Wazuh-MCP-Server and mcp-server-wazuh

These are competing implementations of the same MCP interface to Wazuh SIEM, with A emphasizing AI-powered natural language queries while B provides a more basic server implementation, making them alternatives rather than complementary tools.

Wazuh-MCP-Server
57
Established
mcp-server-wazuh
53
Established
Maintenance 10/25
Adoption 10/25
Maturity 16/25
Community 21/25
Maintenance 6/25
Adoption 10/25
Maturity 15/25
Community 22/25
Stars: 137
Forks: 39
Downloads:
Commits (30d): 0
Language: Python
License: MIT
Stars: 184
Forks: 49
Downloads:
Commits (30d): 0
Language: Rust
License: MIT
No Package No Dependents
No Package No Dependents

About Wazuh-MCP-Server

gensecaihq/Wazuh-MCP-Server

AI-powered security operations for Wazuh SIEM—use any MCP-compatible client to ask security questions in plain English. Faster threat detection, incident triage, and compliance checks with real-time monitoring and anomaly spotting. Production-ready MCP server for conversational SOC workflows.

This project helps security operations teams manage their Wazuh SIEM more efficiently. It allows security analysts to ask plain English questions about alerts, threats, and vulnerabilities, and receive actionable responses. By connecting to any AI assistant, security teams can investigate security events, hunt for threats, and perform incident response actions using natural language.

Security Operations Threat Detection Incident Response Vulnerability Management Compliance Monitoring

About mcp-server-wazuh

gbrigandi/mcp-server-wazuh

MCP Server for Wazuh SIEM

This project helps security and compliance teams quickly understand their security posture by translating complex Wazuh SIEM data into plain language answers. You provide natural language questions about security alerts, vulnerabilities, agent status, or compliance, and it delivers structured, actionable insights from your Wazuh deployment. Security analysts, incident responders, and compliance officers would use this tool.

security-operations incident-response vulnerability-management compliance-auditing threat-hunting

Scores updated daily from GitHub, PyPI, and npm data. How scores work