Sysdig Cloud Security Monitoring
Unified workflow capability combining Sysdig Monitor and Sysdig Secure for cloud and container security monitoring. Enables security teams to correlate runtime security events with monitoring alerts, manage policies, track vulnerabilities, and maintain compliance across Kubernetes and cloud environments.
What You Can Do
MCP Tools
list-alerts
List Sysdig Monitor alerts for cloud-native infrastructure
get-alert
Get details of a specific Sysdig Monitor alert
create-alert
Create a new monitoring alert for cloud infrastructure
list-dashboards
List Sysdig Monitor dashboards
list-monitor-events
List Sysdig Monitor events within a time range
list-security-events
List Sysdig Secure runtime security events triggered by policy violations
list-vulnerabilities
List container and host vulnerability scanning results
get-image-vulnerabilities
Get vulnerability findings for a specific container image
get-image-sbom
Get the Software Bill of Materials (SBOM) for a container image
scan-image
Trigger a vulnerability scan for a container image
list-scanned-images
List all container images that have been scanned
list-policies
List Sysdig Secure runtime security policies
get-policy
Get details of a specific runtime security policy
create-policy
Create a new runtime security policy
list-falco-rules
List all Falco security detection rules
create-falco-rule
Create a custom Falco detection rule
list-compliance-tasks
List compliance evaluation tasks (PCI-DSS, GDPR, NIST)
get-compliance-results
Get compliance check results for a specific task
list-activity-audit
List the activity audit trail for forensic investigation
list-teams
List all Sysdig teams and their configurations
find-metrics
Search for available Sysdig metrics by name pattern