Abnormal MCP Server
by gregdogio.github.GregDog/mcp-server-abnormalv1.1.0
Abnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download.
context tax
queued
security
queued
cold start
queued
freshness
Active10d ago
Install Abnormal MCP server
Install in Claude Code
claude mcp add abnormal -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/gregdog/mcp-server-abnormal:v1.1.0 serveInstall in Cursor
{
"mcpServers": {
"abnormal": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/gregdog/mcp-server-abnormal:v1.1.0",
"serve"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"abnormal": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/gregdog/mcp-server-abnormal:v1.1.0",
"serve"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"abnormal": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/gregdog/mcp-server-abnormal:v1.1.0",
"serve"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"abnormal": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/gregdog/mcp-server-abnormal:v1.1.0",
"serve"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ABNORMAL_API_TOKEN | yes | yes | Abnormal REST API bearer token |
| ABNORMAL_BASE_URL | — | — | Abnormal API base URL |
| ABNORMAL_ALLOW_RESPONSE | — | — | Enable response MCP tools (remediation) |
| ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD | — | — | Enable evidence download MCP tools (EML and attachments) |
| ABNORMAL_MAX_EVIDENCE_BYTES | — | — | Max bytes per evidence download from Abnormal |
Freshness
Active — last maintenance signal 10d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-29 · 10d ago · GitHub
Latest release
2026-09-17 · 22d ago · GitHub · v1.1.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-17 · 22d ago · official registry · v1.1.0
FAQ
›How do I install the Abnormal MCP server in Claude Code?
Run: claude mcp add abnormal -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/gregdog/mcp-server-abnormal:v1.1.0 serve. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Abnormal require an API key?
Yes. It expects ABNORMAL_API_TOKEN, of which 1 is a secret.
›Can I use Abnormal as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Abnormal in the official MCP registry?
Yes, as io.github.GregDog/mcp-server-abnormal.
Alternatives to Abnormal
Other security MCP servers.