Sigma MCP Server
OfficialSigma MCP 서버
pySigma 기능을 AI 어시스턴트 및 기타 MCP 클라이언트에 노출하는 MCP 서버입니다.
기능
기능 | 세부 정보 |
도구 | 구성된 모든 검증 도구를 사용하여 Sigma 규칙(YAML) 검증 |
도구 | 현재 MCP 세션에 대한 사용자 지정 검증 도구 허용 목록/제외 목록 유지 |
리소스 | 사용 가능한 검증 도구 식별자 → 설명의 JSON 딕셔너리 |
리소스 | 사용 가능한 Sigma 값 수정자 이름의 JSON 목록 |
Related MCP server: mcp-audit-server
요구 사항
Python ≥ 3.10
Poetry (개발/설치용)
설치
git clone <repo-url>
cd sigma-mcp-server
poetry install사용법
서버 실행
poetry run sigma-mcp-server
# or, after installation:
sigma-mcp-server서버는 기본적으로 stdio(표준 MCP 전송)에서 수신 대기합니다.
VS Code / Claude Desktop 구성
MCP 클라이언트 구성(예: ~/.config/claude/claude_desktop_config.json)에 다음 항목을 추가합니다:
{
"mcpServers": {
"sigma": {
"command": "sigma-mcp-server"
}
}
}command 경로가 PATH에 없는 경우 설치된 바이너리 경로로 조정하십시오.
도구 참조
validate_rule
단일 Sigma 규칙을 검증합니다.
인수
이름 | 유형 | 설명 |
|
| YAML 형식의 전체 Sigma 규칙 |
반환값
검증 문제 객체의 JSON 배열입니다. 각 객체에는 다음이 포함됩니다:
키 | 유형 | 설명 |
|
| 문제를 생성한 검증 도구 식별자 |
|
| 문제 클래스 이름 (예: |
|
|
|
|
| 문제 클래스에 대한 사람이 읽을 수 있는 설명 |
|
| 문제의 영향을 받는 규칙 ID / 제목 |
추가적인 하위 클래스별 필드(예: identifier)가 존재할 수도 있습니다.
빈 배열은 규칙이 모든 활성 검증 도구를 통과했음을 의미합니다.
configure_validators
현재 MCP 세션에 대한 사용자 지정 검증 도구 구성을 유지합니다. 동일한 세션 내의 모든 후속 validate_rule 호출은 이 구성을 사용합니다.
인수
이름 | 유형 | 기본값 | 설명 |
|
|
| 검증 도구 식별자의 명시적 허용 목록. |
|
|
| 허용 목록이 적용된 후 제외할 검증 도구 식별자. |
반환값
성공 시: 저장된 구성을 확인하는 {"validator_names": ..., "exclusions": [...]}.
오류 시: 알 수 없는 식별자가 제공된 경우 {"error": "<description>"}.
예시 – 단일 검증 도구 제외:
{"exclusions": ["identifier_existence"]}예시 – 두 개의 검증 도구만 사용:
{"validator_names": ["identifier_existence", "identifier_uniqueness"]}리소스 참조
sigma://validators
검증 도구 식별자 문자열을 사람이 읽을 수 있는 설명에 매핑하는 JSON 객체를 반환합니다. 검증 도구 식별자는 configure_validators와 함께 사용됩니다.
응답 예시 (생략됨):
{
"identifier_existence": "Checks if rule has identifier.",
"identifier_uniqueness": "Check rule UUID uniqueness.",
...
}sigma://modifiers
탐지 조건(예: contains, startswith, re, base64)에서 사용할 수 있는 Sigma 값 수정자 이름의 정렬된 JSON 배열을 반환합니다.
개발
# Install dev dependencies
poetry install
# Run tests
poetry run pytest
# Run tests with coverage report
poetry run pytest --cov=sigma/mcp --cov-report=term-missing
# Type checking
poetry run mypy sigma/mcp/ tests/
# Code formatting
poetry run black sigma/ tests/ conftest.py테스트 커버리지는 95% 이상 유지되어야 합니다. 모든 코드는 mypy --strict를 통과해야 하며 기본 구성의 black으로 포맷팅되어야 합니다.
라이선스
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for building and testing AI agents with multi-model experimentation and insights.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
The OpenZeppelin Solidity Contracts MCP server integrates OpenZeppelin's security and style rules into AI-driven development workflows, enabling AI assistants to generate safe, correct, and production-ready smart contracts. It automatically validates generated code against OpenZeppelin standards (including imports, modifiers, naming conventions, and security checks) and supports various contract types including ERC-20, ERC-721, ERC-1155, Stablecoins, RWA, Governor, and Account contracts through prompt-driven workflows.
MCP server for your apps' tools and custom tools, plus hosted AI agents and approval-gated workflows
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceConfig Validator AI - MCP server providing AI-powered tools and automation by MEOK AI Labs18 npmMIT
- AlicenseNot gradedqualityAmaintenanceThis MCP server enables security auditing for MCP configurations and AI agents, including prompt injection testing, data flow tracing, and security policy generation.47 npmMIT

GoReleaser MCPofficial
AlicenseNot gradedqualityAmaintenanceMCP server for GoReleaser that enables AI assistants to validate, fix, and modernize GoReleaser configurations.21MIT- AlicenseAqualityAmaintenanceRSigma is a Rust detection-engineering toolkit for the Sigma standard. Its MCP server (rsigma mcp serve) exposes the toolchain to AI agents over stdio or Streamable HTTP, with tools to author, lint, validate, and convert Sigma rules, evaluate and explain detections against log events, and inspect correlation state.15165MIT