Put intelligence into an approved investigation workflow
Where the integration is configured, approved tools can query relevant FIRCY context to support analyst-led investigation. Examples include source IP, network and targeted-activity context. What’s available depends on your service and deployment configuration.
An analyst might use an approved tool to examine context around a finding, compare relevant activity or prepare follow-up investigation questions. The underlying evidence remains the basis for a decision; a generated explanation is not a replacement for it.
Explore the threat-intelligence workflow.
Two different uses of MCP
| Use | Purpose | What not to confuse it with |
|---|---|---|
| FIRCY Sense production MCP integration | Let approved tools access configured FIRCY intelligence for investigation | It is not a decoy, and legitimate use is not evidence of rogue activity. |
| Decoy MCP surface | Observe selected interactions with a controlled detection surface | It is not the production route for customers to retrieve intelligence. |
For protocol background, see the Model Context Protocol architecture overview. For the detection use case, read detecting rogue AI agents with cyber deception.
Agree the operating boundaries before enabling access
An integration review should establish which tools and users are approved, how access is authenticated, what information is available, and whether any actions beyond retrieval are supported. It should also establish the relevant logging, revocation and review process.
Include the AI provider’s own data handling in that review. Once information reaches a separate tool, that provider’s terms apply.
The answers depend on your deployment, so settle them before access is switched on.
Treat retrieved event content as evidence, not instructions
Security events can contain text supplied by an external actor. An approved AI workflow should treat that text as untrusted data, verify explanations against source evidence, and avoid allowing event content to redefine the analyst’s task. OWASP’s prompt-injection guidance provides background on this risk.
Discuss a supported integration
Tell us the AI tool, the investigation workflow and the information your analysts need. We’ll confirm what’s supported for your tools and environment before anything is enabled.