MCP Server that integrates with Security Copilot, Sentinel and other tools
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-securitycopilotmcpserver","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Security Copilot and Sentinel MCP Server A Python-based MCP server using FastMCP library that provides integration with Microsoft Security Copilot and Microsoft Sentinel using Azure Identity Authentication.  ## Overview This project implements an MCP server that enables: - Running KQL queries against Microsoft Sentinel - Uploading/Updating Microsoft Security Copilot skillsets/plugins - Running prompts and skills in Microsoft Security Copilot The server acts as a bridge between development environments and Microsoft Security Copilot, allowing for testing, deployment, and execution of skills and plugins. It uses SSE as transport layer for the MCP server. There are many use cases for the current integration. One of the most interesting ones is to support the development, test and deployment of Security Copilot KQL Skills.   ## Features - **Sentinel Integration**: Execute KQL queries against your Sentinel workspace - **Security Copilot Management**: - List existing skillsets/plugins - Upload new or update existing skillsets/plugins - Run prompts or skills within Security Copilot - **Authentication Support**: Multiple authentication methods including interactive browser, client secret, and managed identity ## Roadmap The next features will include: - **Promptbook test and Update** - **Run Advance Hunting queries in Defender XDR** ## Prerequisites - Python 3.8+ - Microsoft Sentinel workspace - Microsoft Security Copilot access - Appropriate Azure permissions for Sentinel and Security Copilot ## Installation 1. Clone the repository: ``` git clone https://github.com/jguimera/SecurityCopilotMCPServer.git cd SecurityCopilotMCPServer ``` 2. Install dependencies: ``` pip install -r requirements.txt ``` 3. Create a `.env` file with the following configuration: ``` #Add App Reg to use ClientID and Secret authentication #AZURE_TENANT_ID=your_tenant_…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.