Mcp Msdefenderkql is a Model Context Protocol (MCP) server: Execute KQL queries against Microsoft Defender Advanced Hunting via natural language. Because it speaks the Model Context Protocol, AI assistants can use Mcp Msdefenderkql as a set of callable tools instead of you copy-pasting between apps.
It runs locally: the Python package mcp-msdefenderkql (via uvx) speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v1.0.2.
On mcp.site, Mcp Msdefenderkql sits in the Development category. Any MCP client can use it — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed among them — via the install snippets below. If you maintain Mcp Msdefenderkql for trickyfalcon, claim this listing to verify ownership, earn the Verified badge, and keep the details current.
▸PyPI package — mcp-msdefenderkql · MCP over stdio