4,500+ servers built on MCP Fusion
Vinkius
Cortex XSIAM logo
Vinkius
Claude Code logo

How to Use the Cortex XSIAM MCP in Claude Code

Pipe Cortex XSIAM security telemetry and XQL query results directly into your terminal with Claude Code.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Cortex XSIAM MCP on Cursor AI Code Editor MCP Client Cortex XSIAM MCP on Claude Desktop App MCP Integration Cortex XSIAM MCP on OpenAI Agents SDK MCP Compatible Cortex XSIAM MCP on Visual Studio Code MCP Extension Client Cortex XSIAM MCP on GitHub Copilot AI Agent MCP Integration Cortex XSIAM MCP on Google Gemini AI MCP Integration Cortex XSIAM MCP on Lovable AI Development MCP Client Cortex XSIAM MCP on Mistral AI Agents MCP Compatible Cortex XSIAM MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Code

Connect Cortex XSIAM MCP to Claude Code

Create your Vinkius account to connect Cortex XSIAM to Claude Code and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Execute raw XQL threat hunts from the command line

`run_xql_query` runs raw Cortex Query Language queries against your log repositories, returning raw security events directly to your shell. Claude Code lets you pipe these query results into standard Unix utilities like grep, jq, or awk for rapid parsing. You don't need a heavy browser interface to hunt for active threats. You type your search criteria in plain English, and the CLI translates it into a precise XQL query, executes it, and formats the output.

Triage incidents and isolate hosts via Claude Code

`get_incidents` lists active security incidents in your SOC queue, allowing you to filter by severity or analyst workload from your terminal. When you spot a critical compromise, you run `isolate_endpoint` through this MCP Server to instantly cut off the infected host. This terminal-first approach cuts down response times to seconds. You can query incident details using `get_incident_details` and trigger a cleanup scan with `scan_endpoint` using fast, sequential commands.

Audit indicators of compromise from your terminal

`get_indicators` pulls known-bad IPs, domains, and file hashes from your threat intelligence database. Claude Code uses this tool to check local server logs or deployment files against live threat feeds. You can script this audit to run as a pre-deployment check or a cron job. The MCP Server acts as a bridge, allowing your terminal agent to verify your infrastructure's safety before pushing code live.

Setup guide

Set up Cortex XSIAM MCP in Claude Code

Prerequisites

  • Claude Code CLI installed (npm install -g @anthropic-ai/claude-code)
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Run the add command

    Open your terminal and run the command shown on the right. Replace [YOUR_TOKEN_HERE] with your endpoint token from cloud.vinkius.com. Use --scope user to make it available across all projects.

  2. 2

    Verify the connection

    Start a Claude Code session and type /mcp to list connected servers. You should see cortex-xsiam-mcp with a green status indicator.

  3. 3

    Start using tools

    Ask Claude Code something like "Check my latest Cortex XSIAM transactions." It will automatically discover and invoke the available Cortex XSIAM tools.

Terminal
claude mcp add --transport http cortex-xsiam-mcp https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Cortex XSIAM MCP in Claude Code

You instruct the CLI to execute `execute_playbook` with your chosen playbook name and arguments. Claude Code triggers the automation and outputs the execution logs directly to your terminal.
Yes. Because Claude Code is a headless CLI, you can script it to run `run_xql_query` and check for indicators of compromise during automated deployment stages.
Run `claude mcp add --transport http cortex-xsiam -- ` in your terminal. This registers the server in your `~/.claude.json` configuration file.
Yes. You can tell the CLI to loop through a list of host IDs from `get_endpoints` and trigger `scan_endpoint` on each one sequentially.
All API payloads, including XQL queries, indicator lists, and playbook parameters, run through a secure, isolated V8 sandbox. Your credentials and security data are never cached on external servers.

Start using the Cortex XSIAM MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 9 tools

We've already built the connector for Cortex XSIAM. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 9 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.