Orchestrating the Agentic SOC: A Practical Guide to Model Context Protocol

Sep 03, 2026
5 minutes

Security operations teams have long been burdened by the "integration tax." Automating workflows across SOC tools required customizing prebuilt integrations or building custom scripts from scratch, only to maintain them through every version upgrade.

The Model Context Protocol (MCP) acts as an open "HTTP of AI," providing a standardized orchestration layer that seamlessly connects Large Language Models directly to the SOC tools used by developers and security teams. With MCP, an agent can select and orchestrate the right tools on the fly, executing complex operational plans in response to analyst prompts or system events.

We previously introduced the Cortex MCP server and its native integration with leading LLMs. Today, we are taking it a step further: showing you how to connect Cortex XSIAM, AgentiX, XDR, and Cloud to your enterprise SOC tools to automate workflows and supercharge your agents.

Connecting External MCP Servers via Cortex Marketplace

The Cortex Agentic Assistant uses MCP integrations to connect AI agents directly to third-party tools across your enterprise. This allows agents to retrieve external context and execute tasks across your stack, such as opening a Jira ticket or verifying security guardrails in a GitHub workflow.

Setting up a connection to an external MCP server is straightforward.

Deployment: Install the corresponding content pack from the Cortex Marketplace and set up your integration instance. You can leverage out-of-the-box content packs for Atlassian, Cloudflare, GitHub, and ServiceNow, or use our generic MCP pack to connect any custom server.

To get started, install the Atlassian MCP Content Pack by navigating to Settings → Marketplace and filtering for MCP under Types.

Each integration supports multiple instances, allowing you to tailor access permissions to specific operational needs. For example, you can configure one Atlassian instance with read-only tools for passive context gathering, and a separate instance with read and write capabilities for active ticket management.

 A dark-themed screenshot of the Cortex Agentix Marketplace displaying details for the "Atlassian Cloud MCP" integration pack. The main view presents an overview of automating Atlassian operations via the Model Context Protocol (MCP) for Cortex Agentic AI, along with a list of available tool actions. A right-hand sidebar displays publisher details from Cortex, an "Update available" status tag (installed version 1.0.2 to 1.0.3), certification badges, and compatibility info.
Fig 1: The Atlassian MCP Content Pack

Connection & Authentication: The Cortex Agentic Assistant communicates with URL-accessible MCP servers over streamable HTTP, supporting both OAuth and authless configurations. Connecting to a server like Atlassian is as simple as entering your authentication credentials and testing the link, with guided step-by-step instructions to walk you through the setup.

Configuration modal window for "Atlassian Cloud MCP" displaying form fields for instance name and authorization code alongside a four-step help guide for obtaining the authorization code.
Fig 2: Connecting to the Atlassian MCP Server

Automatic Discovery: Once configured, the integration automatically discovers available tools on the MCP server and converts them into ready-to-use agentic actions.

Tool discovery and security governance follow a few core rules:

Automated Syncing: The integration checks hourly for new or modified tools, and runs an instant sync whenever you save an instance configuration.

Action Registration: Capabilities are registered as system-level actions under the type MCP Tool. Action names combine the server, tool, and instance names, allowing you to easily manage multiple instances of the same server.

Access Controls: Generated system actions can be enabled or disabled at any time. For safety, all imported MCP actions are marked as sensitive by default, requiring human-in-the-loop approval before execution. If an action is safe for automated execution, you can easily toggle off the sensitive flag.

Dark UI dashboard screen displaying the "Agentic Assistant Hub" under the "Actions" tab, showing search results for "atlassian" with a grid of action cards for various Atlassian Cloud MCP tools published by Cortex.
Fig 3: Atlassian MCP tools are automatically added to the Actions library in the Agent Hub

Adding MCP Tools and Managing Permissions

Once registered as actions, these MCP tools can be attached to custom agents inside the Agentic Assistant Hub. By default, any user with access to a custom agent can run its assigned tools. To demonstrate this in action, we created a custom agent named MCP Tester to evaluate our Atlassian integration, prompting it with a simple request: "List all Jira issues created in the last 30 days."

Dark-themed dashboard for "MCP Tester" showing an action list on the left and an active chat sidebar on the right where an AI agent prompts the user for approval to execute sensitive Atlassian Cloud MCP actions.
Fig 4: Prompting the MCP Tester agent to query recent Jira issues.
Dark-themed "MCP Tester" dashboard showing a list of Atlassian Cloud MCP actions on the left and a completed AI agent response on the right, presenting a formatted table of Jira issues created within the last 30 days.
Fig 5: Results of the query

Custom MCP Integrations

To create a custom MCP integration, use the generic MCP content pack, initiate the connection with your MCP server of choice, and the tools associated with it will be automatically downloaded into the Actions library for use by your agent. You would then create a custom agent with these actions for engaging with the MCP server.

Configuration modal for "Generic MCP" showing server URL and authentication form fields alongside a help guide detailing parameter requirements.
Fig 6: The Generic MCP Content Pack allows you to easily integrate custom MCP servers

Orchestration without the Friction

Security operations are moving past the friction of custom API scripts and integrations. By using MCP to orchestrate tools across their security stack, security teams replace brittle code with a standardized AI connection layer. This eliminates integration maintenance, letting human expertise and AI orchestration operate in tandem to accelerate threat response.

Experience the Power of the Agentic SOC

Ready to eliminate the integration tax and unlock Agentic AI in your SOC? Experience how Cortex XSIAM and our other Cortex products use native MCP integrations to connect your security stack, automate complex workflows, and accelerate response times. 

Schedule a demo.

 


Subscribe to Security Operations Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.