An MCP server for Security Onion Community Edition that provides 21 read and write tools for SOC operations, including event querying, alert management, detection tuning, PCAP retrieval, and agent enrollment, without requiring a Pro license.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.SO_API_ENDPOINTSO_OS_USER— / SO_OS_PASSWORD so_elastic + its password (sudo cat /opt/so/conf/elasticsearch/curl.config on the manager)SO_OS_PASSWORD— SO_OS_USER / so_elastic + its password (sudo cat /opt/so/conf/elasticsearch/curl.config on the manager)SO_CA_CERT— SO_API_VERIFY_SSL false for a lab self-signed cert, or set and trueSO_API_VERIFY_SSL— false for a lab self-signed cert, or set SO_CA_CERT and trueSO_SSH_HOST— / SO_SSH_USER / SO_SSH_PASSWORD manager IP + a sudo-capable accountSO_SSH_PORTSO_SSH_USER— SO_SSH_HOST / / SO_SSH_PASSWORD manager IP + a sudo-capable accountSO_SSH_PASSWORD— SO_SSH_HOST / SO_SSH_USER / manager IP + a sudo-capable accountSO_SSH_HOSTKEY— the manager's ed25519 fingerprint — pin it (see .env.example for the one-liner)SO_ENABLE_FILE_LOGGINGSO_DEFAULT_TIME_RANGE[](https://m8ven.ai/mcp/rudraverma-securityonion-ce-mcp-1iwb13)