INFOKOM-KI/Wazuh-MCP-Server ? reverse-engineered prompt
Reverse engineered prompt
Build me a blue team MCP server for Wazuh that I can plug into Claude Desktop or any MCP client.
I want it to let me inspect Wazuh alerts and agents, look up threat intel from a few common sources, correlate alerts against MITRE ATT&CK, and run guided investigation workflows for SOC work. It should be safe by default, so read only unless I explicitly enable write actions. Also add support for local case notes and simple forensics helpers, plus a way to export/share a sanitized incident bundle when needed.
Make it usable from either local stdio or a remote HTTP setup, with startup config taken from environment variables. Please include guardrails for redaction, auditing, rate limiting, and timeouts so it does not leak sensitive data or keep hammering upstream services. If you need current MCP or Wazuh details, look up the latest docs online and wire it up in a clean, reliable way.
Are you gonna build this?
make sure you review the code using coderabbit