MCP server exposing Wazuh SIEM (manager + indexer) operations to AI clients, with false-positive rule-tuning tooling and an Atomic Red Team integration layer.
Or install with pip: pip install ai-detection-engineering-platform
README Excerpt
**An AI-driven detection-engineering platform for Wazuh.** Investigate alerts, hunt threats, tune false positives, edit and validate detection rules, and run Atomic Red Team validations across your Wazuh deployment — by talking to any AI assistant. Built as a Model Context Protocol (MCP) server. > **v4.2.1** | 48 security tools | Wazuh 4.8.0–4.14.4 | [Changelog](CHANGELOG.md)