# CrowdSentinel

> Use this tool when you need to enhance threat detection and investigation capabilities by connecting language models to enterprise security data. CrowdSentinel solves problems related to natural language threat hunting, AI-guided investigation workflows, and cross-tool indicator of compromise (IoC) correlation. It accepts inputs from various sources, including Elasticsearch, OpenSearch, EVTX logs, and PCAP files, and provides outputs in multiple security framework mappings, such as MITRE ATT&CK and Cyber Kill Chain.

Canonical page: https://skillsregistry.net/skills/thomasxm-crowdsentinel  
JSON: https://api.skillsregistry.net/v1/skills/thomasxm-crowdsentinel

## Description

Connects language models to enterprise security data for natural language threat hunting, AI-guided investigation workflows, and cross-tool IoC correlation. Supports Elasticsearch, OpenSearch, EVTX logs via Chainsaw, and PCAP files via Wireshark with persistent investigation state and multiple security framework mappings including MITRE ATT&CK and Cyber Kill Chain.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/thomasxm-crowdsentinel)
- **Repository:** <https://github.com/thomasxm/crowdsentinels-ai-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "thomasxm-crowdsentinel"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/thomasxm-crowdsentinel` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/thomasxm-crowdsentinel/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
