MCP server for the MITRE ATT&CK knowledge base: map alerts to techniques, profile threat groups, analyze detection coverage, and enrich SOC workflows from an AI client.
-
Updated
Jul 14, 2026 - TypeScript
MCP server for the MITRE ATT&CK knowledge base: map alerts to techniques, profile threat groups, analyze detection coverage, and enrich SOC workflows from an AI client.
Point an agent at your homelab and it can nuke a VM. proxmox-mcp gates every write before the Proxmox API sees it, so an AI client can operate the cluster without owning it.
Your SIEM answers live behind a console you babysit. wazuh-mcp reads Wazuh alerts, agents, and CVEs straight into your AI client. Read-only, nothing leaves the box.
Your photo library outgrew the click-grid. immichctrl gives shells, cron, and agents one typed control surface for Immich, with writes off by default.
One bad call can take down your DNS filtering. adguardctrl gates every AdGuard Home write behind confirm and destructive flags. CLI plus MCP adapter, no daemon.
MISP threat intel lives in tabs you never finish reading. misp-mcp turns events, attributes, and IOC lookups into answers your AI client pulls on demand.
A hallucinated call can mute a real alert. librenmsctrl gives shells, cron, and agents one stdio control surface for LibreNMS devices, ports, and alerts, writes gated.
Analysts click through a dozen Cortex jobs by hand. cortex-mcp detonates the indicator and hands your agent one aggregated verdict. Destructive actions stay confirm-gated.
n8n automations are locked behind its own UI. n8nctrl hands workflow inspect, validate, run, and ops to shells, cron, and agents over CLI plus MCP.
MCP server for Suricata IDS/IPS and Zeek NSM: analyze EVE JSON alerts, hunt threats, and manage rules from an AI client
MCP server for TheHive: AI-driven incident response, case management, alerts, observables, and Cortex analyzers (SOAR).
Five operator CLIs kept re-implementing the same HTTP, config, and error skeleton. effect-operator-kit owns it once: typed config, a request kernel, retries, redaction, and MCP helpers on Effect.
Public profile and default community files for Lidless Labs.
Shared dark-watch theme, OG card, README banner pipeline, SEO head, and tool-version sync for the Lidless Labs hub site.
MCP server for Zeek + Suricata network security monitoring logs. Query, hunt, and correlate NSM telemetry from an AI client.
Add a description, image, and links to the lidless-labs topic page so that developers can more easily learn about it.
To associate your repository with the lidless-labs topic, visit your repo's landing page and select "manage topics."