Enables cybersecurity training, purple-team collaboration, and executive readiness through tools for scenario generation, attack simulation, telemetry analysis, incident investigation, forensics, and reporting with an immutable audit trail.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.CYBERSIM_API_KEY— require Authorization: Bearer <key> headerCYBERSIM_APPROVAL_TOKEN— shared secret required for restricted tools (simulate_attack, stop_simulation, replay_telemetry)CYBERSIM_AUDIT_CHAIN_ID— Enable hash-chained logging by setting CYBERSIM_AUDIT_HMAC_KEY (optionally supply for multi-tenant tracking).CYBERSIM_AUDIT_HMAC_KEY— Enable hash-chained logging by setting (optionally supply CYBERSIM_AUDIT_CHAIN_ID for multi-tenant tracking).CYBERSIM_AUDIT_HMAC_KEY_ENCODINGCYBERSIM_AUDIT_HMAC_KEY_IDCYBERSIM_AUDIT_LOG_DIR— Every tool invocation is appended to logs/audit.log (configurable via ) and chained with SHA-256 hashes plus optional HMAC signatures (CYBERSIM_AUDIT_HMAC_KEY, CYBERSIM_AUDIT_CHAIN_ID).CYBERSIM_AUDIT_SEAL_KEY— Use (or reuse the HMAC key) to sign exported seals; set _ENCODING=base64 when providing base64 secrets.CYBERSIM_AUDIT_SEAL_KEY_ENCODINGCYBERSIM_AUDIT_SEAL_KEY_IDCYBERSIM_AUDIT_VALIDATION_HMAC_KEYCYBERSIM_AUDIT_VALIDATION_HMAC_KEY_ENCODINGCYBERSIM_IP_ALLOW— comma-separated list (127.0.0.1,::1,local,203.0.113.10)CYBERSIM_RBAC_CONFIG— optional path to a JSON role policy (see [Role-Based Access & Approvals](#role-based-access--approvals))CYBERSIM_SCIM_TOKEN— SCIM v2 endpoints (/api/scim/v2/Users, /api/scim/v2/Groups) require identity.scim.bearerToken or ; weekly audit seal workflow captures provisioning evidence.PORT[](https://m8ven.ai/mcp/kayembahamid-cybersim-pro-znh5di)