Exaforce
ClaudecommunityThe ExaForce MCP connector lets Claude query your ExaForce security operations data directly. Ask about alerts, investigations, audit logs, and configuration from inside a Claude conversation.
Exaforce
Exaforce is an AI-powered SOC and MDR platform that correlates security signals across cloud, SaaS, identity, endpoint, network, and code systems. The MCP connector brings the Exaforce investigation and search experience directly into your Claude conversations. Once connected, ask Claude to query your Exaforce tenant in natural language. Search across users, endpoints, resources, and events; investigate alerts; pivot through related findings; and correlate runtime activity with configuration state — without learning a query language or switching tabs. Works with your existing Exaforce ingestion pipeline. Out-of-the-box coverage includes AWS, Okta, GitHub, Microsoft 365, and Google Workspace, plus the rest of the Exaforce-supported data sources. Authentication uses OAuth 2.1 with PKCE, scoped to your Exaforce tenant. The connector accesses only your tenant's data and never crosses tenant boundaries. See Exaforce's privacy policy for the data-flow disclosure when MCP is enabled.
Anthropic’s own published signals, snapshot of August 5, 2026; units undocumented — treat as ordinal.
Over time
Details
Tools(42)
- CQLGeneration
- ConfluenceGetPage
- DatabaseLookup
- DefenderXDRAdvancedHuntingQuery
- DefenderXDRGetIncident
- DesignTemplateGetTemplate
- DesignTemplateListTemplates
- ExecuteQuery
- GeoIPLookupTool
- GetAgentInputParameters
- GetAutomationAgentResult
- GoogleWorkspaceListOauthTokens
- GoogleWorkspaceQueryAuditReportsBigquery
- JiraGetIssue
- JiraSearchIssues
- ListAvailableQuestions
- ListQuestionsDetails
- LookUpTableGetData
- ManageBusinessContextRuleCreateRule
- ManageBusinessContextRuleDeleteRule
- ManageBusinessContextRuleFindSimilarRules
- ManageBusinessContextRuleGetRule
- ManageBusinessContextRuleListRules
- ManageBusinessContextRuleUpdateRule
- ManageCaseAddNote
- ManageCaseCreateCase
- ManageCaseGetCase
- ManageCaseUpdateCase
- PerplexitySearch
- QueryBuilderRequestBuildQuery
- QueryBuilderRequestBuildQueryV3
- QueryBuilderRequestExecuteQuery
- SchemaDescribe
- SentinelOneInvestigate
- SentinelOneIsolateDevice
- SentinelOneUpdateAlertStatus
- SentinelOneUpdateThreatStatus
- StartAgent
- UrlScanTool
- VirusTotalDomainScan
- VirusTotalFileScan
- VirusTotalUrlScan
Data from Claude’s public directory API, snapshotted daily by the MCP App Tracker. A listing describes what the directory publishes — not an endorsement.