{"id":"089f306c-aaea-4852-9abe-77b2ca4d2cda","shortId":"9zfhUj","kind":"mcp","title":"Microsoft Sentinel","tagline":"Integrates with Microsoft Sentinel to enable security analysts to execute KQL queries, manage analytics rules, invest...","description":"Integrates with Microsoft Sentinel to enable security analysts to execute KQL queries, manage analytics rules, investigate incidents, and perform threat intelligence lookups directly from their AI environment.\n\nThe Microsoft Sentinel MCP Server provides security analysts with direct access to Microsoft Sentinel's threat hunting and investigation capabilities through the Model Context Protocol. Built by Daniel Streefkerk, this Python implementation integrates with Azure services to enable KQL query execution, analytics rule management, incident investigation, and threat intelligence lookups. The server includes robust authentication handling, caching mechanisms, and error management while offering a comprehensive set of tools for security operations - from basic workspace information retrieval to advanced hunting queries and MITRE ATT&CK framework mappings. It's designed for security professionals who need to leverage Sentinel's capabilities within MCP-compatible environments like Claude.","tags":["microsoft","sentinel"],"capabilities":["mcp","transport-stdio","open-source"],"categories":[],"synonyms":[],"warnings":[],"endpointUrl":"https://github.com/dstreefkerk/ms-sentinel-mcp-server","protocol":"mcp","transport":"stdio","auth":{"type":"mcp","details":{"transport":"stdio"}},"qualityScore":"0.584","qualityRationale":"deterministic score 0.58 from registry signals: · indexed on pulsemcp · has source repo · 17 github stars · registry-generated description present","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:mcp:v1","enrichmentVersion":1,"enrichedAt":"2026-04-22T00:23:46.885Z","embedding":null,"createdAt":"2026-04-21T19:27:47.831Z","updatedAt":"2026-04-22T00:23:46.885Z","lastSeenAt":"2026-04-22T00:23:46.885Z","tsv":"'access':56 'advanc':123 'ai':44 'analyst':10,26,53 'analyt':16,32,87 'att':128 'authent':100 'azur':80 'basic':118 'built':71 'cach':102 'capabl':65,144 'ck':129 'claud':151 'compat':148 'comprehens':110 'context':69 'daniel':73 'design':134 'direct':41,55 'enabl':8,24,83 'environ':45,149 'error':105 'execut':12,28,86 'framework':130 'handl':101 'hunt':62,124 'implement':77 'incid':35,90 'includ':98 'inform':120 'integr':3,19,78 'intellig':39,94 'invest':18 'investig':34,64,91 'kql':13,29,84 'leverag':141 'like':150 'lookup':40,95 'manag':15,31,89,106 'map':131 'mcp':49,147 'mcp-compat':146 'mechan':103 'microsoft':1,5,21,47,58 'mitr':127 'model':68 'need':139 'offer':108 'open-source' 'oper':116 'perform':37 'profession':137 'protocol':70 'provid':51 'python':76 'queri':14,30,85,125 'retriev':121 'robust':99 'rule':17,33,88 'secur':9,25,52,115,136 'sentinel':2,6,22,48,59,142 'server':50,97 'servic':81 'set':111 'streefkerk':74 'threat':38,61,93 'tool':113 'transport-stdio' 'within':145 'workspac':119","prices":[{"id":"ce6018f7-2d9c-4270-819d-b2c95fa1fe02","listingId":"089f306c-aaea-4852-9abe-77b2ca4d2cda","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"mcp-free","isPrimary":true,"details":{"transport":"stdio"},"createdAt":"2026-04-21T19:27:47.831Z"}],"sources":[{"listingId":"089f306c-aaea-4852-9abe-77b2ca4d2cda","source":"pulsemcp","sourceId":"https://www.pulsemcp.com/servers/dstreefkerk-ms-sentinel","sourceUrl":"https://api.pulsemcp.com/v0beta/servers","isPrimary":true,"firstSeenAt":"2026-04-21T19:27:47.831Z","lastSeenAt":"2026-04-22T00:23:46.885Z"}],"details":{"listingId":"089f306c-aaea-4852-9abe-77b2ca4d2cda","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"source":"pulsemcp","transport":"stdio","server_name":"Microsoft Sentinel","github_stars":17,"registry_url":"https://www.pulsemcp.com/servers/dstreefkerk-ms-sentinel","source_code_url":"https://github.com/dstreefkerk/ms-sentinel-mcp-server"},"updatedAt":"2026-04-22T00:23:46.885Z"}}