Developer Tools · Security

MCP Panther

panther-labs/mcp-panther

Panther's Model Context Protocol (MCP) server provides functionality to.

Install

docker run -i -e PANTHER_INSTANCE_URL -e PANTHER_API_TOKEN --rm ghcr.io/panther-labs/mcp-panther

Client configuration

{
  "mcpServers": {
    "mcp-panther": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "-e",
        "PANTHER_INSTANCE_URL",
        "-e",
        "PANTHER_API_TOKEN",
        "--rm",
        "ghcr.io/panther-labs/mcp-panther"
      ],
      "env": {
        "PANTHER_INSTANCE_URL": "<PANTHER_INSTANCE_URL>",
        "PANTHER_API_TOKEN": "<PANTHER_API_TOKEN>"
      }
    }
  }
}

Environment variables

PANTHER_INSTANCE_URLPANTHER_API_TOKEN
Category
Developer Tools, Security
License
Apache-2.0
Updated
Oct 6, 2026

Tools (36)

  • add_alert_comment

    Add a comment to a Panther alert

  • start_ai_alert_triage

    Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations

  • get_ai_alert_triage_summary

    Retrieve the latest AI triage summary previously generated for a specific alert

  • get_alert

    Get detailed information about a specific alert

  • get_alert_events

    Get a small sampling of events for a given alert

  • list_alerts

    List alerts with comprehensive filtering options (date range, severity, status, etc.)

  • bulk_update_alerts

    Bulk update multiple alerts with status, assignee, and/or comment changes

  • update_alert_assignee

    Update the assignee of one or more alerts

  • update_alert_status

    Update the status of one or more alerts

  • list_alert_comments

    List all comments for a specific alert

  • query_data_lake

    Execute SQL queries against Panther's data lake with synchronous results

  • get_table_schema

    Get schema information for a specific table

  • list_databases

    List all available data lake databases in Panther

  • list_database_tables

    List all available tables for a specific database in Panther's data lake

  • get_alert_event_stats

    Analyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics

  • list_scheduled_queries

    List all scheduled queries with pagination support

  • get_scheduled_query

    Get detailed information about a specific scheduled query by ID

  • list_log_sources

    List log sources with optional filters (health status, log types, integration type)

  • get_http_log_source

    Get detailed information about a specific HTTP log source by ID

  • list_detections

    List detections from Panther with comprehensive filtering support.

  • get_detection

    Get detailed information about a specific detection including the detection body and tests.

  • disable_detection

    Disable a detection by setting enabled to false.

  • list_global_helpers

    List global helper functions with comprehensive filtering options (name search, creator, modifier)

  • get_global_helper

    Get detailed information and complete Python code for a specific global helper

  • list_data_models

    List data models that control UDM mappings in rules

  • get_data_model

    Get detailed information about a specific data model

  • list_log_type_schemas

    List available log type schemas with optional filters

  • get_log_type_schema_details

    Get detailed information for specific log type schemas

  • get_rule_alert_metrics

    Get metrics about alerts grouped by rule

  • get_severity_alert_metrics

    Get metrics about alerts grouped by severity

  • get_bytes_processed_metrics

    Get data ingestion metrics by log type and source

  • list_users

    List all Panther user accounts with pagination support

  • get_user

    Get detailed information about a specific user

  • get_permissions

    Get the current user's permissions

  • list_roles

    List all roles with filtering options (name search, role IDs, sort direction)

  • get_role

    Get detailed information about a specific role including permissions

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux
Goose logo

Goose

Desktop · Free · Apache 2.0

A general-purpose AI agent that can dynamically plug in new extensions and learn how to use them. It uses tools from multiple extensions to solve more advanced problems and can interact with multiple extensions simultaneously.

MacOSLinux

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools