Anywhere MCP Server
About
AlienVault/USM Anywhere MCP Server - Threat intelligence and security monitoring
Explore
- OAuth 2.0 Authentication: Secure authentication using client credentials flow
- USM Anywhere API Integration: Access to alarms, events, and security data
- Legacy OTX Support: Backward compatibility with AlienVault OTX API
- Type-Safe: Built with TypeScript and Zod validation
- MCP Protocol: Standard Model Context Protocol implementation
1. Clone the repository:
git clone https://github.com/jballesteros/anywhere-mcp-server.git
cd anywhere-mcp-server
2. Install dependencies:
npm install
3. Build the project:
npm run build
ANYWHERE_CLIENT_ID=your_client_id
ANYWHERE_CLIENT_SECRET=your_client_secret
ANYWHERE_SUBDOMAIN=your_subdomain
1. Log into your USM Anywhere console
2. Navigate to Settings > API Keys
3. Create a new API key with appropriate permissions
4. Note your subdomain from the URL (e.g., company.alienvault.cloud)
1. get_alarms - Retrieve security alarms with filtering options
2. get_events - Retrieve security events with filtering options
3. get_alarm_details - Get detailed information about a specific alarm
4. get_event_details - Get detailed information about a specific event
5. search_pulses - Search threat intelligence pulses
6. get_indicator - Get indicator information (IP, domain, hash)
7. get_pulse - Get detailed pulse information
A Model Context Protocol (MCP) server for integrating with Levelblue USM Anywhere platform. This server provides secure access to security monitoring data including alarms, events, and threat intelligence through the USM Anywhere API v2.0.
Features
- OAuth 2.0 Authentication: Secure authentication using client credentials flow
- USM Anywhere API Integration: Access to alarms, events, and security data
- Legacy OTX Support: Backward compatibility with AlienVault OTX API
- Type-Safe: Built with TypeScript and Zod validation
- MCP Protocol: Standard Model Context Protocol implementation
Available Tools
USM Anywhere API v2.0 Tools
1. get_alarms - Retrieve security alarms with filtering options
2. get_events - Retrieve security events with filtering options
3. get_alarm_details - Get detailed information about a specific alarm
4. get_event_details - Get detailed information about a specific event
Legacy OTX API Tools
5. search_pulses - Search threat intelligence pulses
6. get_indicator - Get indicator information (IP, domain, hash)
7. get_pulse - Get detailed pulse information
Installation
1. Clone the repository:
git clone https://github.com/jballesteros/anywhere-mcp-server.git
cd anywhere-mcp-server
2. Install dependencies:
npm install
3. Build the project:
npm run build
Configuration
USM Anywhere API (Primary)
Create a .env file with your USM Anywhere credentials:
```env
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



