Msspalert Command Zero Launches API and MCP Server for Enhanced SOC Automation
Article Content
- •Command Zero launched new APIs and an MCP server for SOC automation.
- •The platform integrates seamlessly with existing security tools to enhance investigations.
- •AI capabilities allow analysts to make faster, high-confidence decisions.
On April 29, 2026, Command Zero announced the release of a new set of API endpoints and a Model Context Protocol (MCP) server for its Autonomous & AI-Assisted SOC platform. This release aims to streamline security operations by integrating investigation capabilities directly into existing automated workflows. The platform allows security teams to connect with various tools and orchestration pipelines, enhancing the efficiency of incident response. The API is organized into seven functional areas, enabling programmatic investigations and remediation. Analysts can utilize AI-driven commands to manage investigations and cases, significantly reducing response times. This initiative addresses the complexity of managing multiple security tools and aims to elevate the role of human analysts in decision-making. The release is expected to improve operational efficiency and enable faster, more confident decision-making in security operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…