Provides structured access to OCSF-normalized security data in Amazon Security Lake for querying via AWS Athena.
The Amazon Security Lake tool acts as a Model Context Protocol (MCP) server, enabling powerful queries against your AWS Security Lake data using Athena. It transforms raw security logs into an OCSF-normalized format, making it easy for AI assistants and applications to search for critical information like IP addresses, GuardDuty findings, and to discover available data sources. This seamless integration with AWS services provides a secure and efficient way to analyze your cybersecurity posture, ensuring input validation, query sanitization, and least-privilege access.