
Crowdsentinel MCP Server
by thomasxmio.github.thomasxm/crowdsentinel-mcp-serverv0.6.0
AI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics
context tax
queued
security
queued
cold start
queued
freshness
Maintained3mo ago
Install Crowdsentinel MCP server
Install in Claude Code
claude mcp add crowdsentinel -e ELASTICSEARCH_API_KEY='<elasticsearch-api-key>' -e ELASTICSEARCH_PASSWORD='<elasticsearch-password>' -e ELASTICSEARCH_BEARER_TOKEN='<elasticsearch-bearer-token>' -- uvx crowdsentinel-mcp-serverInstall in Cursor
{
"mcpServers": {
"crowdsentinel": {
"command": "uvx",
"args": [
"crowdsentinel-mcp-server"
],
"env": {
"ELASTICSEARCH_API_KEY": "<elasticsearch-api-key>",
"ELASTICSEARCH_PASSWORD": "<elasticsearch-password>",
"ELASTICSEARCH_BEARER_TOKEN": "<elasticsearch-bearer-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"crowdsentinel": {
"command": "uvx",
"args": [
"crowdsentinel-mcp-server"
],
"env": {
"ELASTICSEARCH_API_KEY": "<elasticsearch-api-key>",
"ELASTICSEARCH_PASSWORD": "<elasticsearch-password>",
"ELASTICSEARCH_BEARER_TOKEN": "<elasticsearch-bearer-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"crowdsentinel": {
"type": "stdio",
"command": "uvx",
"args": [
"crowdsentinel-mcp-server"
],
"env": {
"ELASTICSEARCH_API_KEY": "<elasticsearch-api-key>",
"ELASTICSEARCH_PASSWORD": "<elasticsearch-password>",
"ELASTICSEARCH_BEARER_TOKEN": "<elasticsearch-bearer-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"crowdsentinel": {
"command": "uvx",
"args": [
"crowdsentinel-mcp-server"
],
"env": {
"ELASTICSEARCH_API_KEY": "<elasticsearch-api-key>",
"ELASTICSEARCH_PASSWORD": "<elasticsearch-password>",
"ELASTICSEARCH_BEARER_TOKEN": "<elasticsearch-bearer-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ELASTICSEARCH_HOSTS | — | — | Comma-separated Elasticsearch hosts. Supports HTTP/HTTPS, local/remote/cloud (e.g., http://localhost:9200, https://es.prod.example.com:9200) |
| ELASTICSEARCH_CLOUD_ID | — | — | Elastic Cloud deployment ID (alternative to ELASTICSEARCH_HOSTS for cloud deployments) |
| ELASTICSEARCH_API_KEY | — | yes | API key for authentication (recommended for production and Elastic Cloud) |
| ELASTICSEARCH_USERNAME | — | — | Username for basic authentication (alternative to API key) |
| ELASTICSEARCH_PASSWORD | — | yes | Password for basic authentication (used with ELASTICSEARCH_USERNAME) |
| ELASTICSEARCH_BEARER_TOKEN | — | yes | Bearer/service token for authentication (alternative to API key) |
| VERIFY_CERTS | — | — | TLS certificate verification: true (verify CA — production), false (skip — dev/test), or /path/to/ca.crt (custom CA) |
| REQUEST_TIMEOUT | — | — | Request timeout in seconds (e.g., 60 or 10.5) |
Freshness
Maintained — last maintenance signal 3mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-07-19 · 3mo ago · GitHub
Latest release
2026-07-19 · 3mo ago · GitHub · v0.6.0
Package published
no data · npm/PyPI
Registry entry updated
2026-07-19 · 3mo ago · official registry · v0.6.0
FAQ
›How do I install the Crowdsentinel MCP server in Claude Code?
Run: claude mcp add crowdsentinel -e ELASTICSEARCH_API_KEY='<elasticsearch-api-key>' -e ELASTICSEARCH_PASSWORD='<elasticsearch-password>' -e ELASTICSEARCH_BEARER_TOKEN='<elasticsearch-bearer-token>' -- uvx crowdsentinel-mcp-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Crowdsentinel require an API key?
Yes. It expects ELASTICSEARCH_API_KEY, ELASTICSEARCH_PASSWORD, ELASTICSEARCH_BEARER_TOKEN, of which 3 are secrets.
›Can I use Crowdsentinel as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Crowdsentinel in the official MCP registry?
Yes, as io.github.thomasxm/crowdsentinel-mcp-server.
Alternatives to Crowdsentinel
Other security MCP servers.