dstreefkerk/ms-sentinel-mcp-server

MCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed for use with Claude and other LLMs.

47
/ 100
Emerging

This tool helps security analysts and operations engineers interact with Microsoft Sentinel and Entra ID in test environments. It takes your Azure authentication and provides a queryable interface to access Sentinel logs, incidents, analytics rules, and user/group data from Entra ID. The output allows you to explore security data, validate KQL queries, and analyze threat intelligence without direct console access.

Use this if you are a security analyst or operations engineer needing to explore or test security data and KQL queries in a non-production Microsoft Sentinel environment, especially when working with LLMs.

Not ideal if you need to connect to a production Sentinel instance or require write operations, as this tool is strictly for read-only access in test environments.

security-operations threat-hunting security-analytics incident-response cybersecurity-testing
No Package No Dependents
Maintenance 10 / 25
Adoption 6 / 25
Maturity 15 / 25
Community 16 / 25

How are scores calculated?

Stars

15

Forks

7

Language

Python

License

MIT

Last pushed

Jan 14, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/dstreefkerk/ms-sentinel-mcp-server"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.