dstreefkerk/ms-sentinel-mcp-server

MCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed for use with Claude and other LLMs.

41
/ 100
Emerging

Implements MCP (Model Context Protocol) with Azure CLI authentication, providing read-only access to Sentinel's KQL query engine, Log Analytics schemas, and incident data alongside Entra ID directory querying—all exposed as discrete tools for LLM consumption. Built around modular tool categories (KQL, incidents, analytics rules, hunting queries, threat intelligence) with built-in KQL validation and mock-data testing to catch query errors before execution. Designed for test/non-production environments only, with explicit warnings against connecting to production Sentinel or public LLMs due to exposure of sensitive security and directory metadata.

No Package No Dependents
Maintenance 10 / 25
Adoption 6 / 25
Maturity 9 / 25
Community 16 / 25

How are scores calculated?

Stars

15

Forks

7

Language

Python

License

MIT

Last pushed

Jan 14, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/dstreefkerk/ms-sentinel-mcp-server"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.