Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. MCP Panther
MCP Panther logo
Health: ActiveRecent health check succeeded.Last checked 9/11/2026, 4:30:35 PM

MCP Panther

User RatingsBe the first to rate and review this MCP server!
View Repository47 GitHub StarsTotal stargazers on GitHub for the source repository (47 stars).Visit Website

MCP server for interacting with Panther SIEM via natural language to manage detections, alerts, and query logs.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "panther-labs-mcp-panther": {
      "command": "uvx",
      "args": [
        "mcp-panther"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (36) Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

This MCP server enables security professionals to write and tune detections, query security logs, and manage alerts on Panther's SIEM platform using natural language commands. It supports alert triage, commenting, bulk updates, and detailed querying of logs and detection rules. Use it to integrate Panther SIEM capabilities into AI agents or IDEs for streamlined security operations.

Use cases

โ€ขWrite and tune detection rules from an IDE
โ€ขQuery security logs using natural language
โ€ขTriage and resolve security alerts interactively
โ€ขAdd comments and update alert statuses in bulk
โ€ขRetrieve schema and metadata for data lake tables

Key features

โ€ขNatural language querying of Panther data lake logs
โ€ขAlert management including triage, commenting, and bulk updates
โ€ขDetection rule listing, details retrieval, and disabling
โ€ขAccess to scheduled queries and log source configurations
โ€ขGlobal helper function retrieval with filtering

Capabilities & Tool Schemas (36) ~802 tokensApproximate context cost of this serverโ€™s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server โ€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Panther.

add_alert_comment

Add a comment to a Panther alert

start_ai_alert_triage

Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations

get_ai_alert_triage_summary

Retrieve the latest AI triage summary previously generated for a specific alert

get_alert

Get detailed information about a specific alert

get_alert_events

Get a small sampling of events for a given alert

list_alerts

List alerts with comprehensive filtering options (date range, severity, status, etc.)

Documentation Overview

Panther MCP Server

Ruff

Panther's Model Context Protocol (MCP) server provides functionality to:

  1. Write and tune detections from your IDE
  2. Interactively query security logs using natural language
  3. Triage, comment, and resolve one or many alerts
Panther Server MCP server

Available Tools

Alerts
Tool NameDescriptionSample Prompt
add_alert_commentAdd a comment to a Panther alert"Add comment 'Looks pretty bad' to alert abc123"
start_ai_alert_triageStart an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations"Start AI triage for alert abc123" / "Generate a detailed AI analysis of alert def456"
get_ai_alert_triage_summaryRetrieve the latest AI triage summary previously generated for a specific alert"Get the AI triage summary for alert abc123" / "Show me the AI analysis for alert def456"
get_alertGet detailed information about a specific alert"What's the status of alert 8def456?"
get_alert_eventsGet a small sampling of events for a given alert"Show me events associated with alert 8def456"
list_alertsList alerts with comprehensive filtering options (date range, severity, status, etc.)"Show me all high severity alerts from the last 24 hours"
bulk_update_alertsBulk update multiple alerts with status, assignee, and/or comment changes"Update alerts abc123, def456, and ghi789 to resolved status and add comment 'Fixed'"
update_alert_assigneeUpdate the assignee of one or more alerts"Assign alerts abc123 and def456 to John"
update_alert_statusUpdate the status of one or more alerts"Mark alerts abc123 and def456 as resolved"
list_alert_commentsList all comments for a specific alert"Show me all comments for alert abc123"
Data Lake
Tool NameDescriptionSample Prompt
query_data_lakeExecute SQL queries against Panther's data lake with synchronous results"Query AWS CloudTrail logs for failed login attempts in the last day"
get_table_schemaGet schema information for a specific table"Show me the schema for the AWS_CLOUDTRAIL table"
list_databasesList all available data lake databases in Panther"List all available databases"
list_database_tablesList all available tables for a specific database in Panther's data lake"What tables are in the panther_logs database"
get_alert_event_statsAnalyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics"Show me patterns in events from alerts abc123 and def456"
Scheduled Queries
Tool NameDescriptionSample Prompt
list_scheduled_queriesList all scheduled queries with pagination support"Show me all scheduled queries" / "List the first 25 scheduled queries"
get_scheduled_queryGet detailed information about a specific scheduled query by ID"Get details for scheduled query 'weekly-security-report'"
Sources
Tool NameDescriptionSample Prompt
list_log_sourcesList log sources with optional filters (health status, log types, integration type)"Show me all healthy S3 log sources"
get_http_log_sourceGet detailed information about a specific HTTP log source by ID"Show me the configuration for HTTP source 'webhook-collector-123'"
Detections
Tool NameDescriptionSample Prompt
list_detectionsList detections from Panther with comprehensive filtering support. Supports multiple detection types and filtering by name, state, severity, tags, log types, resource types, output IDs (destinations), and more. Returns outputIDs for each detection showing configured alert destinations"Show me all enabled HIGH severity rules with tag 'AWS'" / "List disabled policies for S3 resources" / "Find all rules with outputID 'prod-slack'" / "Show me detections that alert to production destinations"
get_detectionGet detailed information about a specific detection including the detection body and tests. Accepts a list with one detection type: ["rules"], ["scheduled_rules"], ["simple_rules"], or ["policies"]"Get details for rule ID abc123" / "Get details for policy ID AWS.S3.Bucket.PublicReadACP"
disable_detectionDisable a detection by setting enabled to false. Supports rules, scheduled_rules, simple_rules, and policies"Disable rule abc123" / "Disable policy AWS.S3.Bucket.PublicReadACP"
Global Helpers
Tool NameDescriptionSample Prompt
list_global_helpersList global helper functions with comprehensive filtering options (name search, creator, modifier)"Show me global helpers containing 'aws' in the name"
get_global_helperGet detailed information and complete Python code for a specific global helper"Get the complete code for global helper 'AWSUtilities'"
Data Models
Tool NameDescriptionSample Prompt
list_data_modelsList data models that control UDM mappings in rules"Show me all data models for log parsing"
get_data_modelGet detailed information about a specific data model"Get the complete details for the 'AWS_CloudTrail' data model"
Schemas
Tool NameDescriptionSample Prompt
list_log_type_schemasList available log type schemas with optional filters"Show me all AWS-related schemas"
get_log_type_schema_detailsGet detailed information for specific log type schemas"Get full details for AWS.CloudTrail schema"
Metrics
Tool NameDescriptionSample Prompt
get_rule_alert_metricsGet metrics about alerts grouped by rule"Show top 10 rules by alert count"
get_severity_alert_metricsGet metrics about alerts grouped by severity"Show alert counts by severity for the last week"
get_bytes_processed_metricsGet data ingestion metrics by log type and source"Show me data ingestion volume by log type"
Users & Access Management
Tool NameDescriptionSample Prompt
list_usersList all Panther user accounts with pagination support"Show me all active Panther users" / "List the first 25 users"
get_userGet detailed information about a specific user"Get details for user ID 'john.doe@company.com'"
get_permissionsGet the current user's permissions"What permissions do I have?"
list_rolesList all roles with filtering options (name search, role IDs, sort direction)"Show me all roles containing 'Admin' in the name"
get_roleGet detailed information about a specific role including permissions"Get complete details for the 'Admin' role"

Panther Configuration

Follow these steps to configure your API credentials and environment.

  1. Create an API token in Panther:

    • Navigate to Settings (gear icon) โ†’ API Tokens

    • Create a new token with the following permissions (recommended read-only approach to start):

    • View Required Permissions

      Screenshot of Panther Token permissions Screenshot of Panther Token permissions

  2. Store the generated token securely (e.g., 1Password)

  3. Copy the Panther instance URL from your browser (e.g., https://YOUR-PANTHER-INSTANCE.domain)

    • Note: This must include https://

MCP Server Installation

Choose one of the following installation methods:

Docker (Recommended)

The easiest way to get started is using our pre-built Docker image:

config.json
{
  "mcpServers": {
    "mcp-panther": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "-e", "PANTHER_INSTANCE_URL",
        "-e", "PANTHER_API_TOKEN",
        "--rm",
        "ghcr.io/panther-labs/mcp-panther"
      ],
      "env": {
        "PANTHER_INSTANCE_URL": "https://YOUR-PANTHER-INSTANCE.domain",
        "PANTHER_API_TOKEN": "YOUR-API-KEY"
      }
    }
  }
}

Version Pinning: For production stability, pin to a specific version tag:

json
"ghcr.io/panther-labs/mcp-panther:v2.2.0"

Available tags can be found on the GitHub Container Registry.

UVX

For Python users, you can run directly from PyPI using uvx:

  1. Install UV

  2. Configure your MCP client:

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    ๐Ÿ”’ Security3 views
    Compare vs Apktool MCP Server โ†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    ๐Ÿ”’ Security3 views
    Compare vs Jadx AI MCP โ†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    ๐Ÿ”’ Security2 views
    Compare vs Agentward โ†’
  • MCP Maigret logoMCP Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    ๐Ÿ”’ Security4 views
    Compare vs MCP Maigret โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
47
Stargazers on the source repository.
Last commit
Today
Most recent push to the default branch.
Tools exposed
36
Callable tools this server registers over MCP.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Panther

You can list, comment on, triage, update status and assignees, and bulk update Panther alerts.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Panther AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/panther-labs-mcp-panther?style=directory)](https://allmcps.com/mcp/panther-labs-mcp-panther)
HTML Embed
<a href="https://allmcps.com/mcp/panther-labs-mcp-panther"><img src="https://allmcps.com/api/badge/panther-labs-mcp-panther?style=directory" alt="MCP Panther on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
Last updatedSep 11, 2026
10/11 checks healthy over the last 32d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars47
GitHub Star CountTotal stargazers on GitHub representing community popularity (47 stars).
Last commitToday
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 11, 2026
57Quality signal: Good ยท 57/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools26/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 14d ago via OSV.dev ยท mcp-panther (PyPI)

โ˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server โ†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to MCP Panther โ†’Install in Claude DesktopInstall in CursorInstall in VS Code