# Security Infrastructure

> Use this tool when you need to unify access to multiple security platforms, such as Splunk SIEM, CrowdStrike EDR, and Microsoft MISP, to perform cross-platform threat hunting and security event analysis. It solves the problem of correlated data analysis across different vendor interfaces, providing a comprehensive web interface and backend API integration for seamless interactions. The tool is ideal for Security Operations Center (SOC) operations, accepting natural language inputs and producing security event searches, detections, and threat intelligence queries as outputs.

Canonical page: https://skillsregistry.net/skills/jmstar85-security-infrastructure  
JSON: https://api.skillsregistry.net/v1/skills/jmstar85-security-infrastructure

## Description

This security infrastructure MCP server provides unified access to three major security platforms - Splunk SIEM, CrowdStrike EDR, and Microsoft MISP - through a comprehensive web interface and backend API integration. Built with Python async/await patterns and featuring both MCP server implementations and a React-based documentation frontend, it enables security analysts to perform cross-platform threat hunting, search security events, retrieve detections, and query threat intelligence through natural language interactions. The implementation includes Docker containerization, comprehensive test coverage, and a live documentation site with interactive code examples, making it valuable for SOC operations where analysts need to correlate data across multiple security tools without switching between different vendor interfaces.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/jmstar85-security-infrastructure)
- **Repository:** <https://github.com/jmstar85/securityinfrastructure>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "jmstar85-security-infrastructure"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/jmstar85-security-infrastructure` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/jmstar85-security-infrastructure/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
