering by timeframe, alert rule, and pagination. Returns alert summaries including title, rule, status, and hit counts. | optional alert_rule, fields, limit, offset, triggered |
recorded-future_search_detection_rules | Search Recorded Future detection rules (Sigma, Yara, Snort) with filtering by type, related entities, and date range. Returns rules with content for import into security tools. | optional after, before, entities, limit, types |
recorded-future_search_playbook_alerts | Search Recorded Future playbook alerts with filtering by status, priority, category, and time ranges. Returns actionable security alerts with triage information. | optional categories, created_from_relative, entities, limit, priorities, statuses, updated_from_relative |
ReliaQuest GreyMatter
Section titled “ReliaQuest GreyMatter”22 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
reliaquest-greymatter_acknowledge_incident | Acknowledge a Grey Matter incident by providing acknowledgement method and auto-assignment preference. Use the base64-encoded incident ID | required input |
reliaquest-greymatter_add_incident_comment | Add a comment to a Grey Matter incident by providing the comment text and incident ID. Use the base64-encoded incident ID | required inputoptional after, filter, first, order |
reliaquest-greymatter_assign_incident | Assign a Grey Matter incident to a specific user by providing the assignee ID and incident ID. FIRST use list_users to find the user ID by email/name, THEN assign the incident. Use the base64-encoded incident ID | required input |
reliaquest-greymatter_close_incident | Close a Grey Matter incident by providing the close code, close note, incident ID, and optional final state. Use the base64-encoded incident ID | required request |
reliaquest-greymatter_get_audits | Retrieve user activity audits with comprehensive filtering and pagination support. For time-based queries, use exec tool to get current date first. | optional after, filter, first, order |
reliaquest-greymatter_get_customer_detection | Retrieve a specific Grey Matter customer detection with activity logs and rule details. For date filtering, use exec tool to get current date first. | required id, byoptional after, filter, first, order |
reliaquest-greymatter_get_incident | Retrieve a specific Grey Matter incident by ID or ticket number with all related data. For date filtering, use exec tool to get current date first. | required byoptional after, after4, filter, filter5, first, first4, order, order4 |
reliaquest-greymatter_get_indicator | Retrieve a specific Grey Matter indicator by Global ID or name/type combination | required by |
reliaquest-greymatter_get_playbook_run | Retrieve a specific Grey Matter playbook run with execution results, user details, and complete audit trail | required idoptional after, after1, after2, after3, after4, after5, after6, after7, filter, filter1, filter2, filter3, filter4, filter5, first, first1, first2, first3, first4, first5, first6, first7, order, order1, order2, order3, order4, order5 |
reliaquest-greymatter_get_playbook_run_filter_data | Get available filter values for playbook runs including tempRuleIds, ticketNumbers, and users | optional after, after1, after2, filter, filter1, filter2, first, first1, first2, order, order1, order2 |
reliaquest-greymatter_get_recommended_playbooks | Get recommended Grey Matter playbooks based on artifacts and temporary rule ID. Use single artifact object with field and values array, not array of artifacts. | required filter |
reliaquest-greymatter_get_user | Retrieve a specific Grey Matter user by ID with comprehensive access groups, pods, and roles information | required idoptional after, after1, after2, filter, filter1, filter2, first, first1, first2, order, order1, order2 |
reliaquest-greymatter_list_customer_detections | Fetch all Grey Matter customer detections matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z). | optional after, filter, first, order |
reliaquest-greymatter_list_customer_playbooks | Get all Grey Matter customer playbooks with their configurations and supported integrations | — |
reliaquest-greymatter_list_detection_rules | Fetch all Grey Matter detection rules matching filter criteria with comprehensive filtering, ordering, and pagination support. | optional after, detectionRuleOrder, filter, first |
reliaquest-greymatter_list_incidents | Fetch all Grey Matter incidents matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z). | optional after, first, incidentFilter, incidentOrder |
reliaquest-greymatter_list_indicators | Fetch all Grey Matter indicators matching filter criteria with pagination. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z). | optional after, filter, first, order |
reliaquest-greymatter_list_playbook_runs | Get Grey Matter playbook runs with comprehensive filtering, pagination, and sorting options. For date filtering, use exec tool to get current date first in ISO 8601 format with a Z suffix for UTC timezone (e.g., 2025-06-22T00:00:00Z). | optional after, filter, first, orderBy |
reliaquest-greymatter_list_playbooks | Get all available Grey Matter playbooks with their metadata, field definitions, and supported technologies | — |
reliaquest-greymatter_list_users | Retrieve users for the current customer organization with pagination support. Returns customer info and paginated user list including id, email, fullName, and serviceNowId. | optional after, first |
reliaquest-greymatter_run_playbook | Execute a Grey Matter playbook with specified configuration, integration IDs, and variables. Used to trigger automated response actions. | required input |
reliaquest-greymatter_update_incident_state | Update the state of a Grey Matter incident by providing a comment explaining the change, incident ID, and new state. Use the base64-encoded incident ID, not the ticket number. Returns incident state details and success status. | required input |
SentinelOne
Section titled “SentinelOne”22 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
sentinelone_get_alert | Get detailed information about a specific alert by ID. Args: alert_id: The unique identifier of the alert. Returns: Detailed alert information in JSON format. Raises: RuntimeError: If there’s an error retrieving the alert. | required alert_id |
sentinelone_get_alert_history | Get the complete audit history and timeline for an alert. Args: alert_id: The unique identifier of the alert. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional). | required alert_idoptional after, first |
sentinelone_get_alert_notes | Get all notes and comments associated with an alert. Args: alert_id: The unique identifier of the alert. Returns: List of notes in JSON format with author and timestamp information. | required alert_id |
sentinelone_get_inventory_item | Get detailed information about a specific inventory item by ID. Args: item_id: The unique identifier of the inventory item. Returns: Detailed inventory item information in JSON format. Raises: ValueError: If item_id is invalid or empty. | required item_id |
sentinelone_get_misconfiguration | Get detailed information about a specific misconfiguration by ID. Args: misconfiguration_id: The unique identifier of the misconfiguration. Returns: Detailed misconfiguration information in JSON format. | required misconfiguration_id |
sentinelone_get_misconfiguration_history | Get the audit history for a misconfiguration. Args: misconfiguration_id: The unique identifier of the misconfiguration. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional). | required misconfiguration_idoptional after, first |
sentinelone_get_misconfiguration_notes | Get all notes associated with a misconfiguration. Args: misconfiguration_id: The unique identifier of the misconfiguration. Returns: List of notes in JSON format. | required misconfiguration_id |
sentinelone_get_timestamp_range | Get both current timestamp and offset timestamp for time range queries. This tool returns both the current time and a calculated offset time, designed specifically for PowerQuery time range queries. | optional days, direction, hours, minutes, months, reference_time, seconds, weeks, years |
sentinelone_get_vulnerability | Get detailed information about a specific vulnerability by ID. Args: vulnerability_id: The unique identifier of the vulnerability. Returns: Detailed vulnerability information in JSON format. | required vulnerability_id |
sentinelone_get_vulnerability_history | Get the audit history for a vulnerability. Args: vulnerability_id: The unique identifier of the vulnerability. first: Number of history events to retrieve (1-100, default: 10). after: Cursor for pagination (optional). | required vulnerability_idoptional after, first |
sentinelone_get_vulnerability_notes | Get all notes associated with a vulnerability. Args: vulnerability_id: The unique identifier of the vulnerability. Returns: List of notes in JSON format. Raises: RuntimeError: If there’s an error retrieving vulnerability notes. | required vulnerability_id |
sentinelone_iso_to_unix_timestamp | Convert an ISO 8601 datetime string to UNIX timestamp in milliseconds. Args: iso_datetime: ISO 8601 formatted datetime string. Returns: UNIX timestamp in milliseconds as a string. | required iso_datetime |
sentinelone_list_alerts | List alerts with pagination and filtering capabilities. Args: first: Number of alerts to retrieve (1-100, default: 10). after: Cursor for pagination (optional). | optional after, fields, first, view_type |
sentinelone_list_inventory_items | List inventory items with pagination and optional surface filtering. Args: limit: Number of items to retrieve (1-1000, default: 50). skip: Number of items to skip for pagination (default: 0). | optional limit, skip, surface |
sentinelone_list_misconfigurations | List misconfigurations with pagination and view filtering. Args: first: Number of misconfigurations to retrieve (1-100, default: 10). after: Cursor for pagination (optional). | optional after, fields, first, view_type |
sentinelone_list_vulnerabilities | List vulnerabilities with pagination. Args: first: Number of vulnerabilities to retrieve (1-100, default: 10). after: Cursor for pagination (optional). fields: Optional JSON string containing an array of field names to return. | optional after, fields, first |
sentinelone_powerquery | Run a SentinelOne PowerQuery in AISIEM and return the results. Args: query: The PowerQuery string to execute start_datetime: Start time in ISO 8601 format. | required query, start_datetime, end_datetime |
sentinelone_purple_ai | Ask Purple AI a question. Purple AI is a tool to answer cyber security questions. Args: query: The question to ask Purple AI. Returns: The response from Purple AI as a string. Raises: RuntimeError: If settings are not properly configured. | required query |
sentinelone_search_alerts | Search alerts using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys. | optional after, fields, filters, first, view_type |
sentinelone_search_inventory_items | Search inventory items using REST API filters. Note: This tool does not support surface filtering. For surface-specific queries (ENDPOINT, CLOUD, IDENTITY, NETWORK_DISCOVERY), use list_inventory_items instead. | optional filters, limit, skip |
sentinelone_search_misconfigurations | Search misconfigurations using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys. | optional after, fields, filters, first, view_type |
sentinelone_search_vulnerabilities | Search vulnerabilities using advanced filters and criteria. Args: filters: JSON string containing an array of filter objects (optional). Each filter object must have fieldId and filterType keys. | optional after, fields, filters, first |
Splunk
Section titled “Splunk”26 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
splunk_add_investigation_note | Add a free-form note to a Splunk ES Mission Control v2 record via the unified notes endpoint (POST /servicesNS/nobody/missioncontrol/public/v2/investigations/{id}/notes). | required investigation_id, contentoptional notable_time, title |
splunk_cancel_job | Cancel a running search job | required sid |
splunk_create_finding | Create a new manual finding in Splunk Enterprise Security / Mission Control (the ES 8.0+ term for what used to be a ‘notable event’). | required title, description, security_domain, entity, entity_type, finding_scoreoptional disposition, fields, owner, status, urgency |
splunk_create_investigation | Create a new investigation (case) in Splunk Enterprise Security via the Mission Control v2 REST API. | required nameoptional description, incident_origin, owner, sensitivity, status, urgency |
splunk_create_saved_search | Create a new saved search | required name, searchoptional cron_schedule, description, earliest_time, is_scheduled, latest_time |
splunk_create_search_job | Create a search job that runs asynchronously | required queryoptional earliest_time, latest_time, search_mode |
splunk_delete_saved_search | Delete an existing saved search by name | required nameoptional app, owner |
splunk_export_results | Export search results in a specific format | required queryoptional earliest_time, latest_time, max_results, output_mode |
splunk_get_index | Get details of a specific index | required name |
splunk_get_investigation | Retrieve full details of a specific investigation (case) by ID from Splunk Enterprise Security, including status, description, collaborators, tags, and timestamps. | required investigation_id |
splunk_get_job_results | Retrieve results from a completed search job | required sidoptional count, offset, output_mode |
splunk_get_job_status | Get the status and progress of a search job | required sid |
splunk_get_saved_search | Get details of a specific saved search | required nameoptional app, owner |
splunk_get_server_info | Get Splunk server information and status | — |
splunk_link_findings_to_investigation | Link existing Mission Control v2 findings to an investigation in a single bulk request (POST /investigations/{guid}/findings). | required investigation_id, finding_idsoptional finding_times |
splunk_list_findings | List Splunk ES findings via Mission Control v2 (GET /findings). | optional count, earliest, latest, offset |
splunk_list_indexes | List all indexes accessible to the user | optional count, datatype, offset |
splunk_list_investigations | List investigations (cases) from Splunk ES Mission Control v2. | optional count, disposition, earliest, latest, offset, owner, sensitivity, status, urgency |
splunk_list_jobs | List all search jobs for the current user | optional count, offset, sort_dir, sort_key |
splunk_list_saved_searches | List all saved searches accessible to the user | optional app, count, offset, owner |
splunk_notable_update | [Legacy — do not use for structured updates on ES 8.x] On Splunk Enterprise Security 8.x, status / owner / urgency / disposition updates through this tool silently no-op even when the endpoint returns 2xx. | optional app, comment, disposition, new_owner, owner, rule_uids, search_id, status_id, urgency |
splunk_run_saved_search | Dispatch a saved search and return the job SID for tracking | required nameoptional app, earliest_time, latest_time, owner, trigger_actions |
splunk_run_search | Execute a Splunk search query and return results | required queryoptional earliest_time, latest_time, max_results, output_mode |
splunk_update_finding | [PRIMARY tool for finding status / owner / urgency / disposition updates on Splunk ES 8.x] Use this instead of notable_update whenever the user asks to change a finding’s status, owner, urgency or disposition. | required finding_idoptional disposition, notable_time, owner, status, urgency |
splunk_update_investigation | Partially update an investigation (case) in Splunk ES Mission Control v2. Only the provided fields are sent to the server; unspecified fields are left untouched. | required investigation_idoptional description, disposition, name, owner, sensitivity, status, urgency |
splunk_update_saved_search | Update an existing saved search | required nameoptional app, cron_schedule, description, disabled, is_scheduled, owner, search |
Sumo Logic
Section titled “Sumo Logic”12 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
sumo-logic_cloud_siem_add_comment_to_insight | Add a comment to a Cloud SIEM Insight for collaboration. | required insightId, comment |
sumo-logic_cloud_siem_add_tags_to_insight | Add tags to a Cloud SIEM Insight for better organization. | required insightId, tagName |
sumo-logic_cloud_siem_enrich_entities | Enrich entity information with additional context from Cloud SIEM. | required entityType, entityValue |
sumo-logic_cloud_siem_get_entity_details | Get detailed information about a specific Cloud SIEM Entity (user, hostname, IP address, etc.) by ID. | required idoptional expand |
sumo-logic_cloud_siem_get_insight_details | Get detailed information about a specific Cloud SIEM Insight by ID. | required id, recordSummaryFieldsoptional exclude |
sumo-logic_cloud_siem_list_insights | Get a list of Cloud SIEM Insights with optional filtering. Note: This API will not return more than 10,000 Insights for a given query. Use the query parameter to filter results. | required recordSummaryFieldsoptional exclude, limit, offset, q |
sumo-logic_cloud_siem_ping | Test connectivity to Sumo Logic Cloud SIEM. | — |
sumo-logic_cloud_siem_search_entity_signals | Search for signals related to a specific entity in Cloud SIEM. | required entityValueoptional endTime, limit, minSeverity, offset, startTime |
sumo-logic_cloud_siem_update_insight_assignee | Assign or reassign a Cloud SIEM Insight to a specific user or team. | required insightId, assigneeType, assigneeValue |
sumo-logic_cloud_siem_update_insight_status | Update the status of a Cloud SIEM Insight. When closing an insight you must also provide a resolution; omit the resolution for any other status. | required insightId, statusoptional resolution |
sumo-logic_query_metrics | Query metrics data from Sumo Logic. | required query, from, to |
sumo-logic_search_logs | Search logs in Sumo Logic with a custom query. Results are limited to prevent overwhelming responses. | required query, from, tooptional limit |
Swimlane
Section titled “Swimlane”18 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
swimlane_create_comment | Add a comment or investigation note to a Swimlane record | required app_id, record_id, message |
swimlane_create_record | Create a new record in a Swimlane application using human-readable field names | required app_id, values |
swimlane_delete_record | Delete a record from a Swimlane application by ID | required app_id, record_id |
swimlane_execute_task | Trigger a Swimlane orchestration task to run immediately (e.g., enrichment, response action) | required task_id |
swimlane_find_record_by_field | Find records in a Swimlane application whose named field matches a value (e.g. find the record where ‘Client Name’ is ‘Acme’). | required app_id, field_name, valueoptional limit |
swimlane_get_app | Get a single Swimlane application by id, name, or acronym, including its full field schema (the UI layout tree is omitted for size). | required query |
swimlane_get_group | Get a single Swimlane group by ID or name | required query |
swimlane_get_record | Get a single Swimlane record by record_id OR tracking_id (e.g. ‘INC-42’), never both. app_id must be the application’s internal id — resolve a name or acronym with get_app first. | required app_idoptional record_id, tracking_id |
swimlane_get_task | Get an orchestration task (automation step) by ID, including status and metadata | required task_id |
swimlane_get_user | Get a single Swimlane user by display name or username. Use swimlane_search_users to discover users first, then look up by their displayName or userName. Swimlane user IDs cannot be used for direct lookup. | required query |
swimlane_get_workflow | Get a Swimlane workflow/playbook definition by ID (read-only, for triage context). Requires application admin permissions — the personal access token must belong to a user with the Administration role on the workflow’s parent application. | required workflow_id |
swimlane_list_apps | List Swimlane applications (form definitions) as compact summaries: id, name, acronym, description, field count, dates. Use get_app for one app’s full field schema — the summaries deliberately omit it. | optional cursor, limit |
swimlane_list_attachments | List file attachment metadata on a Swimlane record (no file content) | required app_id, record_id |
swimlane_list_comments | List comments and investigation notes on a Swimlane record | required app_id, record_id |
swimlane_list_groups | List all Swimlane user groups | — |
swimlane_list_records | List records in a Swimlane application with field names resolved to human-readable labels | required app_idoptional limit |
swimlane_search_users | Search Swimlane users by display name. Provide a partial name to search (e.g. ‘admin’). Wildcards like ’*’ are not supported. To list all users, pass an empty string. | required query |
swimlane_update_record | Update fields on an existing Swimlane record using human-readable field names. | required app_id, valuesoptional record_id, tracking_id |
ThreatConnect
Section titled “ThreatConnect”24 tools. Available as 2 connections: ThreatConnect (API key), ThreatConnect (HMAC) (credentials in connection settings).
| Tool | Description | Arguments |
|---|---|---|
threatconnect_create_association | Create an association between two ThreatConnect objects. Links indicators to groups, groups to cases, indicators to cases, etc. Source and target types can be: indicators, groups, or cases. | required source_type, source_id, target_type, target_idoptional owner |
threatconnect_create_case | Create a new incident response case with name, status (Open/Closed), severity (Low/Medium/High/Critical), and optional assignee. | required name, status, severityoptional assignee, description, tags |
threatconnect_create_group | Create a new group (Incident, Adversary, Campaign, Threat, Malware, Document, Report, etc.) with optional tags and status. | required group_type, nameoptional event_date, owner, status, tags |
threatconnect_create_indicator | Create a new threat indicator. Supports Address (IP), Host (domain), File (hash), URL, EmailAddress, ASN, CIDR, Mutex, and more. Set confidence (0-100) and rating (1.0-5.0) for threat scoring. | required indicator_typeoptional active, address, confidence, host_name, ip, md5, owner, rating, sha1, sha256, summary, tags, text |
threatconnect_create_tag | Create a new tag for organizing indicators, groups, and cases. | required name |
threatconnect_create_task | Create a new task within a case. Specify case ID, name, and optionally an assignee, due date, and status. | required name, case_idoptional assignee, description, due_date, status |
threatconnect_delete_group | Delete a group by ID. | required group_id |
threatconnect_delete_indicator | Delete a threat indicator by numeric ID or summary value. | required indicator_idoptional owner |
threatconnect_get_case | Get a single case by ID with full details including tasks, artifacts, and notes. | required case_idoptional fields |
threatconnect_get_group | Get a single group by ID with full details including associations, tags, and attributes. | required group_idoptional fields |
threatconnect_get_indicator | Get a single indicator by numeric ID or summary value (IP address, hostname, file hash, URL, email address). | required indicator_idoptional fields, owner |
threatconnect_get_victim | Get a single victim by ID with details including assets and associations. | required victim_idoptional fields |
threatconnect_list_cases | List incident response cases with optional TQL filtering by status, severity, assignee, and date range. | optional fields, owner, result_limit, result_start, tql |
threatconnect_list_groups | List threat intelligence groups (Incidents, Adversaries, Campaigns, Threats, Malware, etc.) with optional TQL filtering. | optional fields, group_type, owner, result_limit, result_start, tql |
threatconnect_list_indicators | List threat indicators (IOCs) with optional TQL filtering. Supports filtering by type (Address, Host, File, URL, etc.), rating, confidence, date range, and owner. | optional fields, indicator_type, owner, result_limit, result_start, tql |
threatconnect_list_owners | List accessible organizations and communities (owners). Owners represent data partitions for threat intelligence sharing. | optional result_limit, result_start |
threatconnect_list_security_labels | List security labels (e.g., TLP:RED, TLP:GREEN) used for classification and access control. | optional owner, result_limit, result_start, tql |
threatconnect_list_tags | List tags with optional TQL filtering and owner scoping. | optional owner, result_limit, result_start, tql |
threatconnect_list_tasks | List tasks with optional TQL filtering by case, status, and assignee. | optional owner, result_limit, result_start, tql |
threatconnect_list_victims | List victims with optional TQL filtering. Victims represent targeted entities (people, organizations) in threat scenarios. | optional fields, owner, result_limit, result_start, tql |
threatconnect_update_case | Update an existing case’s status, severity, resolution, assignee, description, or tags. | required case_idoptional assignee, description, name, resolution, severity, status, tags |
threatconnect_update_group | Update an existing group’s name, status, or tags. | required group_idoptional name, status, tags |
threatconnect_update_indicator | Update an existing indicator’s confidence, rating, active status, or tags. Identify the indicator by numeric ID or summary value. | required indicator_idoptional active, confidence, owner, rating, tags |
threatconnect_update_task | Update a task’s name, status, assignee, due date, or description. | required task_idoptional assignee, description, due_date, name, status |
Trellix Endpoint Security (HX)
Section titled “Trellix Endpoint Security (HX)”13 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
trellix-hx_get_alert | Get full details for a specific Trellix HX alert by numeric ID. Returns the matched indicator, condition, event type, event values (process command lines, file hashes, network connections), timestamps, and resolution status. | required alert_id |
trellix-hx_get_alert_group | Get details for a specific Trellix HX alert group (correlated incident). Returns the assessment summary, source, first/last event timestamps, acknowledgement status, and event statistics. Required role: api_analyst. | required group_id |
trellix-hx_get_host | Get full details for a specific Trellix HX managed endpoint by agent ID. Returns OS information, agent version, check-in timestamps, containment state, and alert statistics. Required role: api_analyst. | required agent_id |
trellix-hx_get_host_containment | Get the containment status and history for a specific Trellix HX host. Returns state (normal/contain/containing/releasing/contain_fail/release_fail), timestamps, requesting actor, and containing actor. Required role: api_analyst. | required agent_id |
trellix-hx_get_indicator | Get details for a specific Trellix HX indicator (IOC), optionally including match conditions (file hashes, registry keys, network IOCs, process names, etc.) when include_conditions=true (the default). | required category_uri_name, indicator_uri_nameoptional include_conditions |
trellix-hx_get_search_results | Retrieve match results (hits) from a Trellix HX enterprise search. | required search_idoptional limit, offset |
trellix-hx_list_alert_groups | List correlated alert groups (incidents) in Trellix HX. Alert groups correlate multiple related raw alerts into a single incident with an assessment summary. | optional limit, offset |
trellix-hx_list_alerts | List security alerts from Trellix HX with optional filtering. Returns alert ID, matched indicator, event type, timestamps, source, resolution status, and event values (command lines, file hashes, etc.). | optional host_id, limit, offset, reported_after, resolution, source |
trellix-hx_list_file_acquisitions | List file acquisition jobs in Trellix HX. File acquisitions collect specific files from endpoints for forensic analysis. Returns acquisition ID, requested file path and name, state, MD5 hash, and associated host. | optional host_id, limit, offset |
trellix-hx_list_hosts | List managed endpoint hosts in Trellix HX with optional filtering. Returns agent ID, hostname, IP address, OS, agent version, containment state, last check-in timestamps, and alert counts. Required role: api_analyst. | optional containment_state, has_active_threats, has_alerts, hostname, ip_address, limit, offset, os_platform, search |
trellix-hx_list_indicators | List threat indicators (IOCs) configured in the Trellix HX appliance. Returns indicator ID, name, category, platforms, active-since date, and statistics (alerted agents, active conditions). Required role: api_analyst. | optional category, has_alerts, limit, offset, search_term |
trellix-hx_list_searches | List enterprise IOC sweep searches in Trellix HX. Enterprise searches perform asynchronous IOC sweeps across host sets. Returns search ID, state (RUNNING/COMPLETE/STOPPED/FAILED), host set, creation actor, and settings. | optional host_set_id, limit, offset, state |
trellix-hx_list_triage_acquisitions | List triage acquisition jobs in Trellix HX. Triage acquisitions collect endpoint triage packages for forensic analysis. Returns acquisition ID, state, host, request actor, timestamps, and any associated indicator. | optional host_id, limit, offset, state |
Vectra AI
Section titled “Vectra AI”23 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
vectra-ai_create_assignment | Create new assignment. | required assignment_data |
vectra-ai_create_entity_note | Add an investigation note to an entity (host or account). Returns: str: Confirmation message with note details. | required entity_id, entity_type, note |
vectra-ai_delete_assignment | Get specific assignment by ID. | required assignment_id |
vectra-ai_get_account_details | Get complete detailed information about a specific account entity. This tool returns account details including detections, scoring information, associated accounts, access history, detection summaries, external data, and more. | required account_idoptional exclude_fields, fields, include_access_history, include_detection_summaries, include_external, src_linked_account |
vectra-ai_get_assignment_detail_by_id | Retrieve details of a specific investigation assignment. Returns: str: JSON string with details of the assignment. Raises: Exception: If fetching assignment details fails. | required assignment_id |
vectra-ai_get_assignment_for_entity | Retrieve investigation assignment for a specific account. Returns: str: JSON string with assignment details for the account. Raises: Exception: If fetching assignment fails. | required entity_ids, entity_type |
vectra-ai_get_detection_count | Get the total count of detections matching the specified criteria. Returns: str: Count of detections matching the criteria. | optional detection_category, detection_name, end_date, is_targeting_key_asset, src_ip, start_date, state |
vectra-ai_get_detection_details | Get complete detailed information for a particular detection. Returns: str: JSON string with detection details. Raises: Exception: If fetching detection details fails. | required detection_id |
vectra-ai_get_detection_pcap | Get Vectra Match statistics. | required detection_id |
vectra-ai_get_detection_summary | Get a concise summary of a detection including its ID, name, category, last timestamp, triage status, state, entity type, and detection summary. | required detection_id |
vectra-ai_get_host_details | Get complete detailed information about a specific host entity. Returns: str: Formatted string with detailed information about the host entity. | required host_id |
vectra-ai_list_assignments | List all investigation assignments with optional filtering by timestamp and resolved state. Returns: str: JSON string with list of assignments. | optional created_after, resolved |
vectra-ai_list_assignments_for_user | List all investigation assignments assigned to a user/analyst. Returns: str: JSON string with list of assignments. | required user_idoptional resolved |
vectra-ai_list_detection_ids | List detection IDs with filtering and sorting options. Use this to get a list of detection IDs based on various criteria. Returns: str: JSON string with list of detection IDs. | optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state |
vectra-ai_list_detections_with_basic_info | List detections with basic information and filtering options. Use this to get a quick overview of detections without detailed information. Returns: str: JSON string with list of detections ids. | optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state |
vectra-ai_list_detections_with_details | List detections with filtering and sorting options. Use this to get a detailed list of detections based on various criteria. Returns: str: JSON string with list of detections. | optional detection_category, detection_name, end_date, is_targeting_key_asset, limit, ordering, src_ip, start_date, state |
vectra-ai_list_entities | List entities (hosts & accounts) in Vectra platform based on various filters. This tool returns entities with all their detailed information. Returns: str: Formatted string with list of detections. | required entity_typeoptional host_ip, is_prioritized, limit, name, ordering, state, tags |
vectra-ai_list_entity_detections | List all detections with full details for a specific entity. Returns: str: JSON string with list of detections for the entity. | required entity_idoptional state |
vectra-ai_list_lockdown_entities | List entities that are currently in lockdown. Returns: str: JSON string with list of entities in lockdown. | — |
vectra-ai_list_platform_users | List users in the Vectra platform. Returns: str: JSON string with list of users. | optional email, last_login_after, limit, role |
vectra-ai_lookup_entity_info_by_name | Retrieve information about an entity (account or host) by its name. Search is case-insensitive and can match partial names. | required entity_name |
vectra-ai_lookup_host_by_ip | Retrieve information about a host entity by its IP address. Returns: str: Formatted string with host information including name, ID, type, last detection timestamp, prioritization status, urgency score, state, and IP address. | required host_ip |
vectra-ai_mark_detection_fixed | Marks or unmark detection as fixed. | required detection_ids, fixed_status |
VirusTotal
Section titled “VirusTotal”7 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
virustotal_get_analysis | Retrieve the status and results of a VirusTotal analysis by its id (returned by submit_url_scan or reanalyse_file). The attributes.status field is ‘queued’, ‘in-progress’, or ‘completed’. The meta field identifies the scanned file or URL. | required analysis_id |
virustotal_get_domain_report | Get the VirusTotal report for a domain. Returns detection stats, reputation, WHOIS, DNS records, categories, and related certificates. | required domain |
virustotal_get_file_report | Get the VirusTotal analysis report for a file by its hash (MD5, SHA-1, or SHA-256). Returns antivirus detection stats, engine results, reputation, file metadata, and relationships. | required file_hash |
virustotal_get_ip_report | Get the VirusTotal report for an IPv4 or IPv6 address. Returns detection stats, reputation, ASN/owner, country, and related certificates. | required ip_address |
virustotal_get_url_report | Get the VirusTotal analysis report for a URL. Returns detection stats, engine verdicts, categories, and reputation. Raises a not-found error if the URL has never been submitted; use submit_url_scan first to analyse a new URL. | required url |
virustotal_reanalyse_file | Request a fresh VirusTotal analysis of a file already present in the dataset, identified by its hash (MD5/SHA-1/SHA-256). Returns an analysis object whose id can be polled with get_analysis to retrieve updated detection results. | required file_hash |
virustotal_submit_url_scan | Submit a URL to VirusTotal for scanning. Returns an analysis object whose id can be polled with get_analysis to retrieve the results once the scan completes. | required url |
45 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
wazuh_assign_agent_to_group | Add an agent to a group. An agent can belong to multiple groups. | required group_id, agent_id |
wazuh_clear_syscheck_results | Clear all stored FIM results for an agent. The next scan will start fresh. | required agent_id |
wazuh_create_group | Create a new agent group in the Wazuh manager. | required group_id |
wazuh_delete_agent | Delete a single Wazuh agent by its ID. Refuses wildcard / multi-ID input. | required agent_idoptional purge |
wazuh_get_agent | Get detailed information about a specific Wazuh agent by its ID (zero-padded string, e.g., ‘001’). | required agent_id |
wazuh_get_agent_config | Get the active configuration of a specific component on a Wazuh agent. | required agent_id, component, configuration |
wazuh_get_agent_stats | Get statistical information from a Wazuh agent daemon. | required agent_idoptional component |
wazuh_get_agent_summary | Get a summary of agent counts grouped by connection status (active, disconnected, never_connected, pending, total). | — |
wazuh_get_cdb_list | Get the contents of a specific CDB list file via GET /lists/files/{filename}. Returns the file’s key/value entries — use list_cdb_lists for the metadata listing across all CDB list files. | required filename |
wazuh_get_cluster_health | Get a health check of the Wazuh cluster, showing node connectivity and sync status. | — |
wazuh_get_cluster_status | Get Wazuh cluster status (enabled/disabled, running/stopped). | — |
wazuh_get_decoder | Get details of a specific Wazuh decoder by name. | required decoder_name |
wazuh_get_group_agents | List all agents that belong to a specific group. | required group_idoptional limit, offset |
wazuh_get_manager_info | Get Wazuh manager version, compilation date, and installation path. | — |
wazuh_get_manager_logs | Get recent Wazuh manager log messages for troubleshooting. | optional level, limit, offset, q, sort, tag |
wazuh_get_manager_stats | Get Wazuh manager daemon statistics (events processed, alerts generated). | — |
wazuh_get_manager_status | Get the status of all Wazuh manager daemons (running/stopped). | — |
wazuh_get_rule | Get details of a specific Wazuh rule by its numeric ID. | required rule_id |
wazuh_get_sca_checks | Get detailed SCA check results for a specific policy on an agent, showing pass/fail status for each check. | required agent_id, policy_idoptional limit, offset, q, result |
wazuh_get_sca_summary | Get a high-level SCA compliance summary for an agent. Returns the list of evaluated policies with their pass/fail/score totals — same endpoint as list_sca_policies, provided as an alias for discoverability. | required agent_id |
wazuh_get_syscollector_hardware | Get hardware inventory information for an agent (CPU, RAM, board serial). | required agent_id |
wazuh_get_syscollector_os | Get operating system information for an agent (OS name, version, architecture). | required agent_id |
wazuh_list_agents | List Wazuh agents with optional filtering by status, OS, group, or WQL query. Returns agent ID, name, IP, status, OS info, and group membership. | optional group, limit, offset, q, search, sort, status |
wazuh_list_cdb_lists | List CDB (Constant Database) lists used for threat intelligence lookups in rules. | optional filename, limit, offset, search, sort |
wazuh_list_cluster_nodes | List all nodes in the Wazuh cluster with their status and type (master/worker). | optional limit, offset, search, sort |
wazuh_list_decoder_files | List all decoder files loaded in the Wazuh manager. | optional limit, offset, search, sort |
wazuh_list_decoders | List Wazuh decoders with optional filtering by filename or status. | optional filename, limit, offset, q, search, sort, status |
wazuh_list_groups | List all agent groups configured in the Wazuh manager. | optional limit, offset, search, sort |
wazuh_list_mitre_tactics | List MITRE ATT&CK tactics known to the Wazuh manager. | optional limit, offset, q, search, sort |
wazuh_list_mitre_techniques | List MITRE ATT&CK techniques known to the Wazuh manager, useful for mapping alerts to the MITRE framework. | optional limit, offset, q, search, sort |
wazuh_list_rule_files | List all rule files loaded in the Wazuh manager. | optional limit, offset, search, sort |
wazuh_list_rule_groups | List all available rule groups in the Wazuh manager. | optional limit, offset, search, sort |
wazuh_list_rules | List Wazuh rules with optional filtering by level, group, filename, or status. | optional filename, group, level, limit, offset, q, search, sort, status |
wazuh_list_sca_policies | List Security Configuration Assessment (SCA) policies evaluated on an agent, showing compliance scores. | required agent_id |
wazuh_list_syscheck_results | Get File Integrity Monitoring (FIM) scan results for an agent, showing file changes detected. | required agent_idoptional event_type, file, limit, offset, q, search, sort |
wazuh_list_syscollector_packages | List installed packages/software on an agent with optional filtering. | required agent_idoptional limit, offset, q, search, sort |
wazuh_list_syscollector_ports | List open network ports on an agent. | required agent_idoptional limit, offset, q, sort |
wazuh_list_syscollector_processes | List running processes on an agent. | required agent_idoptional limit, offset, q, search, sort |
wazuh_remove_agent_from_group | Remove an agent from a specific group. | required group_id, agent_id |
wazuh_restart_agents | Restart one or more Wazuh agents by their IDs. This forces agents to reload their configuration. | required agents_list |
wazuh_restart_manager | Restart the Wazuh manager. This will briefly interrupt agent connections. | — |
wazuh_run_active_response | Execute an active response command on one or more agents (e.g., block an IP, restart a service). | required command, agents_listoptional alert, arguments |
wazuh_run_logtest | Test a log sample against the current rules and decoders. Useful for validating rule behavior before deployment. | required event, log_formatoptional location, token |
wazuh_run_syscheck_scan | Trigger a File Integrity Monitoring (FIM) scan on one or more agents. | required agents_list |
wazuh_upgrade_agents | Upgrade one or more Wazuh agents to the latest available version. | required agents_list |
