ClaudeChatGPTPerplexityGeminiMicrosoft CopilotRaycastMeta AIGrokZ.aiQwenKimi
DeepSeekMistralCursorVS CodeWindsurfJetBrainsClineLovableVercel AI SDKLangChain

Use Cortex XSIAM with your AI.

Connect your account once and let the AI you already use work with it, without building another integration. Connect Cortex XSIAM to any AI agent via MCP.

Included with plan

Ask AI about this Connector

Developed, maintained, and hosted by Vinkius.

MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED

Waiting for input…

Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.

ChatGPTClaudeCursorPerplexityGeminiMicrosoft CopilotRaycastMeta AI

Complete set · 9 capabilities

The complete Cortex XSIAM capability set.

These are the exact actions your AI can choose when you ask it to work with Cortex XSIAM.

Capability set01 / 03

01-03

3 capabilities in this set.

Part of 9 available through Cortex XSIAM.

  1. 01

    Execute playbook

    G., enrich IOCs, block IP, reset password). Requires playbook name and optional input arguments. Use this to speed up response times and ensure consistent handling of incidents. Execute an automated incident response playbook in Cortex XSIAM

  2. 02

    Get alerts

    Use this to review detection rules firing or analyze threat patterns. List security alerts detected by Cortex XSIAM

  3. 03

    Get incidents

    Use this to monitor SOC queue, identify high-severity incidents, or track analyst workload. Supports sorting and limiting results. List security incidents in Cortex XSIAM

Capability set02 / 03

04-06

3 capabilities in this set.

Part of 9 available through Cortex XSIAM.

  1. 04

    Get indicators

    Use this to review threat intelligence or check if specific artifacts are known malicious. List indicators of compromise (IOCs) tracked in Cortex XSIAM

  2. 05

    Get endpoints

    Use this to audit endpoint coverage, identify disconnected hosts, or target remediation actions. List managed endpoints (hosts/devices) in Cortex XSIAM

  3. 06

    Get incident details

    Requires the incident ID. Use this for deep investigation or context before taking action. Get detailed information about a specific security incident

Capability set03 / 03

07-09

3 capabilities in this set.

Part of 9 available through Cortex XSIAM.

  1. 07

    Isolate endpoint

    Requires the endpoint ID. Use this immediately upon confirming a severe compromise to prevent lateral movement. Isolate a compromised endpoint from the network

  2. 08

    Run xql query

    XQL allows searching logs, endpoints, network data, and more. Requires a valid XQL query string. Returns the results of the query. Use this for custom threat hunting, compliance reporting, or data analysis. Execute an XQL (Cortex Query Language) query for advanced threat hunting

  3. 09

    Scan endpoint

    Supports "quick" or "deep" scan types. Requires the endpoint ID. Use this to verify if a host is infected or after cleaning a threat. Trigger a malware scan on a specific endpoint

Observed, not estimated

838ms average. Fast in production.

Cortex XSIAM is checked daily against the live service.

Daily averagePeak 1074ms
Aug 24Today
Fastest day
742ms
Slowest day
1074ms
14-day trend
Improving-25%

Connect your client

One URL. Every client.

Activate the Connector, copy your link, and paste it into the client you already use. 9 capabilities arrive ready to run.

Preview access · not provider authentication

The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Cortex XSIAM, so you can see the experience inside your AI.

It does not authenticate your account with Cortex XSIAM. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.

Cortex XSIAM Connector

You're all set. Choose your MCP client and follow the setup instructions.

Connector linkhttps://edge.vinkius.com/vk_preview_YwrSpVSwSvDK62ayYXdVmPKCeutuJGKGx2KNGGce/mcp

Claude Desktop

Follow the steps below to connect in seconds.

  1. 1In Claude Desktop, open Settings → Connectors.
  2. 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
  3. 3Click Add and start a new chat — Cortex XSIAM capabilities are ready to use.
Configuration · claude_desktop_config.jsonCopy
{
  "mcpServers": {
    "cortex-xsiam-mcp": {
      "url": "https://edge.vinkius.com/vk_preview_YwrSpVSwSvDK62ayYXdVmPKCeutuJGKGx2KNGGce/mcp"
    }
  }
}
  • Claude
  • ChatGPT
  • Cursor
  • VS Code
  • Windsurf
  • Claude Code
  • JetBrains
  • Cline

Step-by-step instructions for each client are in the guide. How to connect