generated: '2026-07-21' method: derived status: candidate source: https://github.com/demisto/content/blob/master/Packs/Uptycs/Integrations/Uptycs/Uptycs.py description: 'No official Uptycs MCP server was found (docs, npm, the public MCP registries). This is a CANDIDATE tool list derived from the real Uptycs platform API surface as exercised by the official Uptycs pack for Cortex XSOAR (provider: Uptycs), which calls https://{stack}.uptycs.io/public/api/customers/{customerId}/... with a per-user API key/secret signed as an HS256 JWT. Tool names mirror the pack''s command surface; nothing here is a shipped server.' server: name: uptycs transport: http url: null auth: type: jwt-bearer detail: HS256 JWT (iss = API key, signed with API secret) as Authorization Bearer tools: - name: get_alerts description: Retrieve alerts generated by the Uptycs platform source_endpoint: /alerts - name: set_alert_status description: Update the status of an alert source_endpoint: /alerts - name: get_alert_rules description: List configured alert rules source_endpoint: /alertRules - name: get_event_rules description: List configured event rules source_endpoint: /eventRules - name: get_events description: Retrieve events collected from managed assets source_endpoint: /events - name: get_assets description: List assets (endpoints, cloud workloads) enrolled in the stack source_endpoint: /assets/query - name: get_asset_groups description: List asset object groups source_endpoint: /objectGroups - name: get_asset_tags description: List tags applied to assets source_endpoint: /assets/tags - name: set_asset_tag description: Apply a tag to an asset source_endpoint: /tags - name: delete_tag description: Delete a tag source_endpoint: /tags - name: run_query description: Run an ad-hoc SQL (osquery) query against live or global tables source_endpoint: /query - name: run_saved_query description: Execute a saved query source_endpoint: /queries - name: get_saved_queries description: List saved queries source_endpoint: /queries - name: post_saved_query description: Create a saved query source_endpoint: /queries - name: get_processes description: Query process activity on an asset (processes, child processes, open files, open sockets) source_endpoint: /query - name: get_threat_indicators description: List threat indicators known to the stack source_endpoint: /threatIndicators - name: get_threat_sources description: List threat intelligence sources source_endpoint: /threatSources - name: post_threat_source description: Upload a custom threat intelligence source source_endpoint: /threatSources - name: get_threat_vendors description: List threat intelligence vendors source_endpoint: /threatVendors - name: get_carves description: List file carves collected from endpoints source_endpoint: /carves - name: get_carve_download_link description: Get a download link for a carved file source_endpoint: /carves - name: get_lookuptables description: List lookup tables source_endpoint: /lookupTables - name: create_lookuptable description: Create a lookup table source_endpoint: /lookupTables - name: post_lookuptable_data description: Upload CSV data into a lookup table source_endpoint: /lookupTables/{tableId}/csvdata - name: delete_lookuptable description: Delete a lookup table source_endpoint: /lookupTables - name: get_users description: List users on the Uptycs stack source_endpoint: /users - name: get_user_information description: Get details for a single user source_endpoint: /users/{userId} deployment: mode: none verified: derived tools: 27 checked: '2026-08-12' source: catalog MCP census