{"repo":"thomasxm/CrowdSentinels-AI-MCP","free":true,"listed":false,"github":"https://github.com/thomasxm/CrowdSentinels-AI-MCP","clone":"git clone https://github.com/thomasxm/CrowdSentinels-AI-MCP.git","description":"AI-powered threat hunting and incident response MCP server for Elasticsearch/OpenSearch","language":"Python","stars":206,"topics":[],"license":"GPL-3.0","category":"mcp-servers","readme_excerpt":"CrowdSentinel MCP Server AI-Powered Threat Hunting & Incident Response Framework MCP Official Registry · PyPI Package Open-source threat hunting orchestrator connecting LLMs to enterprise security data via Model Context Protocol (MCP) Quick Start · Installation · CLI Usage · Features · Architecture · Documentation · Examples Warning This project is in active development and intended for security testing, research, and educational purposes only . It is not production-ready. Do not deploy in production environments. APIs, tool interfaces, and data formats may change without notice. Use at your own risk. --- Demo https://github.com/user-attachments/assets/0d0381f0-5b68-43b2-8630-19ec130885b2 --- What is CrowdSentinel? CrowdSentinel transforms traditional SIEM querying into intelligent, framework-driven investigations using natural language. It serves as a unified security intelligence layer that connects large language models to enterprise security data sources, enabling: - Natural Language Threat Hunting — Query Elasticsearch using plain English - AI-Guided Investigation Workflows — Built-in prompts guide agents through proper IR methodology - Persistent Investigation State — Memory-managed IoC tracking, forensic timelines, and cross-query correlation that survives across sessions (8GB FIFO storage) - Cross-Tool IoC Correlation — IoCs discovered in one tool are automatically available to all others - Multi-Source Analysis — Elasticsearch, EVTX logs (Chainsaw), PCAP files (Wires","default_branch":null,"files":null,"tree":[],"storefront":"/r/thomasxm","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/thomasxm/CrowdSentinels-AI-MCP/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}