ms-sentinel-mcp-server

dstreefkerk/ms-sentinel-mcp-server
★ 18 stars Unknown language AI/LLM Updated today
MCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed for use with Claude and other LLMs.
View on GitHub → Try with Claude — $10 free →

Quick Install

Copy the config for your editor. Some servers may need additional setup — check the README.

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "ms-sentinel-mcp-serv": {
      "command": "npx",
      "args": [
        "-y",
        "dstreefkerk/ms-sentinel-mcp-server"
      ]
    }
  }
}

Topics

azurellm-integrationlog-analyticsmcpmcp-servermicrosoft-sentinelthreat-intelligence