Tracecat

MCP servers on Tracecat

Connect security and IT agents to 50+ hosted MCP servers. No infra to manage.

Elastic
Search and analyze security telemetry across the Elastic stack.
View docs
http
Panther
Investigate alerts and run detections on Panther.
View docs
stdio
Splunk
Search indexes and triage events on Splunk (Cloud or on-prem).
View docs
stdio
Microsoft Sentinel
Query Sentinel's data lake and triage incidents across Microsoft Defender.
View docs
http
RunReveal
Query security data and run detections on RunReveal.
View docs
http
Google Cloud SecOps
Triage SIEM alerts and run SOAR workflows on Google Cloud SecOps.
View docs
stdio
Sumo Logic
Search logs and triage incidents on Sumo Logic Cloud SIEM and SOAR.
View docs
http
CrowdStrike Falcon
Investigate detections and devices on CrowdStrike Falcon.
View docs
stdio
SentinelOne Purple
Query Purple AI, alerts, and vulnerabilities on SentinelOne.
View docs
stdio
Jamf
Manage Apple devices across Jamf Pro, Protect, and Security Cloud.
View docs
Iru / Kandji
Manage Apple devices and inventory across Iru (formerly Kandji) endpoints.
View docs
http
Secure Annex
Investigate browser and code editor extension risk.
View docs
http
Microsoft Defender XDR
Triage Defender XDR detections across endpoints, identity, and email.
View docs
http
Wiz
Investigate cloud security findings, identities, and exposures on Wiz.
View docs
http
AWS
Call any of 15,000+ AWS APIs via the official AWS MCP server.
View docs
http
Microsoft Entra ID
Query users, groups, and access policies through Microsoft Graph.
View docs
http
Okta
Manage users, groups, apps, policies, and logs on Okta.
View docs
stdio
HashiCorp Vault
Read mounts, KV secrets, and PKI from HashiCorp Vault.
View docs
http
Cloudflare
Control Cloudflare edge, DNS, WAF, and Zero Trust.
View docs
http
Zscaler
Query ZIA, ZPA, ZDX, and the rest of the Zscaler SASE stack.
View docs
stdio
Palo Alto Networks
Investigate incidents and assets on Cortex XSIAM and XDR.
View docs
http
Semgrep
Run SAST scans and review findings with Semgrep.
View docs
stdio
Snyk
Scan code, dependencies, containers, and IaC with Snyk.
View docs
stdio
Vanta
Review controls, tests, and risks across Vanta compliance frameworks.
View docs
stdio
Drata
Query controls, evidence, and audit data across Drata trust workflows.
View docs
http
GreyNoise
Check IP context and trending vulnerabilities on GreyNoise.
View docs
stdio
Feedly
Read curated threat intelligence feeds from Feedly.
View docs
VirusTotal
Look up file, URL, IP, and domain reputation via Google Threat Intelligence.
View docs
stdio
Sixtyfour
Enrich people and companies on demand with Sixtyfour.
View docs
stdio
Datadog
Query Datadog metrics, logs, traces, monitors, and incidents.
View docs
http
Sentry
Search issues, events, and releases on Sentry.
View docs
http
Grafana
Query dashboards, Prometheus, Loki, and alerts on Grafana.
View docs
stdio
ClickHouse
Run SQL against ClickHouse analytical databases.
View docs
stdio
Snowflake
Query Snowflake via Cortex Agents and run SQL.
View docs
http
Databricks
Query Databricks SQL, Vector Search, Genie, and Unity Catalog.
View docs
http
Linear
Create, search, and update Linear issues and projects.
View docs
http
Jira / Atlassian
Read and write Jira issues, Confluence pages, and Atlassian Cloud objects.
View docs
http
Atlassian Rovo
Search and act across Jira and Confluence via the Rovo agent endpoint.
View docs
http
ServiceNow
Query and update ServiceNow ITSM records via the Zurich MCP server.
View docs
http
GitHub
Read repos, issues, PRs, and code search on GitHub.
View docs
http
GitLab
Read repos, issues, MRs, and pipelines on GitLab.
View docs
http
Incident.io
Create incidents, manage alerts, and respond to escalations on incident.io.
View docs
http
PagerDuty
Read incidents, schedules, services, and on-call from PagerDuty.
View docs
stdio
Rootly
Manage incidents and on-call rotations on Rootly.
View docs
stdio
Terraform
Plan and apply infrastructure changes with Terraform.
View docs
stdio
Ansible
Run playbooks and manage automation jobs on Ansible Automation Platform.
View docs
stdio
Gmail
Search, label, and send mail through Gmail.
View docs
http
Microsoft Mail
Read, create, and send mail through Microsoft 365.
View docs
http
Slack
Search messages, post to channels, and manage canvases on Slack.
View docs
http
Microsoft Teams
Send chats, manage channels, and run team operations on Microsoft Teams.
View docs
http
Microsoft user profiles
Read user, manager, and directory data through Microsoft Graph /me.
View docs
http
Microsoft Word
Create documents and comments in Microsoft Word.
View docs
http
Microsoft OneDrive
Search, share, and manage files on OneDrive.
View docs
http
Microsoft SharePoint
Work with sites, lists, drives, and files on SharePoint.
View docs
http
Google Drive
Search, read, and create files on Google Drive.
View docs
http
Google Calendar
Read events and schedule meetings on Google Calendar.
View docs
http
Notion
Read and write pages, databases, and comments on Notion.
View docs
http