Command Zero today released a broad set of API endpoints and a Model Context Protocol (MCP) server for its Autonomous & AI-Assisted SOC platform.

SOCs consist of dozens of separate tools and need seamless connectivity to overcome complexity. With this release, teams can wire the Command Zero platform directly into their SOAR playbooks, orchestration pipelines, and internal tooling. This represents a fundamental architectural shift: investigation is no longer just a destination analysts must visit, but a callable capability embedded natively within existing automated workflows.
This configuration ensures AI acts as an elevating force for human analysts, surfacing vital context and institutional methodology so practitioners can make faster, higher-confidence decisions without manually jumping between consoles.
The API is organized across seven core functional areas to drive programmatic investigations and remediation:
The release also includes an MCP server which serves as a wrapper around the APIs that lets Claude and other MCP-compatible agents interact with Command Zero directly.
Analysts can run health checks, list investigations, triage open Cases, and build custom dashboards directly from an AI chat interface. Through 25 tools and seven specific slash commands (like /soc-dashboard, /investigate, and /remediate), Claude orchestrates the API calls while the analyst remains firmly in the driver's seat.
Agentic capabilities elevate analysts. The automation structures the investigation and surfaces the critical context, allowing the analyst to apply expert judgment and make high-stakes decisions in minutes instead of hours.
What You Can Build Today
Security teams and technical alliance partners can build integrations in minutes that fundamentally alter how their SOC operates.
A Specific Case in the SOC: Identity Compromise
To understand the architectural shift, consider a high-fidelity alert: an identity provider flags an impossible travel event for a privileged account.
This initial release covers the core surface customers need to start building. Additional API endpoints will follow, shaped directly by feedback from anchor customers and partners. Be sure to check out Eric Hulse video overview showing a use of Claude and our new API create augmented Investigative Intelligence.
Command Zero today released a broad set of API endpoints and a Model Context Protocol (MCP) server for its Autonomous & AI-Assisted SOC platform.
Run Better Investigations.
At Every Tier.