MCP Defender (mcp-msdefenderkql)
An MCP server for Microsoft Defender Advanced Hunting that enables AI assistants to investigate security events using natural language by translating queries to KQL and executing them against Defender.
Security & IAM
0 platforms
0 features
Install
uvx mcp-msdefenderkql
Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
{
"mcpServers": {
"mcp-defender": {
"command": "uvx",
"args": [
"mcp-msdefenderkql"
],
"env": {
"AZURE_CLIENT_ID": "<AZURE_CLIENT_ID>",
"AZURE_TENANT_ID": "<AZURE_TENANT_ID>",
"AZURE_CLIENT_SECRET": "<AZURE_CLIENT_SECRET>",
"AZURE_CLIENT_CERTIFICATE_PATH": "<AZURE_CLIENT_CERTIFICATE_PATH>"
}
}
}
}Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
Sources: public MCP Server directories. This is an independent third-party directory with no affiliation to or endorsement from the maintainers of the listed servers.