Use Cortex XSIAM with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Connect Cortex XSIAM to any AI agent via MCP.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 9 capabilities
The complete Cortex XSIAM capability set.
These are the exact actions your AI can choose when you ask it to work with Cortex XSIAM.
01-03
3 capabilities in this set.
Part of 9 available through Cortex XSIAM.
- 01
Execute playbook
G., enrich IOCs, block IP, reset password). Requires playbook name and optional input arguments. Use this to speed up response times and ensure consistent handling of incidents. Execute an automated incident response playbook in Cortex XSIAM
- 02
Get alerts
Use this to review detection rules firing or analyze threat patterns. List security alerts detected by Cortex XSIAM
- 03
Get incidents
Use this to monitor SOC queue, identify high-severity incidents, or track analyst workload. Supports sorting and limiting results. List security incidents in Cortex XSIAM
04-06
3 capabilities in this set.
Part of 9 available through Cortex XSIAM.
- 04
Get indicators
Use this to review threat intelligence or check if specific artifacts are known malicious. List indicators of compromise (IOCs) tracked in Cortex XSIAM
- 05
Get endpoints
Use this to audit endpoint coverage, identify disconnected hosts, or target remediation actions. List managed endpoints (hosts/devices) in Cortex XSIAM
- 06
Get incident details
Requires the incident ID. Use this for deep investigation or context before taking action. Get detailed information about a specific security incident
07-09
3 capabilities in this set.
Part of 9 available through Cortex XSIAM.
- 07
Isolate endpoint
Requires the endpoint ID. Use this immediately upon confirming a severe compromise to prevent lateral movement. Isolate a compromised endpoint from the network
- 08
Run xql query
XQL allows searching logs, endpoints, network data, and more. Requires a valid XQL query string. Returns the results of the query. Use this for custom threat hunting, compliance reporting, or data analysis. Execute an XQL (Cortex Query Language) query for advanced threat hunting
- 09
Scan endpoint
Supports "quick" or "deep" scan types. Requires the endpoint ID. Use this to verify if a host is infected or after cleaning a threat. Trigger a malware scan on a specific endpoint
Observed, not estimated
838ms average. Fast in production.
Cortex XSIAM is checked daily against the live service.
- Fastest day
- 742ms
- Slowest day
- 1074ms
- 14-day trend
- Improving-25%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 9 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Cortex XSIAM, so you can see the experience inside your AI.
It does not authenticate your account with Cortex XSIAM. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Cortex XSIAM Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_YwrSpVSwSvDK62ayYXdVmPKCeutuJGKGx2KNGGce/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Cortex XSIAM capabilities are ready to use.
{
"mcpServers": {
"cortex-xsiam-mcp": {
"url": "https://edge.vinkius.com/vk_preview_YwrSpVSwSvDK62ayYXdVmPKCeutuJGKGx2KNGGce/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
Explore
More in Other
CrowdStrike Falcon AI Connector
Detect threats, manage endpoints, investigate incidents, and query telemetry from CrowdStrike Falcon — the #1
ViewHalo Security AI Connector
Automate attack surface management via Halo Security — monitor assets, scans, and vulnerabilities directly fro
ViewCrowdSec AI Connector
Automate threat intelligence via CrowdSec — query local decisions, stream security updates, and check global I
ViewCyberArk Privilege Cloud AI Connector
Manage privileged access via CyberArk — audit secure safes, checkout vaulted account passwords, monitor users,
View
Suggestions
SecurityTrails AI Connector
Uncover IT infrastructure — access DNS history, subdomains, reverse IP lookups, WHOIS data and advanced domain
ViewCyberimpact AI Connector
Email marketing automation with Cyberimpact.
ViewEverbridge Critical Management AI Connector
Equip your AI agent to manage critical notifications, track incidents, and monitor contacts via the Everbridge
ViewKnowBe4 (KMSAT Reporting) AI Connector
Audit security awareness — list users, track phishing tests, and monitor risk scores.
View
