mcp-panther and Wazuh-MCP-Server

The two tools are complements: Wazuh-MCP-Server provides an AI-powered security operations layer for Wazuh SIEM that can be queried by any MCP-compatible client, while panther-labs/mcp-panther offers a platform to write detections, investigate alerts, and query logs using AI agents, implying it could be an MCP-compatible client or integrate with such systems.

mcp-panther
60
Established
Wazuh-MCP-Server
57
Established
Maintenance 10/25
Adoption 7/25
Maturity 25/25
Community 18/25
Maintenance 10/25
Adoption 10/25
Maturity 16/25
Community 21/25
Stars: 41
Forks: 16
Downloads:
Commits (30d): 0
Language: Python
License: Apache-2.0
Stars: 137
Forks: 39
Downloads:
Commits (30d): 0
Language: Python
License: MIT
No risk flags
No Package No Dependents

About mcp-panther

panther-labs/mcp-panther

Write detections, investigate alerts, and query logs from your favorite AI agents

This tool helps security analysts manage their Panther security platform using natural language. You can query security logs, investigate alerts, and adjust detection rules by simply typing your requests. It takes your natural language commands and provides insights into security events, alert statuses, and system configurations.

security-operations threat-detection incident-response log-analysis security-monitoring

About Wazuh-MCP-Server

gensecaihq/Wazuh-MCP-Server

AI-powered security operations for Wazuh SIEM—use any MCP-compatible client to ask security questions in plain English. Faster threat detection, incident triage, and compliance checks with real-time monitoring and anomaly spotting. Production-ready MCP server for conversational SOC workflows.

This project helps security operations teams manage their Wazuh SIEM more efficiently. It allows security analysts to ask plain English questions about alerts, threats, and vulnerabilities, and receive actionable responses. By connecting to any AI assistant, security teams can investigate security events, hunt for threats, and perform incident response actions using natural language.

Security Operations Threat Detection Incident Response Vulnerability Management Compliance Monitoring

Scores updated daily from GitHub, PyPI, and npm data. How scores work