Connect AI assistants to ThreatLocker Portal API for security management tasks.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "threatlocker-mcp" yet — see the docs or source repo.
Use threatlocker-mcp to look up the computer named "FINANCE-LAPTOP-07" and summarize its current status, tags, and whether it is in maintenance mode.
A concise summary of the device, including status, assigned tags, and maintenance mode state.
Use threatlocker-mcp to list recent approval records, sort them by time, and highlight items that need my immediate attention.
A recent approvals list with a short note on which items should be prioritized.
Use threatlocker-mcp to retrieve action logs from multiple tenants over the last 24 hours and summarize unusual or high-frequency actions by tenant.
A tenant-by-tenant action log summary highlighting unusual or noteworthy activity.
Ops or security teams can use AI connected to the ThreatLocker Portal API to quickly query and manage computers, tags, approvals, and maintenance mode, reducing manual console work.
Service providers or teams managing multiple organizations can review action logs, approvals, and device information across single-org and multi-tenant setups more efficiently.
When recent operations or approval changes need review, teams can have AI summarize action logs and related objects to identify important changes faster.
It is an MCP server that connects AI assistants to the ThreatLocker Portal API. The description says it provides 44 tools for managing computers, approvals, action logs, tags, maintenance mode, and more.
Based on the provided description, it supports both single-organization and multi-tenant setups. That makes it suitable for teams that need unified management or lookup across environments.
The provided material does not include installation steps or prerequisites. It likely involves ThreatLocker Portal API connection setup; see the source repository for details.
Query and update ThreatLocker Portal data to automate security operations.
Look up threat intel, CVEs, breached credentials, and dark web data.
Scan local file systems for vulnerabilities and leaked secrets using Trivy and Gitleaks.
MCP tool for compliance automation, PII scanning, and audit tracking.
Monitor threat intel, analyze IOCs, and investigate security incidents in real time.
An MCP tool for threat modeling, security review, and compliance governance.