# xsiam-mcp

> xsiam-mcp — coveosec-xsiam-mcp. Use this tool when you need to integrate with Palo Alto Cortex XSIAM and leverage its REST API for security data investigation and analysis. It solves problems related to security threat detection, incident response, and data querying by providing 129 operations across 26 categories. The tool takes in API requests and returns security data, making it ideal for use cases involving AI-driven security analytics and threat hunting.

Canonical page: https://skillsregistry.net/skills/coveosec-xsiam-mcp  
JSON: https://api.skillsregistry.net/v1/skills/coveosec-xsiam-mcp

## Description

Exposes the entire Palo Alto Cortex XSIAM REST API (129 operations across 26 categories) as MCP tools, plus composite tools like xql_query for AI agents to search and investigate security data.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-08-30

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-08-30

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/hcsywbhegf)
- **Repository:** <https://github.com/CoveoSec/xsiam-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "coveosec-xsiam-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/coveosec-xsiam-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/coveosec-xsiam-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
