{"repo":"gensecaihq/Wazuh-MCP-Server","free":true,"listed":false,"github":"https://github.com/gensecaihq/Wazuh-MCP-Server","clone":"git clone https://github.com/gensecaihq/Wazuh-MCP-Server.git","description":"Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. Connect Claude or any LLM to your SOC. OAuth 2.1, RBAC, multi-cluster, air-gap ready.","language":"Python","stars":221,"topics":["ai","claude","mcp","mcp-server","model-context-protocol","python","wazuh","active-response","compliance","cybersecurity"],"license":"MIT","category":"mcp-servers","readme_excerpt":"🛡️ Wazuh MCP Server Talk to your SIEM in plain language. Query alerts, hunt threats, triage vulnerabilities, and run active responses across your entire Wazuh deployment — through natural conversation with any AI assistant. 55 security tools · dual-era MCP (2026-07-28 + legacy) · multi-cluster · fully air-gappable · production-hardened Quick Start · Tools · Security · Docs · Changelog · Upgrading --- What This Does Your Wazuh SIEM generates thousands of alerts, vulnerability findings, and agent events daily. Investigating them means juggling dashboards, writing API queries, and manually correlating data across tools. This MCP server turns that workflow into a conversation: It works with Claude Desktop , Open WebUI + Ollama (fully local, air-gapped), mcphost , or any MCP-compliant client. --- Works With Cloud AND Local LLMs This is a standard MCP tool server. It doesn't care what LLM you use — it just executes tools and returns results. Mode LLM Client Data leaves your network? ------ ----- -------- -------------------------- Cloud Claude, GPT, etc. Claude Desktop, any MCP client Yes (to LLM provider) Local Llama, Qwen, Mistral via Ollama Open WebUI, mcphost, IBM/mcp-cli No. Fully air-gappable. For security teams that can't send SIEM data to cloud APIs (compliance, air-gapped networks, data sovereignty), the local mode with Ollama keeps everything on-premises. Both modes coexist — same server, same tools, same API. Quick Start: Local LLM with mcphost Quick Start: Multi-User S","default_branch":null,"files":null,"tree":[],"storefront":"/r/gensecaihq","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gensecaihq/Wazuh-MCP-Server/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}