58
grade D
10 days ago
glama

wazuh-mcp

An MCP server for the Wazuh SIEM/XDR platform that enables users to query agents, security alerts, detection rules, and decoders through Claude or other MCP clients. It provides specialized tools and prompts for investigating security alerts, performing agent health checks, and generating environmental security overviews.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: WAZUH_INDEXER_PASSWORD, WAZUH_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configWAZUH_BASE_URLAlternative variable names and WAZUH_USER are also supported.
🔐 secretWAZUH_INDEXER_PASSWORDNo - Indexer password
configWAZUH_INDEXER_URLNo - Wazuh Indexer URL (e.g., https://10.0.0.2:9200)
configWAZUH_INDEXER_USERNAMENo admin Indexer username
configWAZUH_INDEXER_VERIFY_SSLNo false Set to true to verify SSL certificates
🔐 secretWAZUH_PASSWORDYes - API password
configWAZUH_TIMEOUT
configWAZUH_URLYes - Wazuh API URL (e.g., https://10.0.0.2:55000)
configWAZUH_USERAlternative variable names WAZUH_BASE_URL and are also supported.
configWAZUH_USERNAMEYes - API username
configWAZUH_VERIFY_SSLNo false Set to true to verify SSL certificates
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/solomonneas-wazuh-mcp-7r68a2)](https://m8ven.ai/mcp/solomonneas-wazuh-mcp-7r68a2)
commit: c6a2c3a8a7119f57767d36cd4ae30bfc8ab1c556
code hash: ea4125bb11fdbe9239b0054500266a653d72ccb033d82bb4c0958a4e5d13ad54
verified: 4/11/2026, 3:10:01 PM
view raw JSON →