Skip to content
appsgit

Crowdsentinel MCP Server

Crowdsentinel MCP Server is an MCP server that adds database tools to AI assistants such as Claude Desktop, Claude Code and Cursor. AI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics. It has 208 GitHub stars, is released under the GPL-3.0 license and runs locally with uvx crowdsentinel-mcp-server.

github.com/thomasxm/CrowdSentinels-AI-MCP (opens in a new tab)

  • Needs API key
  • Databases
  • GPL-3.0
  • Actively maintained

Install Crowdsentinel MCP Server

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "crowdsentinel-mcp-server": {
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "your-value",
        "ELASTICSEARCH_PASSWORD": "your-value",
        "ELASTICSEARCH_BEARER_TOKEN": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env ELASTICSEARCH_API_KEY=your-value --env ELASTICSEARCH_PASSWORD=your-value --env ELASTICSEARCH_BEARER_TOKEN=your-value --transport stdio crowdsentinel-mcp-server -- uvx crowdsentinel-mcp-server

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "crowdsentinel-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "your-value",
        "ELASTICSEARCH_PASSWORD": "your-value",
        "ELASTICSEARCH_BEARER_TOKEN": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "elasticsearch_api_key",
      "description": "ELASTICSEARCH_API_KEY",
      "password": true
    },
    {
      "type": "promptString",
      "id": "elasticsearch_password",
      "description": "ELASTICSEARCH_PASSWORD",
      "password": true
    },
    {
      "type": "promptString",
      "id": "elasticsearch_bearer_token",
      "description": "ELASTICSEARCH_BEARER_TOKEN",
      "password": true
    }
  ],
  "servers": {
    "crowdsentinel-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "${input:elasticsearch_api_key}",
        "ELASTICSEARCH_PASSWORD": "${input:elasticsearch_password}",
        "ELASTICSEARCH_BEARER_TOKEN": "${input:elasticsearch_bearer_token}"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
ELASTICSEARCH_HOSTSNoComma-separated Elasticsearch hosts. Supports HTTP/HTTPS, local/remote/cloud (e.g., http://localhost:9200, https://es.prod.example.com:9200)
ELASTICSEARCH_CLOUD_IDNoElastic Cloud deployment ID (alternative to ELASTICSEARCH_HOSTS for cloud deployments)
ELASTICSEARCH_API_KEYsecretNoAPI key for authentication (recommended for production and Elastic Cloud)
ELASTICSEARCH_USERNAMENoUsername for basic authentication (alternative to API key)
ELASTICSEARCH_PASSWORDsecretNoPassword for basic authentication (used with ELASTICSEARCH_USERNAME)
ELASTICSEARCH_BEARER_TOKENsecretNoBearer/service token for authentication (alternative to API key)
VERIFY_CERTSNoTLS certificate verification: true (verify CA — production), false (skip — dev/test), or /path/to/ca.crt (custom CA)
REQUEST_TIMEOUTNoRequest timeout in seconds (e.g., 60 or 10.5)

About Crowdsentinel MCP Server

Open-source threat hunting orchestrator connecting LLMs to enterprise security data via Model Context Protocol (MCP) Warning This project is in active development and intended for security testing, research, and educational purposes only. It is not production-ready. Do not deploy in production environments. APIs, tool interfaces, and data formats may change without notice. Use at your own risk.

FAQ

Crowdsentinel MCP Server FAQ

Still curious? Email info@appsgit.com.

What is Crowdsentinel MCP Server?

Crowdsentinel MCP Server is an MCP server that adds database tools to AI assistants such as Claude Desktop, Claude Code and Cursor. AI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics. It has 208 GitHub stars, is released under the GPL-3.0 license and runs locally with uvx crowdsentinel-mcp-server. The source code is at github.com/thomasxm/CrowdSentinels-AI-MCP.

How do I install the Crowdsentinel MCP Server MCP server?

Add the command uvx crowdsentinel-mcp-server to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is Crowdsentinel MCP Server free?

The server is open source under the GPL-3.0 license, so running it is free. It needs credentials (ELASTICSEARCH_API_KEY, ELASTICSEARCH_PASSWORD and ELASTICSEARCH_BEARER_TOKEN) for the service it connects to, which may require a paid account.

Is Crowdsentinel MCP Server actively maintained?

The most recent commit was on Jul 19, 2026. The latest release is v0.6.0, published Jul 19, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.