Skip to content

nuoframework/darktrace-mcp

v1.1.2Apache-2.0

Investigate alerts, devices and incidents on your own Darktrace Threat Visualizer appliance through a local MCP server: read-only by default, previews for every change and human approval for critical actions.

darktrace-investigation

Investigate alerts, devices, incidents and response actions on a Darktrace Threat Visualizer appliance with the darktrace MCP tools. Use for any question about model breaches, AI Analyst incidents, devices, connections, Antigena, tags or Watched Domains. Read-only first, small responses, preview and human approval before any critical action.

Read SKILL.md at the source

Pinned to revision 6d2e816d6f8f, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.