Model Context Protocol server for Wazuh Manager integration
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-socfortress-wazuh-mcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Wazuh MCP Server A production-ready **Model Context Protocol (MCP) server** for seamless integration between Wazuh SIEM and Large Language Models (LLMs). [](https://github.com/socfortress/wazuh-mcp-server/actions) [](https://www.python.org/downloads/) [](https://www.youtube.com/@taylorwalton_socfortress/videos) [](https://www.socfortress.co/contact_form.html) > **Why?** > Combine the power of Wazuh's comprehensive security monitoring with the reasoning capabilities of large language models—enabling natural language queries and intelligent analysis of your security data. --- ## ✨ Key Features - 🚀 **Production-ready**: Proper package structure, logging, error handling, and configuration management - 🔐 **Secure**: JWT token management with automatic refresh - 🌐 **HTTP/2 Support**: Built on modern async HTTP client with connection pooling - 📊 **Comprehensive API**: Access Wazuh agents, authentication, and more - 🎛️ **Configurable**: Environment variables, CLI arguments, and fine-grained tool filtering - 📦 **Pip installable**: Install directly from GitHub releases or source --- ## Table of Contents - [Quick Start](#quick-start) - [Installation](#installation) - [Configuration](#configuration) - [Usage](#usage) - [Available Tools](#available-tools) - [Development](#development) - [CI/CD](#continuous-integration) - [Deployment](#deployment) - [Security](#security-considerations) - [Contributing](#contributing) - [License](#license) --- ## Quick Start ### 1. Install #### From GitHub (Recommended) ```bash python -m venv .venv && source .venv/bin/activate pip inst…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.