AI Agents - MCP Tool Configured

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query identifies AI agents that have Model Context Protocol (MCP) tools configured. MCP tools extend agent capabilities but introduce additional security considerations because they can execute advanced operations and interact with external resources. If misconfigured or unnecessary, these tools may increase the attack surface and expose sensitive data or functionality. Recommended Action: Confirm with the agent owner whether the MCP tool is still required. If it is, review its configuratio

Attribute Value
Type Hunting Query
Solution GitHub Only
ID a4e48491-6ed6-4064-bac2-385ef0e41afe
Tactics Execution
Techniques T1059
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/AI%20Agents/AgentsInfoMCPToolConfigured.yaml)

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
IdentityInfo ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries