Blue Team SOC automation MCP server for Wazuh - provides tools for IOC extraction, domain permutation, index schema exploration, and integration with Wazuh Indexer (OpenSearch)
This is a well-structured blue-team security MCP server with 4 tools, all of which have excellent naming, comprehensive descriptions, and detailed parameter schemas. Tools follow the verb_noun pattern (blueteam_extract_iocs, blueteam_ioc_lifecycle, blueteam_index_schema, blueteam_domain_permute) and are verb-driven. Descriptions are detailed (180-280 chars) with context on WHEN and WHY to use each tool, and all parameters have type definitions and descriptions. The decorator pattern (blueteam_tool) demonstrates strong SOC/security discipline with audit logging, redaction, truncation, and tool annotations. However, output schemas are not explicitly documented in parameter definitions (the tool descriptions mention what is RETURNED but do not show a formal output schema structure), and error handling guidance is not visible in the provided code snippet. The tools are genuinely read-only with no destructive operations, and the composition is clean, each tool does one thing well.
Generate typosquatting/phishing lookalikes of a domain. Produces the most likely near-miss domains an attacker would register against your org (omission, swap, repetition, homoglyph, hyphenation, TLD swap). Feed the top candidates into `blueteam_whois_lookup` / `blueteam_crtsh_lookup` to detect active typosquatting. Pure stdlib no network.
Extract structured Indicators of Compromise from raw text. Parses alert text, log lines, or full_log fields and returns deduplicated lists of IPs, domains, URLs, email addresses, and file hashes (MD5/SHA1/SHA256). **Filters noise**: skips private IPs (10.x, 192.168.x, 172.16-31.x), loopback, broadcast, and common DNS resolvers. Use this BEFORE calling threat intel tools — extract IOCs from alerts, then feed the results to CrowdSec, ThreatFox, VirusTotal, or WHOIS.
Discover Wazuh Indexer field names and types before building queries. Returns each field's type and whether it has a `.keyword` sub-field. Use this BEFORE aggregation queries to avoid the silent false-negative where `field.keyword` doesn't exist (index stores plain `keyword`).
Query the IOC lifecycle store - discovered IOCs ranked by time-decay recency. Returns IOCs recorded from alert extraction (blueteam_extract_iocs) and 3-Sum Engine A triggers, ranked by (decay_weight, count). Recent IOCs score closer to 1.0; IOCs older than the half-life (7 days) approach 0. Priority = recency of last observation, then observation count.
Output schemas not formally documented in tool definitions. Descriptions state what is returned (e.g., 'deduplicated lists of IPs, domains, URLs') but do not include a structured JSON Schema for the response object. LLMs need explicit output schemas to plan downstream tool calls and extract fields reliably.
Error handling guidance not visible in provided tool definitions. No recovery hints (e.g., 'If index not found, try blueteam_index_schema() first') or categorization of errors (retryable vs. user-fixable vs. fatal). The decorator catches BlueTeamMCPError but error messages to the LLM are not shown in the sample code.
Pagination not visible in blueteam_ioc_lifecycle. The tool accepts 'top_n' (max 200 items) but does not expose a next_cursor or offset/page parameters for retrieving more results beyond the limit. Large IOC stores may require cursor-based pagination.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
blueteam_extract_iocs and blueteam_domain_permute offer 'markdown' or 'json' response formats, but the actual schema structures for those responses are not documented. An LLM cannot reliably extract fields from markdown without knowing the exact format.