mcp-hayabusa
Related Servers
Alternatives to mcp-hayabusa
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityCmaintenanceEnables EVTX (Windows Event Log) analysis via Hayabusa, providing tools to scan event logs and retrieve detection rules.-
- FlicenseNot gradedqualityBmaintenanceEnables scanning Windows EVTX event log files with Hayabusa, returning structured detection results through an MCP tool.-
- AlicenseNot gradedqualityBmaintenanceEnables Windows event log forensics by wrapping Hayabusa, offering EVTX scanning, Sigma rule exploration, ATT&CK coverage analysis, and detection engineering resources.MIT
- AlicenseAqualityBmaintenanceEnables MCP clients to run Hayabusa detection scans over Windows event log (.evtx) files for forensic analysis and threat hunting.2MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that wraps the Hayabusa CLI, enabling analysis of Windows EVTX event log files and browsing of its detection rule set.-
- AlicenseNot gradedqualityBmaintenanceEnables Windows Event Log (EVTX) analysis by wrapping Hayabusa, exposing scan and rule retrieval tools.MIT
TDQS
Scored across 9 tools
Each tool targets a distinct task: rule updates, logon summary, version retrieval, keyword extraction, critical system detection, search, combined scan, coverage analysis, and rule suggestion. No two tools have overlapping purposes.
Naming is inconsistent: six tools use the 'hayabusa_' prefix, while three (scan_evtx, analyze_coverage, suggest_rule) do not. Verb patterns also vary (e.g., 'update_rules' vs 'logon_summary').
With 9 tools, the server is well-scoped for Windows event log analysis. Each tool addresses a specific need without redundancy or excessive granularity.
The surface covers rule management, detection, search, keyword extraction, system identification, and coverage analysis. Minor gaps exist (e.g., no dedicated tool to list all rules or export results), but core workflows are supported.