MCP Panther logo

MCP Panther

Unclaimed

by panther-labs

Write detections, investigate alerts, and query logs from your favorite AI agents

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
aicybersecuritymcp-serversecurity-operations

More in Security

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

36 of 36 tools

Documented tools (36)

From project documentation. A server handshake does not verify each tool’s description or behavior.

add_alert_comment

Add a comment to a Panther alert

bulk_update_alerts

Bulk update multiple alerts with status, assignee, and/or comment changes

disable_detection

Disable a detection by setting enabled to false. Supports rules, scheduledrules, simplerules, and policies

get_ai_alert_triage_summary

Retrieve the latest AI triage summary previously generated for a specific alert

get_alert

Get detailed information about a specific alert

get_alert_event_stats

Analyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics

get_alert_events

Get a small sampling of events for a given alert

get_bytes_processed_metrics

Get data ingestion metrics by log type and source

get_data_model

Get detailed information about a specific data model

get_detection

Get detailed information about a specific detection including the detection body and tests. Accepts a list with one detection type: ["rules"], ["scheduledrules"], ["simplerules"], or ["policies"]

get_global_helper

Get detailed information and complete Python code for a specific global helper

get_http_log_source

Get detailed information about a specific HTTP log source by ID

get_log_type_schema_details

Get detailed information for specific log type schemas

get_permissions

Get the current user's permissions

get_role

Get detailed information about a specific role including permissions

get_rule_alert_metrics

Get metrics about alerts grouped by rule

get_scheduled_query

Get detailed information about a specific scheduled query by ID

get_severity_alert_metrics

Get metrics about alerts grouped by severity

get_table_schema

Get schema information for a specific table

get_user

Get detailed information about a specific user

list_alert_comments

List all comments for a specific alert

list_alerts

List alerts with comprehensive filtering options (date range, severity, status, etc.)

list_data_models

List data models that control UDM mappings in rules

list_database_tables

List all available tables for a specific database in Panther's data lake

list_databases

List all available data lake databases in Panther

list_detections

List detections from Panther with comprehensive filtering support. Supports multiple detection types and filtering by name, state, severity, tags, log types, resource types, output IDs (destinations), and more. Returns outputIDs for each detection showing configured alert destinations

list_global_helpers

List global helper functions with comprehensive filtering options (name search, creator, modifier)

list_log_sources

List log sources with optional filters (health status, log types, integration type)

list_log_type_schemas

List available log type schemas with optional filters

list_roles

List all roles with filtering options (name search, role IDs, sort direction)

list_scheduled_queries

List all scheduled queries with pagination support

list_users

List all Panther user accounts with pagination support

query_data_lake

Execute SQL queries against Panther's data lake with synchronous results

start_ai_alert_triage

Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations

update_alert_assignee

Update the assignee of one or more alerts

update_alert_status

Update the status of one or more alerts

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about MCP Panther MCP Server

How do I connect MCP Panther MCP Server to Claude?
The project does not publish a launch command that MCPVault could verify. Open the repository linked on this page for its install steps; the listing names Claude Desktop, Claude Code, Cursor as compatible clients.
Is MCP Panther MCP Server free?
The listed licence is Apache-2.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can MCP Panther MCP Server do?
MCP Panther MCP Server documents 36 tools to the agent, including add_alert_comment, bulk_update_alerts, disable_detection. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.