Cisco XDR MCP Server

Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows and Admin, plus 5 resources and 6 prompts. Apache-2.0, TypeScript, stdio transport only — there is no hosted endpoint and the package is not on npm, so a human must clone and build it before any agent can reach Cisco XDR through it.

API entry from apis.yml

apis.yml Raw ↑
aid: cisco-xdr:cisco-xdr-mcp-server
name: Cisco XDR MCP Server
description: Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across
  Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows and Admin, plus
  5 resources and 6 prompts. Apache-2.0, TypeScript, stdio transport only — there is no hosted endpoint
  and the package is not on npm, so a human must clone and build it before any agent can reach Cisco XDR
  through it.
humanURL: https://github.com/CiscoDevNet/xdr-mcp-community
baseURL: https://visibility.amp.cisco.com
tags:
- Security
- XDR
- MCP
- Agents
- Threat Detection
tags_raw:
- Security
- XDR
- MCP
- Agent
- Threat Detection
properties:
- type: MCPServer
  url: mcp/cisco-xdr-mcp.yml
- type: MCPServer
  url: https://github.com/CiscoDevNet/xdr-mcp-community
- type: ToolCrosswalk
  url: mcp/cisco-xdr-tool-crosswalk.yml
- type: AgentSkill
  url: skills/_index.yml
- type: Documentation
  url: https://github.com/CiscoDevNet/xdr-mcp-community/blob/main/INSTALL.md