# io.github.trickyfalcon/mcp-defender

> Use this tool when you need to simplify threat hunting and incident response by translating natural language into executable KQL queries against Microsoft Defender Advanced Hunting. It solves problems of complex query formulation and facilitates swift investigation of security threats. The tool takes natural language inputs and outputs executable KQL queries, making it ideal for security analysts and threat hunters working with Microsoft Defender.

Canonical page: https://skillsregistry.net/skills/io-github-trickyfalcon-mcp-defender  
JSON: https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-defender

## Description

Execute KQL queries against Microsoft Defender Advanced Hunting via natural language.

## Trust

- **Trust score (0–1):** 0.70
- **Verification tier:** unverified

## Facts

- **Version:** 0.1.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-05-09

## Source

- **Source listing:** [MCP Registry](https://registry.modelcontextprotocol.io/v0/servers/io.github.trickyfalcon%2Fmcp-defender)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "io-github-trickyfalcon-mcp-defender"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-defender` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-defender/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
