gensecaihq/Wazuh-MCP-Server

AI-powered security operations for Wazuh SIEM—use any MCP-compatible client to ask security questions in plain English. Faster threat detection, incident triage, and compliance checks with real-time monitoring and anomaly spotting. Production-ready MCP server for conversational SOC workflows.

57
/ 100
Established

This project helps security operations teams manage their Wazuh SIEM more efficiently. It allows security analysts to ask plain English questions about alerts, threats, and vulnerabilities, and receive actionable responses. By connecting to any AI assistant, security teams can investigate security events, hunt for threats, and perform incident response actions using natural language.

137 stars.

Use this if you are a SOC analyst, incident responder, or security engineer who wants to interact with your Wazuh SIEM using conversational AI to speed up threat detection and response.

Not ideal if you do not use Wazuh as your Security Information and Event Management (SIEM) system.

Security Operations Threat Detection Incident Response Vulnerability Management Compliance Monitoring
No Package No Dependents
Maintenance 10 / 25
Adoption 10 / 25
Maturity 16 / 25
Community 21 / 25

How are scores calculated?

Stars

137

Forks

39

Language

Python

License

MIT

Last pushed

Mar 11, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/gensecaihq/Wazuh-MCP-Server"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.