73
/ 100
10 days ago
glama

Defender Hunt MCP

Enables security investigation and threat hunting through Microsoft Defender and Entra ID, with 31 tools for KQL queries, alerts, threat intelligence, identity investigation, and advanced threat hunting.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: AZURE_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configENABLE_AGENT_GOVERNANCE_BETA
configCACHE_BACKEND
configREDIS_URL
configREDIS_HOST
configREDIS_ENTRA_USERNAME
configREDIS_PORT
configAZURE_MANAGED_IDENTITY_CLIENT_IDAzure User-assigned infrastructure identity for Redis, ACR/Key Vault, and temporary legacy Graph access.
configREDIS_KEY_PREFIX
configAZURE_TENANT_IDYes Microsoft Entra tenant ID.
configAZURE_MANAGED_IDENTITY_PRINCIPAL_ID
configLOG_LEVELNo Logging level (DEBUG, INFO, WARNING, ERROR, CRITICAL). Defaults to INFO.
configAZURE_CLIENT_IDYes App registration client ID.
🔐 secretAZURE_CLIENT_SECRETor certificate OBO only Confidential credential for delegated OBO; use a Key Vault-backed certificate in Azure.
configAZURE_CLIENT_CERTIFICATE_PATH
configENTRA_MCP_AUDIENCEYes Audience of access tokens issued for the MCP resource API.
configENTRA_MCP_ISSUERYes Single-tenant Entra v2 issuer.
configENTRA_MCP_USER_SCOPE
configENTRA_MCP_AGENT_ROLE
configENTRA_AGENT_CLIENT_IDSAgent ID Comma-separated allowlist of approved Microsoft Entra Agent Identity client IDs.
configALLOWED_ORIGINSNo Comma-separated browser origins allowed by CORS. CORS is disabled when empty.
configHOSTNo HTTP bind address. Defaults to 0.0.0.0.
configPORTNo HTTP listen port inside the container. Defaults to 8000.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/soucheff-defenderhuntmcp-ksvs7g)](https://m8ven.ai/mcp/soucheff-defenderhuntmcp-ksvs7g)
commit: 14685de11439c7400d95072acc889391a3c59dc7
code hash: f2ce123ecde9432886a6f373a8de629d0882453a9e2464919c7ddc19ad27b2fe
verified: 7/21/2026, 9:16:35 AM
view raw JSON →