Skip to main content
Glama
MadameFabulous

Chainsaw MCP Server

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_MEMORY_MAXNoMemory cap applied to the systemd unit when deploying the streamable HTTP transport (default 4 GiB).4G
TYPESAFE_API_KEYNoInjected TypeSafe API key used by chainsaw_jev_triage when Jev is enabled (alternative to CHAINSAW_JEV_BWS_SECRET_ID).
MCP_ALLOWED_HOSTSNoComma-separated extra Host headers accepted by the streamable HTTP transport (host or host:*). The bind host, localhost and 127.0.0.1 are always accepted.
CHAINSAW_OUTPUT_DIRNoDirectory where hunts, searches and dumps write JSONL result files and minted result handles (res_<hex16>). Also holds the derived content-addressed mapping under .mappings/.
MCP_ALLOWED_ORIGINSNoComma-separated extra browser origins accepted by the streamable HTTP transport.
CHAINSAW_JEV_ENABLEDNoSet to true to enable the optional chainsaw_jev_triage tool, which sends selected result rows to the external TypeSafe Jev API.false
CHAINSAW_EVIDENCE_ROOTSNoComma-separated evidence roots. Evidence paths passed to tools must resolve inside these roots; nothing under an evidence root is ever written../evidence
CHAINSAW_JEV_BWS_SECRET_IDNoBitwarden Secrets identifier used to resolve the TypeSafe API key for chainsaw_jev_triage when Jev is enabled.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
chainsaw_analyse_evtxA

Summarise EVTX channel, provider and event-ID coverage, including missing metadata.

Runs native analysis and a streamed dump pass. The inline per_file list is a bounded preview; page handle for full files, coverage_handle for identity counts, and diagnostics.handle for all runner messages. Missing Channel in ETW is not evidence of corruption, and successful exit does not establish complete parsing.

chainsaw_analyse_gapsA

Detect chronological or EventRecordID discontinuities for investigation.

Curated or filtered samples naturally contain gaps; these are not proof of deletion. Correlate with acquisition history and Security 1102 / System 104.

chainsaw_analyse_shimcacheA

Build an execution timeline from the shimcache with optional Amcache enrichment.

Wraps chainsaw analyse shimcache. Output is CSV stored under a result handle; the preview holds the first rows. Use chainsaw_result_export for the full file.

chainsaw_analyse_srumA

Analyse the System Resource Usage Monitor (SRUM) database.

Wraps chainsaw analyse srum. Output is stored under a result handle; use chainsaw_result_export for the complete text.

chainsaw_delete_ruleA

Delete a custom rule. Bundled Chainsaw and Sigma rules cannot be deleted.

chainsaw_dumpA

Convert every record in the evidence to JSON under a result handle.

Wraps chainsaw dump. Use it when a hunt or search has narrowed the scope to one or two files and you need the complete record stream; page through the handle.

chainsaw_get_mappingA

Describe a Sigma-to-event-log mapping file: groups, filters, field translations.

Mappings decide which Sigma logsources apply to which Windows events. Read this when a Sigma rule you expect is not firing.

chainsaw_get_ruleA

Read one rule's YAML and parsed summary, or list a rule directory.

chainsaw_huntA

Hunt evidence with Sigma and Chainsaw detection rules.

Runs chainsaw hunt over the given paths, stores every detection as JSONL under a server-minted result handle, and returns aggregate counts (by rule, level, host, channel, event ID, hour) with a small preview. Prefer this over reading raw events.

chainsaw_jev_triageA

Send selected result rows to TypeSafe Jev for advisory classification and priority.

EXTERNAL DATA TRANSFER: sends the selected evidence fields to api.typesafe.ai. Requires CHAINSAW_JEV_ENABLED=true and credentials. One bounded API request per call, no retries. Returns source row indexes, probabilities and confidence; invalid answers fail only their source row, with both scores null and a named error; invalid response containers reject the batch. Each assessment lists all uncertain_reasons: insufficient_context, low_classification_confidence, low_priority_confidence or validation_failed. uncertain is true when reasons exist. Scores are model judgments, not confirmed findings. Review the original evidence before acting. Evidence and stored results are unchanged.

chainsaw_lint_rulesA

Validate rules with chainsaw lint and report which files fail to load and why.

Run it after chainsaw_save_rule, or on a Sigma sub-tree to see unsupported modifiers.

chainsaw_list_evidenceA

List artefact files below an evidence path with sizes and types.

Use it to scope a hunt: pick directories or individual .evtx files instead of hunting an entire mount. Follow next_offset until null for a complete inventory; the evidence tree must remain unchanged between pages.

chainsaw_process_lineageA

Pivot process GUIDs in explicitly scoped original evidence, including unmatched events.

Supply files from one investigation (not a shared evidence root) and an exact host. Each hop queries process/parent GUIDs; output is capped and reports incomplete traversal.

chainsaw_result_chunkB

Read UTF-8 text chunks of a file or oversized JSON row. Resume next_byte_offset.

chainsaw_result_deleteA

Delete a stored result and its metadata. Evidence files are never touched.

chainsaw_result_eventsB

Page unique source-qualified events, retaining every associated rule match.

chainsaw_result_exportA

Render a stored result as CSV or JSONL text for reports or other tools.

Large results are capped by rows and encoded response bytes; resume next_offset. CSV pages repeat their header. For stored text files resume next_byte_offset; those UTF-8 chunks may split records and must be concatenated before parsing.

chainsaw_result_fieldsA

Discover the field paths present in a result so you can project or group on them.

Returns each dotted path with how many sampled rows carry it and an example value.

chainsaw_result_listB

List stored result handles, newest first, with tool, inputs and row counts.

chainsaw_result_pageA

Read a page of rows from a stored result, optionally projected and filtered.

Rows are chainsaw detections (hunt) or raw documents (search, dump). Iterate with next_offset until it is null.

chainsaw_result_summaryA

Aggregate a stored result without paging through it.

Use the default overview to understand a hunt, then group by specific event fields (users, processes, source IPs, logon IDs) to build pivots for chainsaw_search.

chainsaw_rule_statsA

Count installed Chainsaw, Sigma and custom rules by level and status, plus mappings.

Also lists the Sigma collections present; pass those names to chainsaw_hunt's sigma_collections when you want threat-hunting or emerging-threat rules included.

chainsaw_save_ruleA

Save an analyst-authored Chainsaw rule into the custom rules directory.

Saved rules are hunted with extra_rules=['custom']. The file is linted before the result is returned; a failing lint still leaves the file in place so it can be fixed with another save using overwrite=true.

chainsaw_searchA

Search evidence for keywords, regular expressions, or tau field expressions.

Runs chainsaw search; each matching document is stored under a result handle and summarised by host, channel, event ID and hour. Use tau expressions to pivot on a specific field (for example a LogonId, process GUID, or user) after a hunt.

chainsaw_search_rulesA

Find detection rules by keyword, ATT&CK tag, level, status or logsource.

Use it to explain a detection name from a hunt, to check coverage for a technique, or to pick a sub-tree for a focused hunt. Returns rule URIs readable as resources.

chainsaw_statusA

Report server configuration, chainsaw version, rule counts and evidence roots.

Call this first to learn which evidence roots and rule sets are available, and whether the chainsaw binary is installed.

Prompts

Interactive templates invoked by user choice

NameDescription
triage_evtxStructured first-pass triage of Windows event logs with Chainsaw.
pivot_on_indicatorInvestigate one indicator (user, host, IP, process, LogonId) across evidence.
author_ruleWrite, save and validate a Chainsaw detection rule from an observed pattern.

Resources

Contextual data attached and managed by the client

NameDescription
chainsaw-rule-formatHow to write a Chainsaw detection rule (tau syntax, fields, kinds).
chainsaw-configEffective server configuration (paths, limits, Jev settings).

TDQS

A3.7/5.0

Scored across 26 tools

Disambiguation4/5

Tools are largely distinguished by artifact type and action: EVTX/gap/shimcache/SRUM analyses, hunt/search/dump, rule management, and result management. Some overlap exists among result_page, result_events, result_export, and result_chunk, but the descriptions clarify their distinct purposes.

Naming Consistency4/5

All tools use a consistent chainsaw_ prefix and snake_case, making the server easy to navigate. The suffixes mix verb_noun patterns (e.g., chainsaw_delete_rule, chainsaw_analyse_evtx) with noun-first patterns (e.g., chainsaw_rule_stats, chainsaw_result_list), a minor deviation from a strict convention.

Tool Count3/5

At 26 tools, the surface is on the heavy side, with eight result_* tools alone. However, the domain is broad—evidence scoping, hunting, multiple artifact analyses, rule lifecycle, and result paging/export—so the count is borderline rather than clearly excessive.

Completeness4/5

The set covers evidence listing, hunt/search/dump, targeted artifact analyses, rule reading/searching/saving/deleting/linting/stats, and result listing/paging/chunking/exporting/deleting. Minor gaps include no explicit rule update beyond overwrite-on-save and no analysis tools beyond Chainsaw's supported artifact set.

Maintenance

ActivityMaintained
ResponsivenessNo issues