Skip to main content
Glama
chiomao23

mcp-hayabusa

by chiomao23

mcp-hayabusa

MCP server that wraps the Hayabusa CLI for EVTX (Windows Event Log) analysis, exposing scan_evtx and get_hayabusa_rules tools.

Prerequisites

  • Python 3.10+ (this machine's default python/py is 3.8 — use py -3.13 explicitly; see below)

  • The Hayabusa binary — download_hayabusa.py (below) fetches it into ./hayabusa/, which server.py finds automatically. Alternatively, set HAYABUSA_PATH or put hayabusa on PATH.

Related MCP server: hayabusa-mcp

Setup

py -3.13 -m pip install -r requirements.txt
py -3.13 download_hayabusa.py   # downloads Hayabusa for this platform into ./hayabusa/

server.py finds the downloaded binary automatically — no env var needed. On Linux, set HAYABUSA_LIBC=musl at download time if you need the musl build instead of the glibc default.

Run

py -3.13 server.py

This starts the server on stdio, for use with an MCP client (e.g. Claude Code, Claude Desktop).

Tool: scan_evtx

Argument

Type

Default

Description

evtx_path

str

required

Path to a single .evtx file to scan

min_severity

str

medium

Minimum severity to include: informational, low, medium, high, critical

Returns a formatted JSON string (total_detections + a detections array), or {"error": ...} on failure (missing file, missing Hayabusa binary, non-zero exit, timeout, locked/inaccessible file, invalid min_severity).

Tool: get_hayabusa_rules

Argument

Type

Default

Description

keyword

str

""

Case-insensitive substring matched against each rule's title/id/tags/category. Empty = all rules.

limit

int

50

Max rules returned, clamped to [1, 500] (there are ~5000 rule files total)

Returns a formatted JSON string: total_rules_scanned, total_matches, returned, truncated, and a rules array (each with title, id, level, status, category, tags, source, path), sorted highest-severity-first. The first call per server process takes a few seconds (parsing ~5000 YAML rule files); results are cached in memory afterward, so subsequent calls are near-instant regardless of keyword/limit.

Status

Verified against a real, locally downloaded Hayabusa v3.10.0 and real EVTX data (including a locked live Windows event log, to confirm error handling). See CLAUDE.md for architecture notes and known gaps.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    C
    maintenance
    Enables an LLM client to scan Windows event log files (EVTX) for suspicious activity using Hayabusa, and browse its detection rules directly in conversation.
    Last updated
  • F
    license
    -
    quality
    B
    maintenance
    Analyze Windows event logs (EVTX files) using Hayabusa, with tools to scan EVTX files for detections and list Hayabusa detection rules.
    Last updated
  • F
    license
    -
    quality
    B
    maintenance
    Enables Windows Event Log (EVTX) analysis using Hayabusa, with options to filter by severity, rule, and output format.
    Last updated

View all related MCP servers

Related MCP Connectors

  • Offline methodology engine for authorized penetration testing, CTF, and security research.

  • 55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.

  • VirusTotal MCP — file / URL / domain / IP reputation (BYO key)

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/chiomao23/MCP-Detection-Knowledge-Bases'

If you have feedback or need assistance with the MCP directory API, please join our Discord server