mcp-panther and falcon-mcp
About mcp-panther
panther-labs/mcp-panther
Write detections, investigate alerts, and query logs from your favorite AI agents
Implements the Model Context Protocol (MCP) to expose Panther's detection, alerting, and data lake capabilities as AI agent tools—enabling natural language SQL queries against security logs, AI-powered alert triage with intelligent recommendations, and detection authoring directly from IDE-integrated agents. Provides 50+ specialized tools covering alert management (bulk operations, comments, status updates), data lake schema exploration and querying, detection lifecycle management across rules/policies, and operational metrics and access controls.
About falcon-mcp
CrowdStrike/falcon-mcp
Connect AI agents to CrowdStrike Falcon for automated security analysis and threat hunting
Implements the Model Context Protocol (MCP) standard to expose 13+ specialized security modules—including detections, incidents, identity protection, and threat intelligence—each with granular API scope requirements. Supports modular deployment with selective module activation, enabling agents to access only necessary Falcon capabilities while integrating seamlessly with Claude, Amazon Bedrock, and Google Vertex AI platforms through stdio transport.
Related comparisons
Scores updated daily from GitHub, PyPI, and npm data. How scores work