Skip to main content
MCP Servers / Tenable OT MCP Server (Enterprise Manager Edition)

Tenable OT MCP Server (Enterprise Manager Edition)

Contributed

MCP server exposing Tenable OT Security data to AI clients; this EM fork adds relay routing and site-based queries.

Authordpstorey
Transporthttp
Runtimepython
LicenseApache-2.0
AddedAug 31, 2026

Compatible Clients

Claude DesktopClaude CodeCursorWindsurfChatGPTVS Code Copilot

Integrations

Tenable

Tools (121)

  1. query_assets

    Query OT assets

  2. get_asset

    Get one OT asset

  3. get_asset_vulnerabilities

    Get vulnerabilities for one asset

  4. list_custom_fields

    List configured custom fields

  5. query_attack_pathways

    Query attack-pathway data (relational, not computed)

  6. query_vulnerability_clusters

    Query vulnerability clusters (relational join, not computed)

  7. query_temporal_patterns

    Query temporal patterns (event sequence, not motif analysis)

  8. get_asset_intelligence

    Get asset intelligence bundle (joined data, not narrative)

  9. list_paired_icps

    List paired ICP appliances via EM

  10. query_events

    Query OT events

  11. get_event

    Get one OT event

  12. list_asset_groups

    List asset groups (active)

  13. list_archived_asset_groups

    List archived asset groups

  14. get_asset_group

    Get an asset group by id

  15. list_email_groups

    List email groups

  16. get_email_group

    Get an email group by id

  17. find_email_groups_using_smtp_server

    Find email groups that route through a given SMTP server

  18. list_schedule_groups

    List schedule groups

  19. list_archived_schedule_groups

    List archived schedule groups

  20. get_schedule_group

    Get a schedule group by id

  21. list_tag_groups

    List tag groups

  22. get_tag_group

    Get a tag group by id

  23. list_eligible_tags

    Discover tags eligible for a tag group

  24. list_rule_groups

    List rule groups

  25. list_archived_rule_groups

    List archived rule groups

  26. get_rule_group

    Get a rule group by id

  27. list_port_groups

    List port groups

  28. list_archived_port_groups

    List archived port groups

  29. get_port_group

    Get a port group by id

  30. list_protocol_groups

    List protocol groups

  31. list_archived_protocol_groups

    List archived protocol groups

  32. get_protocol_group

    Get a protocol group by id

  33. list_user_groups

    List user groups (ICP-level)

  34. list_archived_user_groups

    List archived user groups (ICP-level)

  35. get_user_group

    Get a user group by id (ICP-level)

  36. list_em_user_groups

    List user groups (Enterprise Manager level)

  37. list_em_archived_user_groups

    List archived user groups (Enterprise Manager level)

  38. get_em_user_group

    Get a user group by id (Enterprise Manager level)

  39. create_asset_group

    Create an asset group (tag-like grouping)

  40. update_asset_group

    Update an asset group's metadata or membership

  41. archive_asset_group

    Archive (soft-delete) an asset group

  42. bulk_set_asset_group_display_tag

    Bulk toggle display-tag flag on asset groups

  43. create_email_group

    Create an email group (alert recipient list)

  44. update_email_group

    Update an email group (rename, change SMTP server, or replace recipients)

  45. archive_email_group

    Archive (delete) an email group

  46. create_schedule_group

    Create a schedule group (policy window)

  47. update_schedule_group

    Update a schedule group

  48. archive_schedule_group

    Archive (delete) a schedule group

  49. create_tag_group

    Create a tag group (PLC controller-tag rollup)

  50. update_tag_group

    Update a tag group

  51. archive_tag_group

    Archive (delete) a tag group

  52. create_rule_group

    Create a rule group (IDS rule bundle)

  53. update_rule_group

    Update a rule group

  54. archive_rule_group

    Archive (delete) a rule group

  55. create_port_group

    Create a port group (port-range bundle for PortPolicy)

  56. update_port_group

    Update a port group

  57. archive_port_group

    Archive (delete) a port group

  58. create_protocol_group

    Create a protocol group (protocol+port-range bundle)

  59. update_protocol_group

    Update a protocol group

  60. archive_protocol_group

    Archive (delete) a protocol group

  61. create_user_group

    Create a user group (ICP-level)

  62. edit_user_group

    Edit a user group (ICP-level)

  63. archive_user_group

    Archive (delete) a user group (ICP-level)

  64. set_user_groups

    Reassign a user's group memberships (ICP-level)

  65. create_em_user_group

    Create a user group (Enterprise Manager level)

  66. edit_em_user_group

    Edit a user group (Enterprise Manager level)

  67. archive_em_user_group

    Archive (delete) a user group (Enterprise Manager level)

  68. set_em_user_groups

    Reassign an EM user's group memberships

  69. list_detection_policies

    List detection policies

  70. query_policy_findings

    Query policy findings

  71. list_policy_exclusions

    List policy exclusions

  72. list_active_scans

    List active scans

  73. get_active_scan

    Get one active scan

  74. get_active_scan_executions

    Get past executions of an active scan

  75. define_active_scan

    Define an active scan (NEW — does not run it)

  76. edit_active_scan

    Edit an active-scan definition

  77. enable_active_scan

    Enable an active scan

  78. disable_active_scan

    Disable an active scan

  79. delete_active_scan

    Delete an active-scan definition

  80. define_port_scan

    Define a port-scan job (NEW — does not run it)

  81. edit_port_scan

    Edit a port-scan job

  82. define_snmp_scan

    Define an SNMP scan job (NEW — does not run it)

  83. edit_snmp_scan

    Edit an SNMP scan job

  84. define_controller_discovery_scan

    Define a controller-discovery scan (NEW — does not run it)

  85. edit_controller_discovery_scan

    Edit a controller-discovery scan job

  86. define_asset_discovery_scan

    Define an asset-discovery scan (NEW — does not run it)

  87. edit_asset_discovery_scan

    Edit an asset-discovery scan job

  88. define_inactive_probing_scan

    Define an inactive-probing scan (NEW — does not run it)

  89. edit_inactive_probing_scan

    Edit an inactive-probing scan job

  90. edit_subnets_discovery_scan

    Edit the subnets-discovery scan

  91. list_sensors

    List sensors

  92. tenable_ot_status

    Check Tenable OT connection

  93. summarize_environment

    Summarize the OT environment

  94. list_segments_and_zones

    List network segments and zones

  95. get_communication_paths

    Get communication paths for an asset

  96. query_vulnerability_findings

    Query vulnerability findings

  97. query_vulnerabilities

    Query OT vulnerabilities

  98. get_vulnerability

    Get one vulnerability

  99. hide_asset

    Hide an OT asset (filter from default views)

  100. restore_asset

    Restore a hidden OT asset

  101. bulk_hide_assets

    Bulk-hide assets matching a filter

  102. bulk_restore_assets

    Bulk-restore assets matching a filter

  103. remove_assets_by_address

    Remove asset entries by IP address

  104. recalculate_asset_risk

    Recalculate one asset's risk score

  105. recalculate_all_risk

    Recalculate risk across the deployment

  106. update_asset

    Edit an OT asset's properties

  107. bulk_edit_assets

    Bulk-edit OT assets matching a filter

  108. reset_asset_metadata

    Reset one asset's operator-set metadata

  109. create_custom_field

    Create a custom-field slot

  110. rename_custom_field

    Rename a custom-field slot

  111. delete_custom_field

    Delete a custom-field slot

  112. enable_detection_policy

    Enable a detection policy

  113. disable_detection_policy

    Disable a detection policy

  114. archive_detection_policy

    Archive a detection policy

  115. enable_detection_policies

    Bulk enable detection policies

  116. disable_detection_policies

    Bulk disable detection policies

  117. archive_detection_policies

    Bulk archive detection policies

  118. create_activity_exclusion

    Create activity exclusion

  119. create_conversation_exclusion

    Create conversation exclusion

  120. delete_exclusion

    Delete policy exclusion

  121. resolve_findings

    Resolve detection findings

Tags

tenableot-securityicsscadavulnerability-management

An open-source Model Context Protocol server that exposes Tenable OT Security data to any MCP-compatible AI client. This listing is for the Enterprise Manager (EM) edition: a fork maintained by Dominic Storey (Tenable) that adds EM-specific routing and query capabilities on top of the original open-source project created by John Walley of OneClearPath, Incorporated.

Note: the Exchange also lists a separate tenable-ot-security-mcp-server entry based on the same underlying open-source project under a different account; this listing covers the Enterprise Manager-specific fork maintained by Dominic Storey (Tenable), distinct from that one.

What it does

Translates MCP tool calls into live queries and actions against a Tenable OT Security deployment — either a direct Industrial Control Platform (ICP) or, in this fork, an Enterprise Manager relay fronting multiple sites. It exposes 121 tools spanning asset inventory and edits, vulnerability and policy findings, detection-policy management and exclusions, sensor status, scan definitions, network topology, and attack-pathway correlation. Every read tool supports paginated, filterable queries; a smaller set of write tools covers tuning actions like hiding/restoring assets, creating exclusions, and enabling or disabling detection policies.

Enterprise Manager–specific enhancements in this fork

  • Site routing — read/write tools accept site_uuid / site_name to route calls through the EM relay to the correct paired ICP
  • EM root querieslist_paired_icps queries the EM directly, bypassing relay routing
  • Machine ID caching — automatic site name → machine ID resolution, cached for subsequent calls
  • Subnet queries — assets can be filtered by CIDR subnet
  • Shortened tool descriptions — trimmed for faster tool-list loading in MCP clients with limited context budgets

How it works

A stateless container built on FastMCP’s Streamable HTTP transport. A setup wizard issues a static bearer token that gates the /mcp endpoint (no OAuth flow — the server advertises RFC 9728 protected-resource metadata purely so clients that expect it can discover the bearer-token requirement). The server wraps the Tenable OT Security REST API, translating each MCP tool call into one or more authenticated HTTP requests, then returns results in a client-friendly shape with cursor-based pagination for large result sets.