← Back to Claude Tool Reviews

Wazuh MCP Server (SIEM)

Connector Security Early

AI-powered SIEM integration for Wazuh with 48 security tools. Natural language queries for alerts, threat hunting, vulnerability assessment, and active response. Air-gapped deployment support.

157 starsMIT (commercial OK)FreeDeveloper setup
New Find — Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.
Fair rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Talk to your SIEM — security teams query alerts, hunt threats, and check compliance in plain English instead of writing complex queries.

Security operations teams using Wazuh who want conversational threat hunting and alert investigation.

Claude Code Claude Cowork Claude Chat

https://github.com/gensecaihq/Wazuh-MCP-Server

By gensecaihq

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
CostFree

Trust Signals Automated Scan

Stars157Contributors11Last updated2026-03-31LicenseMIT (OK for commercial use)Known CVEsNone found

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Reddit

7 mentions across 1 sources

Reviewer notes

Automated Scan review. These are observations, not a security certification.

MIT. Supports air-gapped deployment.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
2/5
Reliability
3/5
Security
4/5
Overall score2.90 / 5.00 EarlyEvaluatedApr 2026

← Back to Claude Tool Reviews