Awesome AI for Infra › Security Monitoring

gensecaihq/Wazuh-MCP-Server

⭐ 248 Python added to this list on 2026-08-10 repository created 2025-03-13

Wazuh MCP Server is a Model Context Protocol server that puts a Wazuh SIEM deployment behind a conversational AI interface. It publishes 55 security tools covering alerts, agents, vulnerabilities, threat analysis, compliance and cluster/system state, so an assistant can query alert data through the Wazuh Indexer, inspect agent health, running processes, open ports and configuration, list CVEs by severity or package, score risk, look up IOC reputation and generate security reports. Active-response tools let the model act on findings, for example blocking a source IP through firewall-drop on a specific agent. Compliance tooling scores a deployment against PCI-DSS, HIPAA, SOX, GDPR and NIST, and includes an ISO 27001:2022 dashboard with Annex A control mapping, gap analysis and SCA policy checks. The server speaks both the 2026-07-28 MCP specification and the legacy protocol era, and works with any compliant client: Claude Desktop, mcphost, Open WebUI, or IBM mcp-cli. Because it is a plain tool server, the model provider is interchangeable — teams that cannot send SIEM data to cloud APIs can run it fully on-premises against local models served by Ollama, making the whole setup air-gappable. Multi-cluster deployments are supported, and Open WebUI can connect to the /mcp endpoint natively to give a whole SOC team AI-assisted analysis with conversation history and role-based access control. Every tool call is validated, rate-limited, scope-checked and audit-logged. It is written in Python 3.11+, ships a container image on GHCR and a docker compose setup, and targets Wazuh 4.8.0 through 4.14.7. The audience is security operations teams that want to replace dashboard juggling and hand-written API queries with natural-language triage and investigation over their existing Wazuh installation.

https://github.com/gensecaihq/Wazuh-MCP-Server

siemwazuhmcpsecopsthreat-huntingincident-responsecompliancevulnerability-management

Also in Security Monitoring

beenuar/AiSOC

AiSOC is an open-source, self-hostable AI-powered Security Operations Center that ingests, correlates, and investigates security events using AI, providing a transparent investigation ledger.

backbay-labs/clawdstrike

Clawdstrike is an AI-powered Endpoint Detection and Response (EDR) system providing policy enforcement, a signed audit chain, and threat detection for developer workstations and autonomous agent fl...