Sigma MCP Server
OfficialSigma MCPサーバー
pySigmaの機能をAIアシスタントやその他のMCPクライアントに公開するMCPサーバーです。
機能
機能 | 詳細 |
ツール | 設定されたすべてのバリデーターに対してSigmaルール(YAML)を検証する |
ツール | 現在のMCPセッション用のカスタムバリデーターの許可リスト/除外リストを保持する |
リソース | 利用可能なバリデーター識別子から説明へのJSON辞書 |
リソース | 利用可能なSigma値修飾子名のJSONリスト |
Related MCP server: mcp-audit-server
要件
Python ≥ 3.10
Poetry(開発/インストール用)
インストール
git clone <repo-url>
cd sigma-mcp-server
poetry install使用方法
サーバーの実行
poetry run sigma-mcp-server
# or, after installation:
sigma-mcp-serverサーバーはデフォルトでstdio(標準的なMCPトランスポート)でリッスンします。
VS Code / Claude Desktopでの設定
MCPクライアントの設定(例: ~/.config/claude/claude_desktop_config.json)に以下のエントリを追加します:
{
"mcpServers": {
"sigma": {
"command": "sigma-mcp-server"
}
}
}commandのパスがPATH上にない場合は、インストールされたバイナリへのパスに調整してください。
ツールリファレンス
validate_rule
単一のSigmaルールを検証します。
引数
名前 | 型 | 説明 |
|
| YAML形式の完全なSigmaルール |
戻り値
検証結果のオブジェクトのJSON配列。各オブジェクトには以下が含まれます:
キー | 型 | 説明 |
|
| 問題を生成したバリデーターの識別子 |
|
| 問題のクラス名(例: |
|
|
|
|
| 問題クラスの人間が読める説明 |
|
| 問題の影響を受けるルールID / タイトル |
サブクラス固有のフィールド(例: identifier)も含まれる場合があります。
空の配列は、ルールがすべてのアクティブなバリデーターを通過したことを意味します。
configure_validators
現在のMCPセッションのカスタムバリデーター設定を保持します。
同じセッション内の後続のすべてのvalidate_rule呼び出しで、この設定が使用されます。
引数
名前 | 型 | デフォルト | 説明 |
|
|
| バリデーター識別子の明示的な許可リスト。 |
|
|
| 許可リスト適用後に除外するバリデーター識別子 |
戻り値
成功時: 保存された設定を確認する {"validator_names": ..., "exclusions": [...]}
エラー時: 不明な識別子が指定された場合の {"error": "<description>"}
例 – 単一のバリデーターを除外する:
{"exclusions": ["identifier_existence"]}例 – 2つのバリデーターのみを使用する:
{"validator_names": ["identifier_existence", "identifier_uniqueness"]}リソースリファレンス
sigma://validators
バリデーター識別子文字列を人間が読める説明にマッピングするJSONオブジェクトを返します。バリデーター識別子はconfigure_validatorsで使用されます。
レスポンス例(省略):
{
"identifier_existence": "Checks if rule has identifier.",
"identifier_uniqueness": "Check rule UUID uniqueness.",
...
}sigma://modifiers
検知条件(例: contains、startswith、re、base64)で使用できるSigma値修飾子名のソート済みJSON配列を返します。
開発
# Install dev dependencies
poetry install
# Run tests
poetry run pytest
# Run tests with coverage report
poetry run pytest --cov=sigma/mcp --cov-report=term-missing
# Type checking
poetry run mypy sigma/mcp/ tests/
# Code formatting
poetry run black sigma/ tests/ conftest.pyテストカバレッジは95%以上を維持する必要があります。すべてのコードはmypy --strictを通過し、デフォルト設定のblackでフォーマットされている必要があります。
ライセンス
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for building and testing AI agents with multi-model experimentation and insights.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
The OpenZeppelin Solidity Contracts MCP server integrates OpenZeppelin's security and style rules into AI-driven development workflows, enabling AI assistants to generate safe, correct, and production-ready smart contracts. It automatically validates generated code against OpenZeppelin standards (including imports, modifiers, naming conventions, and security checks) and supports various contract types including ERC-20, ERC-721, ERC-1155, Stablecoins, RWA, Governor, and Account contracts through prompt-driven workflows.
MCP server for your apps' tools and custom tools, plus hosted AI agents and approval-gated workflows
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceConfig Validator AI - MCP server providing AI-powered tools and automation by MEOK AI Labs18 npmMIT
- AlicenseNot gradedqualityAmaintenanceThis MCP server enables security auditing for MCP configurations and AI agents, including prompt injection testing, data flow tracing, and security policy generation.47 npmMIT

GoReleaser MCPofficial
AlicenseNot gradedqualityAmaintenanceMCP server for GoReleaser that enables AI assistants to validate, fix, and modernize GoReleaser configurations.21MIT- AlicenseAqualityAmaintenanceRSigma is a Rust detection-engineering toolkit for the Sigma standard. Its MCP server (rsigma mcp serve) exposes the toolchain to AI agents over stdio or Streamable HTTP, with tools to author, lint, validate, and convert Sigma rules, evaluate and explain detections against log events, and inspect correlation state.15165MIT