Access email threats, investigate cases, and generate reports in terminal or AI agents.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Abnormal Security MCP" yet — see the docs or source repo.
List high-risk email threats detected in the last 24 hours, grouped by threat type, affected users, and remediation status.
A structured list of email threats organized by risk and status for quick prioritization.
Open case CASE-1024 and summarize the incident timeline, affected mailboxes, actions already taken, and recommended next steps.
An investigation summary with timeline, impact scope, current remediation, and next-step recommendations.
Generate this week's email security report with threat volume, top attack types, remediation efficiency, and concise executive conclusions.
A weekly report for teams or executives with key metrics, trends, and conclusions.
Manage N-central assets with offline org trees, cross-tenant search, and JWT protection.
Triage RocketCyber alerts, track MTTR, and analyze security posture.
Manage AppDirect marketplace operations with offline mirroring and cross-company billing reconciliation.
Manage ConnectWise remote support and access sessions through CLI or AI agents.
Access Atera ops and service data for fleet health, SLA, and ticket insights.
Sync infrastructure configs offline, then drift-check and search them via CLI.
Safely lets AI agents use threat analysis and security operations tools.
Scan inbound emails for prompt injection before they reach AI agents.
Check IP reputation and abuse reports for security triage and investigation.
Analyze AI security, scan vulnerabilities, and monitor code leaks efficiently.
Analyze security incidents, map ATT&CK techniques, score severity, and recommend remediation.
Audit MCP configs for exposed access, secrets, models, and compliance AI-BOMs.