pulsemcp verified Safe content atomic mcp-remote

Microsoft Sentinel

The Microsoft Sentinel MCP Server provides security analysts with direct access to Microsoft Sentinel's threat hunting and investigation capabilities through the Model Context Protocol. Built by Daniel Streefkerk, this Python implementation integrates with Azure services to enable KQL query execution, analytics rule management, incident investigation, and threat intelligence lookups. The server includes robust authentication handling, caching mechanisms, and error management while offering a comprehensive set of tools for security operations - from basic workspace information retrieval to advanced hunting queries and MITRE ATT&CK framework mappings. It's designed for security professionals who need to leverage Sentinel's capabilities within MCP-compatible environments like Claude.

Cognium trust score
100%
Tier
Verified

Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.

Scan details: Circle-IR · 2026-09-28 · Appeal

View full trust & usage report →

Metadata

Version
1.0.0
Skill type
atomic
Execution layer
mcp-remote
Category
cloud-infra
Source
PulseMCP
Author type
human
Last scanned
2026-09-28
Updated
2026-09-28
View source Find related skills

Use via MCP

MCP

Resolve Microsoft Sentinel from your agent

Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.

One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.

claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Swap --scope user for --scope project to commit it to .mcp.json.

Search SkillsRegistry