- Conduid
- Marketplace
- #incident-response
MCP servers tagged incident-response
16 live MCP servers tagged "incident-response", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with incident-response.
Anthropic Cybersecurity Skills
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini…
Volatility3
Volatility 3.0 development
AiSOC
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Attackgen
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tail…
Coroot MCP
Community MCP server that exposes Coroot incidents and health summaries as read-only tools for AI assistants (not an official Coroot product).
Vigil
Vigil - a 100% OpenSource AI system for machine-speed network defense
Unpage
Unpage is the open source framework for building SRE agents with infrastructure context and secure access to any dev tool.
Valhuntir
Valhuntir CLI — AI-augmented incident response platform
Awesome Agentic Devops
Curated + scored map of official MCP servers and agents for DevOps, Cloud, SRE, and Platform Engineering — every entry rated on production access, approval gates, and audit eviden…
Wazuh Autopilot
Autonomous AI SOC for Wazuh SIEM — 11 security-expert agents triage, correlate, investigate and plan responses 24/7, every action gated by two-tier human approval. Runs on OpenCla…
Agent Runbook
MCP server for agent-runbook-generator — Model Context Protocol tool registry
Pypi
FastMCP server exposing ResQ platform capabilities—including digital twin simulations, drone coordination, and incident response—to AI clients like Claude Desktop and Cursor.
Agentic Dart
Agentic-DART — autonomous detection & response agent. Architecture-first, not prompt-first. Starts as agentic DFIR; designed to expand toward agentic SOC and beyond.
Dfireballz
AI-native digital forensics & cybercrime investigation platform. 7 MCP servers (Volatility3, Ghidra, Wireshark, OSINT, threat-intel & more) orchestrated by Claude, ChatGPT, or Oll…
Acornops
Open-source, self-hosted AI-assisted operations for Kubernetes and Linux. Start here for source, architecture, deployment, and contributions.
Vo Soc Harness
Harness de operaciones de ciberseguridad sobre Trend Micro Vision One: agentes de IA que hacen triage, investigan IOCs, ejecutan la contención y documentan la alerta. Incluye el s…