Cortex MCP server

The Cortex MCP Server connects your LLM applications to your Cortex tenant. It uses the Model Context Protocol (MCP), a standard for connecting AI models with applications and tools. Use natural language to investigate and manage your Cortex data.

**Key capabilities**

* Investigate

 Use the built-in tools to manage cases and issues, and conduct investigations.
* Customize

 Create, customize, and fine-tune tools to fit specific use cases and workflows.
* Flexible client

 The Cortex MCP Server is provided as a downloadable file that can be installed on a local machine or a container. While these instructions use Claude Desktop as the MCP client, you can use any client that supports MCP. More detailed setup instructions are provided in the README file included in the download.

The Cortex MCP Server empowers you to integrate AI into your security workflows using natural language. When using LLM-based suggestions, always review and approve actions suggested by the AI before they're executed. We recommend deploying the Cortex MCP server in a secure environment where access is limited to authorized users.

To install, configure, and use the Cortex MCP server:

1. [Install the Cortex MCP server](cortex-mcp-server/install-the-cortex-mcp-server)
2. [Configure the MCP client](cortex-mcp-server/configure-the-mcp-client)
3. (Optional) [Create custom Cortex MCP server tools](cortex-mcp-server/create-custom-cortex-mcp-server-tools)
4. [Use the Cortex MCP server](cortex-mcp-server/use-the-cortex-mcp-server)

Sub-topics