Skip to main content
Glama
SigmaHQ

Sigma MCP Server

Official
by SigmaHQ

Sigma MCP 服务器

一个 MCP 服务器,向 AI 助手和其他 MCP 客户端公开 pySigma 功能。

功能

功能

详情

工具 validate_rule

针对所有已配置的验证器验证 Sigma 规则 (YAML)

工具 configure_validators

为当前 MCP 会话持久化自定义验证器允许列表/排除列表

资源 sigma://validators

可用验证器标识符到描述的 JSON 字典

资源 sigma://modifiers

可用 Sigma 值修饰符名称的 JSON 列表

Related MCP server: mcp-audit-server

要求

  • Python ≥ 3.10

  • Poetry (用于开发/安装)

安装

git clone <repo-url>
cd sigma-mcp-server
poetry install

使用方法

运行服务器

poetry run sigma-mcp-server
# or, after installation:
sigma-mcp-server

服务器默认监听 stdio(标准 MCP 传输)。

在 VS Code / Claude Desktop 中配置

将以下条目添加到您的 MCP 客户端配置中(例如 ~/.config/claude/claude_desktop_config.json):

{
  "mcpServers": {
    "sigma": {
      "command": "sigma-mcp-server"
    }
  }
}

如果 command 路径不在 PATH 中,请将其调整为已安装的二进制文件路径。


工具参考

validate_rule

验证单个 Sigma 规则。

参数

名称

类型

描述

rule_yaml

string

YAML 格式的完整 Sigma 规则

返回

验证问题对象的 JSON 数组。每个对象包含:

键

类型

描述

validator

string

产生该问题的验证器标识符

type

string

问题类名(例如 IdentifierExistenceIssue)

severity

string

low(低)、medium(中)或 high(高)

description

string

问题类的人类可读描述

rules

array[string]

受该问题影响的规则 ID/标题

可能还会存在其他子类特定的字段(例如 identifier)。

空数组表示该规则通过了所有活动验证器的检查。


configure_validators

为当前 MCP 会话持久化自定义验证器配置。同一会话中的所有后续 validate_rule 调用都将使用此配置。

参数

名称

类型

默认值

描述

validator_names

array[string] | null

null

验证器标识符的显式允许列表。null = 使用全部。

exclusions

array[string] | null

null (= [])

应用允许列表后要排除的验证器标识符。

返回

成功时:{"validator_names": ..., "exclusions": [...]} 确认存储的配置。 错误时:{"error": "<description>"} 当提供了未知标识符时。

示例 – 排除单个验证器:

{"exclusions": ["identifier_existence"]}

示例 – 仅使用两个验证器:

{"validator_names": ["identifier_existence", "identifier_uniqueness"]}

资源参考

sigma://validators

返回一个将验证器标识符字符串映射到其人类可读描述的 JSON 对象。验证器标识符与 configure_validators 一起使用。

响应示例(已截断):

{
  "identifier_existence": "Checks if rule has identifier.",
  "identifier_uniqueness": "Check rule UUID uniqueness.",
  ...
}

sigma://modifiers

返回一个已排序的 Sigma 值修饰符名称的 JSON 数组,这些修饰符可用于检测条件(例如 contains、startswith、re、base64)。


开发

# Install dev dependencies
poetry install

# Run tests
poetry run pytest

# Run tests with coverage report
poetry run pytest --cov=sigma/mcp --cov-report=term-missing

# Type checking
poetry run mypy sigma/mcp/ tests/

# Code formatting
poetry run black sigma/ tests/ conftest.py

测试覆盖率必须保持在 ≥ 95%。所有代码必须通过 mypy --strict 检查,并使用默认配置的 black 进行格式化。

许可证

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    This MCP server enables security auditing for MCP configurations and AI agents, including prompt injection testing, data flow tracing, and security policy generation.
    47 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    RSigma is a Rust detection-engineering toolkit for the Sigma standard. Its MCP server (rsigma mcp serve) exposes the toolchain to AI agents over stdio or Streamable HTTP, with tools to author, lint, validate, and convert Sigma rules, evaluate and explain detections against log events, and inspect correlation state.
    15
    165
    MIT