Wazuh SIEM Agent System
A Claude-powered MCP tool suite for interacting with a Wazuh SIEM manager. Exposes Wazuh REST API capabilities as MCP tools so Claude can triage alerts, monitor agent health, hunt threats, manage rules, and propose/execute active responses.
Architecture
wazuh-agent/
├── mcp/
│ └── wazuh_mcp_server.py # MCP server — all tools registered here
├── agents/
│ ├── orchestrator.py # Routes queries to the right specialist agent
│ ├── triage.py # Alert severity analysis & MITRE mapping
│ ├── health.py # Fleet connectivity & health checks
│ ├── hunting.py # IOC search & behavioural pattern detection
│ ├── rules.py # Rule analysis & coverage gaps
│ └── response.py # Active response proposals & gated execution
├── config.py # Connection settings (credentials via env vars)
└── requirements.txt
The MCP server imports analysis functions from each agent module and exposes them as MCP tools. Claude (via Claude Code or another client) uses these tools to reason over real-time Wazuh data.
Setup
1. Install dependencies
pip install -r requirements.txt
2. Set credentials
Create a .env file (never commit this):
WAZUH_USER=your_api_user
WAZUH_PASSWORD=your_api_password
Or set environment variables directly in your shell.
3. Register the MCP server with Claude Code
Add to your Claude Code MCP settings (claude_desktop_config.json or .claude/settings.json):
{
"mcpServers": {
"wazuh": {
"command": "python",
"args": ["G:/claudeai/wazuh-agent/mcp/wazuh_mcp_server.py"],
"env": {
"WAZUH_USER": "${WAZUH_USER}",
"WAZUH_PASSWORD": "${WAZUH_PASSWORD}"
}
}
}
}
Available MCP Tools
Raw API tools
| Tool | Description | |------|-------------| | get_agents | List all agents by status | | get_agent_details | Details for a specific agent | | get_alerts | Recent alerts with optional level/agent filter | | get_manager_info | Manager version and status | | get_manager_stats | Events/alerts per hour | | get_agent_processes | Running processes (syscollector) | | get_agent_ports | Open ports (syscollector) | | get_agent_packages | Installed packages (syscollector) | | get_agent_vulnerabilities | CVEs by agent and severity | | get_rules | Search detection rules | | get_rule_by_id | Look up a specific rule |
Analysis tools
| Tool | Description | |------|-------------| | triage_alerts | Severity buckets, top rules, MITRE tactic counts | | check_health | Fleet health: disconnected/stale agents, unknowns | | hunt_ioc | Search all alerts for an IP, hash, domain, or username | | hunt_patterns | Detect brute-force, lateral movement, priv-esc patterns | | analyze_rules | Rule coverage summary and category breakdown | | propose_response | Ranked active-response options (no execution) | | execute_active_response | Execute a response — requires confirmed=True |
Known Agents
| ID | Name | Notes | |----|------|-------| | 000 | wazuh | Manager | | 001 | kali | | | 002 | Area-51 | | | 003 | Prism | | | 004 | DESKTOP-GPLJ6GT | | | 005 | vert-server | | | 006 | pve610 | Disconnected | | 007 | pve720XD | | | 008 | pve720 | |
Safety — Active Response
Active response commands modify target systems immediately and some are irreversible.
The workflow is always:
- Call
propose_response(agent_id, threat_summary)→ review options - Present proposals to the user and get explicit approval
- Call
execute_active_response(..., confirmed=True)only after approval
execute_active_response called without confirmed=True returns a blocked status and never touches the Wazuh API.











