# MCP Defender (mcp-msdefenderkql)

> Use this tool when you need to investigate security events using natural language, as it translates queries to KQL and executes them against Microsoft Defender Advanced Hunting. It solves problems related to security threat analysis and incident response by providing an intuitive interface for AI assistants to query Defender data. It takes natural language inputs and returns relevant security event data as output.

Canonical page: https://skillsregistry.net/skills/trickyfalcon-mcp-defender  
JSON: https://api.skillsregistry.net/v1/skills/trickyfalcon-mcp-defender

## Description

An MCP server for Microsoft Defender Advanced Hunting that enables AI assistants to investigate security events using natural language by translating queries to KQL and executing them against Defender.

## Trust

- **Trust score (0–1):** 0.70
- **Verification tier:** verified
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-01

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/s83dh1fd6w)
- **Repository:** <https://github.com/trickyfalcon/mcp-defender>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "trickyfalcon-mcp-defender"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/trickyfalcon-mcp-defender` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/trickyfalcon-mcp-defender/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
