Security Detections MCP
Security Detections MCP
An MCP (Model Context Protocol) server that lets LLMs query a unified database of Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike CQL security detection rules.
New here? Start with the Setup Guide -- covers macOS, Windows (WSL & native), and Linux step by step.
Want it hosted? Skip the install entirely: Hosted MCP Setup Guide
Two Ways to Run It
Local (full power) — the npm package you're looking at. Runs on your machine, indexes your own detection repos, exposes all 81 tools. You need Node.js and ~10 minutes.
Hosted (zero setup) — a Streamable HTTP server at detect.michaelhaag.org/api/mcp/mcp. Sign up, generate a token, paste one URL into your MCP client. ~25 read-only tools, always in sync with the latest content, 200 calls/day free. Read on for quick-install buttons.
Install — Local
Claude Code (CLI one-liner):
claude mcp add security-detections -- npx -y security-detections-mcpClaude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"security-detections": {
"command": "npx",
"args": ["-y", "security-detections-mcp"]
}
}
}OpenAI Codex (CLI):
codex mcp add security-detections -- npx -y security-detections-mcpAfter install, configure env vars (
SIGMA_PATHS,SPLUNK_PATHS, etc.) to point at your detection repos. See the Setup Guide for full details.
Install — Hosted (no setup, token required)
Create a token at detect.michaelhaag.org/account/tokens. Free tier: 200 calls/day, all read-only tools.
Click the button for your client — replace
sdmcp_YOUR_TOKEN_HEREin the resulting config with the token you just generated.
Claude Code (CLI one-liner):
claude mcp add --transport http security-detections https://detect.michaelhaag.org/api/mcp/mcp --header "Authorization: Bearer sdmcp_YOUR_TOKEN_HERE"Claude Desktop (via mcp-remote — Desktop doesn't speak remote HTTP natively yet):
{
"mcpServers": {
"security-detections": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://detect.michaelhaag.org/api/mcp/mcp",
"--header",
"Authorization: Bearer sdmcp_YOUR_TOKEN_HERE"
]
}
}
}OpenAI Codex (CLI):
export SDMCP_TOKEN="sdmcp_YOUR_TOKEN_HERE" && codex mcp add security-detections --url https://detect.michaelhaag.org/api/mcp/mcp --bearer-token-env-var SDMCP_TOKENSee the Hosted MCP Setup Guide for the full table of clients, the complete tool inventory, and troubleshooting tips.
AI Model Routing (Web App)
The web chat supports Free, Pro/Admin, and BYOK (Bring Your Own Key) routing. You can also see the active model at the top of the chat UI.
Free Tier (default)
Default model:
nvidia/nemotron-3-super-120b-a12b:freeAutomatic fallback order if the first model is busy:
nvidia/nemotron-3-super-120b-a12b:freenousresearch/hermes-3-llama-3.1-405b:freemeta-llama/llama-3.3-70b-instruct:freeopenai/gpt-oss-120b:free
Pro/Admin (no BYOK key set)
Uses app-managed OpenRouter routing with your Preferred Model setting in /account:
Preferred Model | Routed model |
| Free model pool (default: |
|
|
|
|
|
|
|
|
BYOK behavior (takes precedence over tier routing)
If you set your own API key(s), routing priority is:
Claude key (
sk-ant-...) ->claude-sonnet-4-6-20250514via AnthropicOpenAI key (
sk-...) ->gpt-5.4via OpenAIOpenRouter key (
sk-or-...) -> uses the same Preferred Model mapping table above
If multiple keys are present, the first match in that order is used.
Features
8,200+ detections across 6 formats — Sigma, Splunk ESCU, Elastic, KQL, Sublime, CrowdStrike CQL
MITRE ATT&CK STIX — 172 threat actors, 784 software, 4,362 actor-technique relationships
Procedure-level coverage — auto-extracted behavioral clusters from every detection rule
ATT&CK Navigator layers — export coverage/gap JSON, filterable by source/tactic/severity/actor
Autonomous pipeline — CTI ingestion → gap analysis → detection generation → Atomic testing → DRAFT PR (see Autonomous docs)
81 local tools / ~25 hosted tools — unified search, MITRE mapping, coverage analysis, knowledge graph, pattern learning, sprint planning
11 MCP Prompts — ransomware assessment, APT emulation, purple team, executive briefing, and more
MCP Resources & Completions — readable context, autocomplete for technique IDs, CVEs, process names
Quick Start
npx -y security-detections-mcpOr clone and build: git clone https://github.com/MHaggis/Security-Detections-MCP.git && cd Security-Detections-MCP && npm install && npm run build
Configure env vars to point at your detection repos:
Variable | Description |
| Sigma rule directories |
| Splunk ESCU detection directories |
| Elastic detection rule directories |
| KQL hunting query directories |
| Sublime Security rule directories |
| CQL Hub (CrowdStrike) query directories |
| Jamf Protect custom analytic detection directories (macOS) |
| Splunk analytic story directories (optional) |
| Path to |
See the Setup Guide for full per-client config examples (Cursor, VS Code, Claude Desktop, WSL).
Getting Detection Content
Download all sources with sparse checkout (rules only, not full repos):
mkdir -p detections && cd detections
git clone --depth 1 --filter=blob:none --sparse https://github.com/SigmaHQ/sigma.git && cd sigma && git sparse-checkout set rules rules-threat-hunting && cd ..
git clone --depth 1 --filter=blob:none --sparse https://github.com/splunk/security_content.git && cd security_content && git sparse-checkout set detections stories && cd ..
git clone --depth 1 --filter=blob:none --sparse https://github.com/elastic/detection-rules.git && cd detection-rules && git sparse-checkout set rules && cd ..
git clone --depth 1 https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules.git kql-bertjanp
git clone --depth 1 https://github.com/jkerai1/KQL-Queries.git kql-jkerai1
git clone --depth 1 --filter=blob:none --sparse https://github.com/sublime-security/sublime-rules.git && cd sublime-rules && git sparse-checkout set detection-rules && cd ..
git clone --depth 1 https://github.com/ByteRay-Labs/Query-Hub.git cql-hubMCP Tools
Core Detection Tools
Tool | Description |
| Full-text search across all detection fields |
| Get a single detection by ID |
| Paginated list of all detections |
| Filter by source ( |
| Index statistics |
| Force re-index from configured paths |
MITRE ATT&CK & Filtering
Tool | Description |
| Filter by technique ID (e.g., T1059.001) |
| Filter by tactic (execution, persistence, etc.) |
| Find detections for a CVE |
| Find detections referencing a process |
| Filter by severity level |
| Filter by data source |
Coverage & Analysis (Token-Optimized)
Tool | Description |
| Coverage stats by tactic, top techniques, weak spots (~2KB) |
| Find gaps for ransomware, apt, persistence, etc. (~500B) |
| Detection ideas for a technique (~2KB) |
| Tactic percentages (~200B) |
| Coverage against a specific threat actor |
| Compare coverage across multiple actors |
| Behavioral procedure breakdown |
| Export ATT&CK Navigator JSON layers |
Engineering, Knowledge Graph & More
81 tools total including pattern learning, template generation, knowledge graph, dynamic tables, and autonomous analysis. See the Tools Reference for the complete list.
MCP Prompts
11 pre-built expert workflows. Just ask by name:
Prompt | Description |
| Full kill-chain analysis with risk scoring |
| Coverage against specific threat actors (APT29, Lazarus, etc.) |
| Complete test plans with procedures and expected detections |
| Triage guidance, hunting queries, escalation criteria |
| Prioritized backlog with user stories |
| C-level report with business risk language |
| Rapid assessment for emerging CVEs |
| Telemetry requirements analysis |
| Deep-dive quality analysis for a technique |
| Align priorities with current threats |
| Compare coverage against actors or baseline |
You: "Run apt-threat-emulation for APT29"
→ Technique-by-technique coverage, gaps, and purple team test planUsing with MITRE ATT&CK MCP
Pairs with mitre-attack-mcp for complete threat coverage analysis. Install both:
{
"mcpServers": {
"security-detections": {
"command": "npx",
"args": ["-y", "security-detections-mcp"],
"env": { "SIGMA_PATHS": "/path/to/sigma/rules" }
},
"mitre-attack": {
"command": "npx",
"args": ["-y", "mitre-attack-mcp"],
"env": { "ATTACK_DOMAIN": "enterprise-attack" }
}
}
}Stats
Source | Count |
Sigma Rules | ~3,200+ |
Splunk ESCU | ~2,000+ |
Elastic Rules | ~1,500+ |
KQL Queries | ~420+ |
Sublime Rules | ~900+ |
CrowdStrike CQL | ~139+ |
Total | ~8,200+ |
Development
npm install && npm run build && npm testDocumentation
Setup Guide — Full install walkthrough for all platforms
Hosted MCP Guide — Hosted setup, token management, tool inventory
Autonomous Platform — CTI-to-detection pipeline
E2E Testing Guide — Per-SIEM setup (Splunk, Sentinel, Elastic, Sigma)
Architecture — System design decisions
Knowledge Graph — Tribal knowledge and analytical memory
Engineering Intelligence — Pattern learning and templates
Tools Reference — Complete reference for all 81 tools
License
Apache 2.0