Abnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A secure, open-source Model Context Protocol server for Abnormal Security.
This project is not an official Abnormal product and is not endorsed by Abnormal AI.
abnormal-mcp lets MCP clients such as Cursor and Claude Desktop query Abnormal Security over stdio (default) or Streamable HTTP. It uses a lightweight handwritten client against the Abnormal Security Client API.
The server is read-only by default. Response and evidence download tools are opt-in and independent. Abnormal authorization still applies to every request.
Read (always on)
abnormal_threat_action_get)since, sender, sender_domain, recipient, subject, url, attachment, sender_ip, judgement)Response (opt-in: ABNORMAL_ALLOW_RESPONSE=true)
delete, move_to_inbox) with confirm: true preview gateconfirm: true preview gateconfirm: true preview gateconfirm: true preview gateEvidence download (opt-in: ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD=true)
Message EML download (by ABX message ID or search cloud_message_id)
Attachment analysis signals and attachment download
Metadata + bounded preview by default; optional base64 embed (max 1 MiB in tool output)
stdio transport (default) and opt-in Streamable HTTP
Native Go binary and Docker image
MCP Registry listing on tagged releases (io.github.GregDog/mcp-server-abnormal)
Create an Abnormal REST API token in the Abnormal portal under Integrations β Abnormal REST API.
See examples/claude-desktop.json.
27 read tools are always registered. With ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD=true, five evidence tools are added (32 total). With ABNORMAL_ALLOW_RESPONSE=true, four response tools are added (31 total, or 36 with both gates enabled).
| Area | Tools |
|---|---|
| Threats | abnormal_threats_list, abnormal_threat_get, abnormal_threat_action_get, abnormal_threat_links_list, abnormal_threat_attachments_list |
| Search | abnormal_search_messages, abnormal_search_activities_list, abnormal_search_activity_get |
| Messages | abnormal_message_remediation_history |
| Mailbox | abnormal_mailbox_campaigns_list, abnormal_mailbox_campaign_get, abnormal_mailbox_unanalyzed_list |
| Employees | abnormal_employee_get, abnormal_employee_identity_get, abnormal_employee_logins_list |
| ATO cases | abnormal_cases_list, abnormal_case_get, abnormal_case_analysis_get, abnormal_case_action_get |
| Vendors | abnormal_vendors_list, abnormal_vendor_get, abnormal_vendor_activity_list, abnormal_vendor_cases_list, abnormal_vendor_case_get |
| Detection 360 | abnormal_detection360_reports_list |
| URL rewrite | abnormal_url_rewrite_clicks_list |
| Audit logs | abnormal_audit_logs_list |
| Evidence (opt-in) | abnormal_message_eml_get, abnormal_search_message_eml_get, abnormal_message_attachment_get, abnormal_message_attachment_download, abnormal_search_attachment_download |
| Response (opt-in) | abnormal_search_remediate, abnormal_threat_remediate, abnormal_case_update, abnormal_detection360_report_submit |
See docs/tools.md for parameters.
| Variable | Default | Purpose |
|---|---|---|
ABNORMAL_API_TOKEN | (required) | Bearer token |
ABNORMAL_BASE_URL | https://api.abnormalplatform.com/v1 | API base URL |
ABNORMAL_ALLOW_RESPONSE | false | Enable response tools (Phase 2+) |
ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD | false | Enable evidence download (Phase 5+) |
ABNORMAL_MCP_TRANSPORT | stdio | stdio or http |
Full list: docs/configuration.md.
Read tools are always on. Response and evidence tools require explicit opt-in.
Local use only: this server has no built-in authentication or RBAC. Use stdio (default) or loopback HTTP on the same machine. Do not expose the HTTP endpoint on a network without your own access controls.
See docs/security.md and SECURITY.md.
See docs/development.md.
Apache-2.0. See LICENSE.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/abnormal-mcp-server)<a href="https://allmcps.com/mcp/abnormal-mcp-server"><img src="https://allmcps.com/api/badge/abnormal-mcp-server?style=directory" alt="Abnormal MCP Server on AllMCPs" /></a>