by gensecaihq
AI-powered security operations for Wazuh SIEM—use any MCP-compatible client to ask security questions in plain English. Faster threat detection, incident triage, and compliance checks with real-time monitoring and anomaly spotting. Production-ready MCP server for conversational SOC workflows.
# Add to your Claude Code skills
git clone https://github.com/gensecaihq/Wazuh-MCP-ServerProduction-ready MCP server connecting AI assistants to Wazuh SIEM.
Version 4.0.7 | Wazuh 4.8.0 - 4.14.3 | Full Changelog
Security teams using Wazuh SIEM generate thousands of alerts, vulnerabilities, and events daily. Analyzing this data requires constant context-switching between dashboards, writing API queries, and manually correlating information.
This MCP server solves that problem by providing a secure bridge between AI assistants (like Claude) and your Wazuh deployment. Query alerts, analyze threats, check agent health, and generate compliance reports—all through natural conversation.
You: "Show me critical alerts from the last 24 hours"
Claude: [Uses get_wazuh_alerts tool] Found 12 critical alerts...
You: "Which agents have unpatched critical vulnerabilities?"
Claude: [Uses get_wazuh_critical_vulnerabilities tool] 3 agents affected...
Ready to move beyond manual security operations?
Combine this MCP server with Wazuh OpenClaw Autopilot to build a fully autonomous Security Operations Center powered by AI agents.
No comments yet. Be the first to share your thoughts!
While this MCP server gives you conversational access to Wazuh, OpenClaw takes it to the next level—deploying AI agents that work around the clock to triage alerts, correlate incidents, and recommend responses without human intervention.
| Capability | What It Does | |------------|--------------| | Autonomous Alert Triage | AI agents continuously analyze incoming alerts, prioritize threats, and create structured incident cases | | Intelligent Correlation | Automatically groups related alerts into attack timelines with blast radius assessment | | AI-Powered Response Planning | Generates actionable response recommendations with risk scoring | | Human-in-the-Loop Safety | Critical actions require Slack approval—automation with guardrails |
Traditional SOC: Alert → Analyst reviews → Hours later → Response
Agentic SOC: Alert → AI triages → Seconds later → Response ready for approval
This is the future of security operations. Start with the MCP server, scale to autonomous agents.
| Category | Capabilities | |----------|-------------| | MCP Protocol | 100% compliant with MCP 2025-11-25, Streamable HTTP + Legacy SSE | | Security Tools | 29 specialized tools for alerts, ag...