Stellar Cyber Security Operations
Unified security operations workflow combining Stellar Cyber's Open XDR API capabilities for incident response, threat hunting, case management, and automated playbook execution. Designed for SOC analysts and security engineers who need to investigate alerts, manage cases, monitor sensors, and automate response actions.
What You Can Do
MCP Tools
list-cases
Retrieve security cases from Stellar Cyber. Use for investigating ongoing incidents and tracking case status.
create-case
Create a new security case in Stellar Cyber. Use when an alert or event requires formal investigation and tracking.
get-case
Get detailed information about a specific security case by ID.
update-case
Update a security case status, priority, or other attributes. Use to progress cases through investigation workflows.
list-alerts
Retrieve security alerts from Stellar Cyber Open XDR. Use for alert triage and identifying threats requiring investigation.
ingest-events
Ingest custom security event documents into Stellar Cyber for analysis and correlation.
list-watchlists
Retrieve all threat watchlists. Use to check what indicators and entities are currently being monitored.
create-watchlist
Create a new watchlist for tracking threat indicators such as malicious IPs, domains, or file hashes.
list-sensors
List all sensors registered with Stellar Cyber. Use to check sensor health and coverage across the environment.
list-playbooks
Retrieve all automated response playbooks. Use to review available automation workflows for threat response.
create-playbook
Create a new ATH Playbook response action for automated threat response.
list-reports
List available security reports. Use for compliance reporting and security posture reviews.
create-report
Generate a new security report for compliance or executive reporting.