开发者工具 · 安全

MCP Panther

panther-labs/mcp-panther

Panther MCP服务器是一个安全分析平台,提供IDE编写检测规则、自然语言查询安全日志、警报处理等功能,支持多种工具和客户端配置。

安装

docker run -i -e PANTHER_INSTANCE_URL -e PANTHER_API_TOKEN --rm ghcr.io/panther-labs/mcp-panther

客户端配置

{
  "mcpServers": {
    "mcp-panther": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "-e",
        "PANTHER_INSTANCE_URL",
        "-e",
        "PANTHER_API_TOKEN",
        "--rm",
        "ghcr.io/panther-labs/mcp-panther"
      ],
      "env": {
        "PANTHER_INSTANCE_URL": "<PANTHER_INSTANCE_URL>",
        "PANTHER_API_TOKEN": "<PANTHER_API_TOKEN>"
      }
    }
  }
}

环境变量

PANTHER_INSTANCE_URLPANTHER_API_TOKEN
分类
开发者工具, 安全
许可证
Apache-2.0
更新于
2026年10月6日

工具(36)

  • add_alert_comment

    Add a comment to a Panther alert

  • start_ai_alert_triage

    Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations

  • get_ai_alert_triage_summary

    Retrieve the latest AI triage summary previously generated for a specific alert

  • get_alert

    Get detailed information about a specific alert

  • get_alert_events

    Get a small sampling of events for a given alert

  • list_alerts

    List alerts with comprehensive filtering options (date range, severity, status, etc.)

  • bulk_update_alerts

    Bulk update multiple alerts with status, assignee, and/or comment changes

  • update_alert_assignee

    Update the assignee of one or more alerts

  • update_alert_status

    Update the status of one or more alerts

  • list_alert_comments

    List all comments for a specific alert

  • query_data_lake

    Execute SQL queries against Panther's data lake with synchronous results

  • get_table_schema

    Get schema information for a specific table

  • list_databases

    List all available data lake databases in Panther

  • list_database_tables

    List all available tables for a specific database in Panther's data lake

  • get_alert_event_stats

    Analyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics

  • list_scheduled_queries

    List all scheduled queries with pagination support

  • get_scheduled_query

    Get detailed information about a specific scheduled query by ID

  • list_log_sources

    List log sources with optional filters (health status, log types, integration type)

  • get_http_log_source

    Get detailed information about a specific HTTP log source by ID

  • list_detections

    List detections from Panther with comprehensive filtering support.

  • get_detection

    Get detailed information about a specific detection including the detection body and tests.

  • disable_detection

    Disable a detection by setting enabled to false.

  • list_global_helpers

    List global helper functions with comprehensive filtering options (name search, creator, modifier)

  • get_global_helper

    Get detailed information and complete Python code for a specific global helper

  • list_data_models

    List data models that control UDM mappings in rules

  • get_data_model

    Get detailed information about a specific data model

  • list_log_type_schemas

    List available log type schemas with optional filters

  • get_log_type_schema_details

    Get detailed information for specific log type schemas

  • get_rule_alert_metrics

    Get metrics about alerts grouped by rule

  • get_severity_alert_metrics

    Get metrics about alerts grouped by severity

  • get_bytes_processed_metrics

    Get data ingestion metrics by log type and source

  • list_users

    List all Panther user accounts with pagination support

  • get_user

    Get detailed information about a specific user

  • get_permissions

    Get the current user's permissions

  • list_roles

    List all roles with filtering options (name search, role IDs, sort direction)

  • get_role

    Get detailed information about a specific role including permissions

本页信息摘自该项目的 README。 查看 README

支持的客户端

该服务器 README 中提到的客户端:

查看全部
Claude Desktop logo

Claude Desktop

桌面端 · 免费增值 · Proprietary

Anthropic 官方推出的 Claude AI 桌面应用程序。支持 MCP 服务器以扩展功能。

WindowsMacOS
Cursor logo

Cursor

桌面端 · 免费增值 · Proprietary

首个代理式 IDE。Cursor 编辑器让开发者与 AI 的工作真正融合在一起,提供如魔法般的编码体验。

WindowsMacOSLinux
Goose logo

Goose

桌面端 · 免费 · Apache 2.0

通用 AI 代理,可以动态插入新扩展并学习如何使用它们。它使用来自多个扩展的工具解决更高级的问题,可以同时与多个扩展交互。

MacOSLinux

相关 MCP 服务器

更多服务器
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright是一个跨浏览器的Web测试和自动化框架,支持Chromium、Firefox和WebKit,提供无头执行、多浏览器兼容性测试、强大的断言和工具支持,适用于多种编程语言。

开发者工具
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix是一个将代码库打包为AI友好格式的工具,支持本地和远程仓库处理,提供代码压缩、安全检查和多种输出格式。

开发者工具
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS 是字节跳动的多模态 AI 智能体技术栈,包含两个项目:Agent TARS(基于 MCP 的命令行与 Web UI 智能体)和 UI-TARS-desktop(桌面 GUI 智能体)。

开发者工具
blender logo

blender

ahujasid/blender-mcp

10.6k

BlenderMCP通过MCP协议将Blender与Claude AI连接,实现AI辅助3D建模与场景控制

开发者工具
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

Playwright MCP是一个基于Playwright的浏览器自动化服务器,通过结构化数据而非像素输入实现LLM与网页的交互。

开发者工具
2344 logo

2344

comet-ml/opik

7k

Opik是一个开源的LLM评估框架,支持追踪、评估和监控LLM应用,帮助开发者构建更高效、更经济的LLM系统。

开发者工具