MCP Panther
UnclaimedWrite detections, investigate alerts, and query logs from your favorite AI agents
Set up this server
More in Security
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
36 of 36 tools
Documented tools (36)
From project documentation. A server handshake does not verify each tool’s description or behavior.
add_alert_comment
Add a comment to a Panther alert
bulk_update_alerts
Bulk update multiple alerts with status, assignee, and/or comment changes
disable_detection
Disable a detection by setting enabled to false. Supports rules, scheduledrules, simplerules, and policies
get_ai_alert_triage_summary
Retrieve the latest AI triage summary previously generated for a specific alert
get_alert
Get detailed information about a specific alert
get_alert_event_stats
Analyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics
get_alert_events
Get a small sampling of events for a given alert
get_bytes_processed_metrics
Get data ingestion metrics by log type and source
get_data_model
Get detailed information about a specific data model
get_detection
Get detailed information about a specific detection including the detection body and tests. Accepts a list with one detection type: ["rules"], ["scheduledrules"], ["simplerules"], or ["policies"]
get_global_helper
Get detailed information and complete Python code for a specific global helper
get_http_log_source
Get detailed information about a specific HTTP log source by ID
get_log_type_schema_details
Get detailed information for specific log type schemas
get_permissions
Get the current user's permissions
get_role
Get detailed information about a specific role including permissions
get_rule_alert_metrics
Get metrics about alerts grouped by rule
get_scheduled_query
Get detailed information about a specific scheduled query by ID
get_severity_alert_metrics
Get metrics about alerts grouped by severity
get_table_schema
Get schema information for a specific table
get_user
Get detailed information about a specific user
list_alert_comments
List all comments for a specific alert
list_alerts
List alerts with comprehensive filtering options (date range, severity, status, etc.)
list_data_models
List data models that control UDM mappings in rules
list_database_tables
List all available tables for a specific database in Panther's data lake
list_databases
List all available data lake databases in Panther
list_detections
List detections from Panther with comprehensive filtering support. Supports multiple detection types and filtering by name, state, severity, tags, log types, resource types, output IDs (destinations), and more. Returns outputIDs for each detection showing configured alert destinations
list_global_helpers
List global helper functions with comprehensive filtering options (name search, creator, modifier)
list_log_sources
List log sources with optional filters (health status, log types, integration type)
list_log_type_schemas
List available log type schemas with optional filters
list_roles
List all roles with filtering options (name search, role IDs, sort direction)
list_scheduled_queries
List all scheduled queries with pagination support
list_users
List all Panther user accounts with pagination support
query_data_lake
Execute SQL queries against Panther's data lake with synchronous results
start_ai_alert_triage
Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations
update_alert_assignee
Update the assignee of one or more alerts
update_alert_status
Update the status of one or more alerts
Tool change history
FAQ
Questions about MCP Panther MCP Server
- How do I connect MCP Panther MCP Server to Claude?
- The project does not publish a launch command that MCPVault could verify. Open the repository linked on this page for its install steps; the listing names Claude Desktop, Claude Code, Cursor as compatible clients.
- Is MCP Panther MCP Server free?
- The listed licence is Apache-2.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can MCP Panther MCP Server do?
- MCP Panther MCP Server documents 36 tools to the agent, including add_alert_comment, bulk_update_alerts, disable_detection. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.