Enables security investigation and threat hunting through Microsoft Defender and Entra ID, with 31 tools for KQL queries, alerts, threat intelligence, identity investigation, and advanced threat hunting.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.ENABLE_AGENT_GOVERNANCE_BETACACHE_BACKENDREDIS_URLREDIS_HOSTREDIS_ENTRA_USERNAMEREDIS_PORTAZURE_MANAGED_IDENTITY_CLIENT_ID— Azure User-assigned infrastructure identity for Redis, ACR/Key Vault, and temporary legacy Graph access.REDIS_KEY_PREFIXAZURE_TENANT_ID— Yes Microsoft Entra tenant ID.AZURE_MANAGED_IDENTITY_PRINCIPAL_IDLOG_LEVEL— No Logging level (DEBUG, INFO, WARNING, ERROR, CRITICAL). Defaults to INFO.AZURE_CLIENT_ID— Yes App registration client ID.AZURE_CLIENT_SECRET— or certificate OBO only Confidential credential for delegated OBO; use a Key Vault-backed certificate in Azure.AZURE_CLIENT_CERTIFICATE_PATHENTRA_MCP_AUDIENCE— Yes Audience of access tokens issued for the MCP resource API.ENTRA_MCP_ISSUER— Yes Single-tenant Entra v2 issuer.ENTRA_MCP_USER_SCOPEENTRA_MCP_AGENT_ROLEENTRA_AGENT_CLIENT_IDS— Agent ID Comma-separated allowlist of approved Microsoft Entra Agent Identity client IDs.ALLOWED_ORIGINS— No Comma-separated browser origins allowed by CORS. CORS is disabled when empty.HOST— No HTTP bind address. Defaults to 0.0.0.0.PORT— No HTTP listen port inside the container. Defaults to 8000.[](https://m8ven.ai/mcp/soucheff-defenderhuntmcp-ksvs7g)