Expose Cortex XSIAM APIs as MCP tools for AI-driven security search and investigation.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "xsiam-mcp" yet — see the docs or source repo.
Use xql_query to find high-severity security events from the last 24 hours and summarize them by host and severity.
A summary of XQL query results listing relevant events and aggregated findings.
Use the relevant XSIAM MCP tools to investigate a suspicious alert, including related records and traceable context.
Related investigation data, key leads, and suggested next steps for analysis.
Use the Cortex XSIAM MCP tools in an automated security analysis workflow, calling the needed REST APIs and organizing the results.
Structured analysis output produced from multiple coordinated XSIAM API calls.
Security or operations teams can let an AI agent call Cortex XSIAM APIs through MCP to quickly search and investigate security data. It is useful when context must be gathered across many API categories.
Developers can integrate Cortex XSIAM REST APIs into AI workflows as MCP tools, reducing the complexity of handling many separate endpoints. This is especially useful when LLMs need direct access to security platform functions.
When teams want natural-language-driven security queries, they can use the composite xql_query tool. It fits rapid exploration, filtering, and validation of security-event-related data.
It exposes the entire Palo Alto Cortex XSIAM REST API as MCP tools, covering 129 operations across 26 categories. It also includes composite tools such as xql_query for AI agents to search and investigate security data.
Yes. The description explicitly mentions composite tools like xql_query for AI agents to perform security data search and investigation.
The provided material does not include installation, runtime, or authentication details. In practice, you would typically need access to the Cortex XSIAM API and credentials; see the source repository for specifics.
Provide governed agent access to Cortex XSIAM security operations APIs.
Connect AI tools to Cortex platforms for natural-language security workflow development and automation.
Let AI agents investigate threats and manage Cisco Secure Access operations.
Securely equips AI agents with executable tools for commands, search, and file operations.
Safely lets AI agents use threat analysis and security operations tools.
Build production-ready AI tools with security, auditability, data quality, and testing.