rapid7-mcp
Model Context Protocol server for the Rapid7 InsightIDR SIEM platform
Versions
1.0.0latestTools 26
search_logs Execute a LEQL (Log Entry Query Language) query against a specific log set in InsightIDR
list_log_sets List all available log sets in InsightIDR (Firewall, DNS, DHCP, Endpoint, Cloud, etc.)
get_log_entry Retrieve a specific log entry by its ID from a given log set
get_log_stats Get aggregate statistics for a log set over a time range using a LEQL query
search_investigations List and filter InsightIDR investigations by status, priority, assignee, or date range
get_investigation Get full details of a specific InsightIDR investigation including its timeline
create_investigation Create a new InsightIDR investigation with a title, priority, and status
update_investigation Update an existing investigation
add_investigation_comment Add a comment or note to an InsightIDR investigation
get_investigation_alerts Get all alerts associated with a specific investigation
search_users Search user accounts monitored by InsightIDR by name, email, domain, or department
get_user_activity Get user behavior analytics data: login times, locations, accessed assets, and anomalies
get_risky_users Get users with abnormal behavior scores from InsightIDR
list_saved_queries List saved LEQL queries available in InsightIDR
create_saved_query Save a LEQL query for reuse in InsightIDR
leql_help Get LEQL (Log Entry Query Language) syntax reference, examples, and common patterns for InsightIDR log searches
search_assets Search InsightIDR assets (endpoints) by hostname, IP address, OS, or agent status
get_asset Get full details of an InsightIDR asset including installed software, vulnerabilities, and network interfaces
get_asset_activity Get recent activity for an asset including logins, processes, and network connections
list_threat_indicators List IOCs (IPs, domains, hashes) in the InsightIDR threat library
add_threat_indicator Add a new IOC (IP, domain, hash, etc.) to the InsightIDR custom threat library
search_threat_activity Search for threat indicator matches in InsightIDR logs — find where known IOCs have been seen
list_alerts List InsightIDR alerts with optional filters for severity, type, status, and date range
get_alert Get full details of a specific InsightIDR alert including its detection rule and metadata
update_alert_status Update the status of an InsightIDR alert (open, investigating, or closed)
get_alert_evidence Get evidence and indicators associated with an InsightIDR alert
Permissions 2
network medium env_vars low