Developer · Local MCP server

Abnormal MCP Server

Abnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download.

Visit Abnormal MCP Server's website

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.GregDog/mcp-server-abnormal
Version
1.1.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-09-17
Updated
2026-09-17
Publisher
GregDog (GitHub) · 2 servers with pages here
Website
github.com/GregDog/mcp-server-abnormal
Repository
github.com/GregDog/mcp-server-abnormal
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)ghcr.io/gregdog/mcp-server-abnormal:v1.1.0—stdioABNORMAL_API_TOKEN (required, secret), ABNORMAL_BASE_URL, ABNORMAL_ALLOW_RESPONSE, ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD, ABNORMAL_MAX_EVIDENCE_BYTES

How to connect Abnormal MCP Server

Abnormal MCP Server runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/gregdog/mcp-server-abnormal:v1.1.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e ABNORMAL_API_TOKEN -e ABNORMAL_BASE_URL -e ABNORMAL_ALLOW_RESPONSE -e ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD -e ABNORMAL_MAX_EVIDENCE_BYTES ghcr.io/gregdog/mcp-server-abnormal:v1.1.0. It reads these environment variables: ABNORMAL_API_TOKEN (required, secret), ABNORMAL_BASE_URL, ABNORMAL_ALLOW_RESPONSE, ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD and ABNORMAL_MAX_EVIDENCE_BYTES; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "mcp-server-abnormal": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "ABNORMAL_API_TOKEN",
        "-e",
        "ABNORMAL_BASE_URL",
        "-e",
        "ABNORMAL_ALLOW_RESPONSE",
        "-e",
        "ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD",
        "-e",
        "ABNORMAL_MAX_EVIDENCE_BYTES",
        "ghcr.io/gregdog/mcp-server-abnormal:v1.1.0"
      ],
      "env": {
        "ABNORMAL_API_TOKEN": "<secret>",
        "ABNORMAL_BASE_URL": "<value>",
        "ABNORMAL_ALLOW_RESPONSE": "<value>",
        "ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD": "<value>",
        "ABNORMAL_MAX_EVIDENCE_BYTES": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from GregDog (GitHub)

All 2 →
ServerRunsEndpoint or package
Openlane MCP ServerMCP server for Openlane GRC: controls, evidence, policies, risks, workflows, and approvals.Local · stdioOCI image (Docker): ghcr.io/gregdog/mcp-server-theopenlane:v0.8.0

More developer servers

All 6,250 →
ServerRunsEndpoint or package
abbyseo.comScan any URL for on-page, technical & content SEO; 0-100 score with copy-paste fixes.Remote · HTTPabbyseo.com
abcopABC complexity gate for AI-written code with an MCP inspection tool.Local · stdioCargo (crates.io): abcop
AblyMCP server for Ably — channel history, presence, occupancy, stats, publish, and app management.Remote · HTTPably.usefulapi.io
ABMeterRun A/B experiments through your AI assistant. SDKs for Ruby, Python, JS, Node, React Native, Go.Remote · HTTPmcp.abmeter.ai
Abnormal SecurityMCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/abnormal-mcp:v1.2.6
Abnormal SecurityMCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.Local · stdioOCI image (Docker): ghcr.io/wyre-technology/abnormal-mcp:v1.2.5
Abnormal Security MCPAbnormal Security email threats, cases, and reporting in your terminal and your AI agents.Local · stdioMCP Bundle (.mcpb): Servosity/msp-skills/releases/download/abnormal-
AbscissaSafety-aware MCP server for Linear issues, projects, cycles, and dependencies.Local · stdioPyPI: abscissa