← Back to search

rapid7-mcp

solomonneas Scanned 7h ago

Model Context Protocol server for the Rapid7 InsightIDR SIEM platform

C
73.6 / 100

Versions

1.0.0latest
Apr 30, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 26

search_logs
annotations: none low

Execute a LEQL (Log Entry Query Language) query against a specific log set in InsightIDR

list_log_sets
annotations: none low

List all available log sets in InsightIDR (Firewall, DNS, DHCP, Endpoint, Cloud, etc.)

get_log_entry
annotations: none low

Retrieve a specific log entry by its ID from a given log set

get_log_stats
annotations: none low

Get aggregate statistics for a log set over a time range using a LEQL query

search_investigations
annotations: none low

List and filter InsightIDR investigations by status, priority, assignee, or date range

get_investigation
annotations: none low

Get full details of a specific InsightIDR investigation including its timeline

create_investigation
annotations: none low

Create a new InsightIDR investigation with a title, priority, and status

update_investigation
annotations: none low

Update an existing investigation

add_investigation_comment
annotations: none low

Add a comment or note to an InsightIDR investigation

get_investigation_alerts
annotations: none low

Get all alerts associated with a specific investigation

search_users
annotations: none low

Search user accounts monitored by InsightIDR by name, email, domain, or department

get_user_activity
annotations: none low

Get user behavior analytics data: login times, locations, accessed assets, and anomalies

get_risky_users
annotations: none low

Get users with abnormal behavior scores from InsightIDR

list_saved_queries
annotations: none low

List saved LEQL queries available in InsightIDR

create_saved_query
annotations: none low

Save a LEQL query for reuse in InsightIDR

leql_help
annotations: none low

Get LEQL (Log Entry Query Language) syntax reference, examples, and common patterns for InsightIDR log searches

search_assets
annotations: none low

Search InsightIDR assets (endpoints) by hostname, IP address, OS, or agent status

get_asset
annotations: none low

Get full details of an InsightIDR asset including installed software, vulnerabilities, and network interfaces

get_asset_activity
annotations: none low

Get recent activity for an asset including logins, processes, and network connections

list_threat_indicators
annotations: none low

List IOCs (IPs, domains, hashes) in the InsightIDR threat library

add_threat_indicator
annotations: none low

Add a new IOC (IP, domain, hash, etc.) to the InsightIDR custom threat library

search_threat_activity
annotations: none low

Search for threat indicator matches in InsightIDR logs — find where known IOCs have been seen

list_alerts
annotations: none low

List InsightIDR alerts with optional filters for severity, type, status, and date range

get_alert
annotations: none low

Get full details of a specific InsightIDR alert including its detection rule and metadata

update_alert_status
annotations: none low

Update the status of an InsightIDR alert (open, investigating, or closed)

get_alert_evidence
annotations: none low

Get evidence and indicators associated with an InsightIDR alert

Permissions 2

network medium
Server uses network capabilities via: fetch()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 65

low
Tool 'search_logs' has no annotations annotation_checker · 100%
low
Tool 'list_log_sets' has no annotations annotation_checker · 100%
low
Tool 'get_log_entry' has no annotations annotation_checker · 100%
low
Tool 'get_log_stats' has no annotations annotation_checker · 100%
low
Tool 'search_investigations' has no annotations annotation_checker · 100%
low
Tool 'get_investigation' has no annotations annotation_checker · 100%
low
Tool 'create_investigation' has no annotations annotation_checker · 100%
low
Tool 'update_investigation' has no annotations annotation_checker · 100%
low
Tool 'add_investigation_comment' has no annotations annotation_checker · 100%
low
Tool 'get_investigation_alerts' has no annotations annotation_checker · 100%
low
Tool 'search_users' has no annotations annotation_checker · 100%
low
Tool 'get_user_activity' has no annotations annotation_checker · 100%
low
Tool 'get_risky_users' has no annotations annotation_checker · 100%
low
Tool 'list_saved_queries' has no annotations annotation_checker · 100%
low
Tool 'create_saved_query' has no annotations annotation_checker · 100%
low
Tool 'leql_help' has no annotations annotation_checker · 100%
low
Tool 'search_assets' has no annotations annotation_checker · 100%
low
Tool 'get_asset' has no annotations annotation_checker · 100%
low
Tool 'get_asset_activity' has no annotations annotation_checker · 100%
low
Tool 'list_threat_indicators' has no annotations annotation_checker · 100%
low
Tool 'add_threat_indicator' has no annotations annotation_checker · 100%
low
Tool 'search_threat_activity' has no annotations annotation_checker · 100%
low
Tool 'list_alerts' has no annotations annotation_checker · 100%
low
Tool 'get_alert' has no annotations annotation_checker · 100%
low
Tool 'update_alert_status' has no annotations annotation_checker · 100%
low
Tool 'get_alert_evidence' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12.1 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@4.1.8 (GHSA-82fw-gwwq-j7x9) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: search_logs manifest_parser · 70%
info
Tool: list_log_sets manifest_parser · 70%
info
Tool: get_log_entry manifest_parser · 70%
info
Tool: get_log_stats manifest_parser · 70%
info
Tool: search_investigations manifest_parser · 70%
info
Tool: get_investigation manifest_parser · 70%
info
Tool: create_investigation manifest_parser · 70%
info
Tool: update_investigation manifest_parser · 70%
info
Tool: add_investigation_comment manifest_parser · 70%
info
Tool: get_investigation_alerts manifest_parser · 70%
info
Tool: search_users manifest_parser · 70%
info
Tool: get_user_activity manifest_parser · 70%
info
Tool: get_risky_users manifest_parser · 70%
info
Tool: list_saved_queries manifest_parser · 70%
info
Tool: create_saved_query manifest_parser · 70%
info
Tool: leql_help manifest_parser · 70%
info
Tool: search_assets manifest_parser · 70%
info
Tool: get_asset manifest_parser · 70%
info
Tool: get_asset_activity manifest_parser · 70%
info
Tool: list_threat_indicators manifest_parser · 70%
info
Tool: add_threat_indicator manifest_parser · 70%
info
Tool: search_threat_activity manifest_parser · 70%
info
Tool: list_alerts manifest_parser · 70%
info
Tool: get_alert manifest_parser · 70%
info
Tool: update_alert_status manifest_parser · 70%
info
Tool: get_alert_evidence manifest_parser · 70%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (4) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 283 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%