Mcp Msdefenderkql

io.github.trickyfalconv1.0.2Updated Sep 23, 2026

Execute KQL queries against Microsoft Defender Advanced Hunting via natural language.

VerifiedSTDIODesktop onlyOther

Installation

In SourceWeft

  1. Open Mcp Msdefenderkql in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.2LatestSep 16, 2026