Abnormal Security
Rank #7,209io.github.WYRE-AI/abnormal-mcp
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
Abnormal Security is a Model Context Protocol (MCP) server published by wyre-technology. It ranks #7,209 of 115,460 servers tracked on MCP Toplist. Abnormal Security is listed across 2 registries — Official MCP and PulseMCP, with 8 tracked versions. It was first listed on Mar 2, 2026 and most recently updated on Aug 26, 2026.
Ranks ahead of 108,251 of 115,460 servers on MCP Toplist.
Use Abnormal Security
Requires user-supplied configuration before first use — typically an API key, token or connection string set via environment variables.
claude mcp add abnormal-mcp -e "ABNORMAL_API_TOKEN=<your ABNORMAL_API_TOKEN>" -e "MCP_TRANSPORT=<your MCP_TRANSPORT>" -e "AUTH_MODE=<your AUTH_MODE>" -e "LOG_LEVEL=<your LOG_LEVEL>" -- docker run -i --rm ghcr.io/wyre-ai/abnormal-mcp:v1.2.6Replace each placeholder with your own value before saving.
[mcp_servers.abnormal-mcp]
command = "docker"
args = ["run", "-i", "--rm", "ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"]
[mcp_servers.abnormal-mcp.env]
ABNORMAL_API_TOKEN = "<your ABNORMAL_API_TOKEN>"
MCP_TRANSPORT = "<your MCP_TRANSPORT>"
AUTH_MODE = "<your AUTH_MODE>"
LOG_LEVEL = "<your LOG_LEVEL>"Add to ~/.codex/config.toml. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"abnormal-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"
],
"env": {
"ABNORMAL_API_TOKEN": "<your ABNORMAL_API_TOKEN>",
"MCP_TRANSPORT": "<your MCP_TRANSPORT>",
"AUTH_MODE": "<your AUTH_MODE>",
"LOG_LEVEL": "<your LOG_LEVEL>"
}
}
}
}Add to claude_desktop_config.json (Settings → Developer → Edit Config). Replace each placeholder with your own value before saving.
{
"mcpServers": {
"abnormal-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"
],
"env": {
"ABNORMAL_API_TOKEN": "<your ABNORMAL_API_TOKEN>",
"MCP_TRANSPORT": "<your MCP_TRANSPORT>",
"AUTH_MODE": "<your AUTH_MODE>",
"LOG_LEVEL": "<your LOG_LEVEL>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project). Replace each placeholder with your own value before saving.
{
"servers": {
"abnormal-mcp": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"
],
"env": {
"ABNORMAL_API_TOKEN": "<your ABNORMAL_API_TOKEN>",
"MCP_TRANSPORT": "<your MCP_TRANSPORT>",
"AUTH_MODE": "<your AUTH_MODE>",
"LOG_LEVEL": "<your LOG_LEVEL>"
}
}
}
}Save as .vscode/mcp.json in your workspace. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"abnormal-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"
],
"env": {
"ABNORMAL_API_TOKEN": "<your ABNORMAL_API_TOKEN>",
"MCP_TRANSPORT": "<your MCP_TRANSPORT>",
"AUTH_MODE": "<your AUTH_MODE>",
"LOG_LEVEL": "<your LOG_LEVEL>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"abnormal-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/abnormal-mcp:v1.2.6"
],
"env": {
"ABNORMAL_API_TOKEN": "<your ABNORMAL_API_TOKEN>",
"MCP_TRANSPORT": "<your MCP_TRANSPORT>",
"AUTH_MODE": "<your AUTH_MODE>",
"LOG_LEVEL": "<your LOG_LEVEL>"
}
}
}
}Replace each placeholder with your own value before saving.
Show your rank
Maintain this server? Add the live rank badge to your README — it updates automatically as the leaderboard changes.
[](https://mcptoplist.com/server/io.github.WYRE-AI%2Fabnormal-mcp)<a href="https://mcptoplist.com/server/io.github.WYRE-AI%2Fabnormal-mcp"><img src="https://mcptoplist.com/badge/io.github.WYRE-AI%2Fabnormal-mcp.svg" alt="MCP Toplist: Top 10% of 115,460" /></a>Variants: append ?metric=score or ?metric=stars to the image URL.
Listed on 2 registries (1 delisted)
wyre-technology
Other servers by wyre-technology
- Autotask#795 · 22 vers
- NinjaOne#1,590 · 20 vers
- Huntress#1,779 · 14 vers
- IT Glue#2,060 · 15 vers
- ConnectWise Manage#2,254 · 9 vers
- IQMS / DELMIA Apriso#2,611 · 6 vers
- CIPP#3,200 · 9 vers
- HaloPSA#3,304 · 20 vers
- Syncro#3,957 · 13 vers
- Hudu#4,160 · 10 vers
- SuperOps#4,501 · 9 vers
- Datto RMM#4,702 · 9 vers
Available versions (8)
| Version | Published |
|---|---|
| 1.2.6 | Aug 26, 2026 |
| 1.2.4 | Aug 20, 2026 |
| 1.2.3 | Aug 20, 2026 |
| 1.2.2 | Aug 13, 2026 |
| 1.2.1 | Aug 7, 2026 |
| 1.2.0 | Jul 17, 2026 |
| 1.0.0 | May 21, 2026 |
| 1.1.3 | May 6, 2026 |
Frequently asked questions
- Who maintains Abnormal Security?
- Abnormal Security is maintained by wyre-technology, which publishes 59 MCP servers (474 total versions) tracked on MCP Toplist.
- Is Abnormal Security listed on the Official MCP Registry?
- Yes — Abnormal Security is listed on the Official MCP Registry, alongside PulseMCP.
- How many versions does Abnormal Security have?
- MCP Toplist tracks 8 versions of Abnormal Security, most recently published on Aug 26, 2026.
- Where can I find the source code for Abnormal Security?
- The source code for Abnormal Security is hosted at github.com/wyre-technology/abnormal-mcp.