Security Detections

Aggregates security detection rules from Sigma, Splunk ESCU, Elastic, and KQL into a unified searchable SQLite database with MITRE

mhaggis 462 ↓ 1.8k
Claude CodeClaude DesktopGeneric
View source ↗

An MCP server that provides unified access to security detection rules from Sigma, Splunk ESCU, Elastic Detection Rules, and KQL query repositories. The implementation indexes detection rules into a searchable SQLite database with full-text search capabilities, automatically parsing YAML and TOML formats to extract MITRE ATT&CK mappings, CVE references, process names, and other metadata. Supports advanced filtering by MITRE tactics, severity levels, data sources, and process names, making it useful for security analysts building detection coverage maps, threat hunters researching specific attack techniques, or security engineers comparing detection approaches across different SIEM platforms.

Source

Repository: https://github.com/mhaggis/security-detections-mcp

Maintain Security Detections?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

Security Detections on getagentictools
[![Security Detections on getagentictools](https://getagentictools.com/badge/mcp/mhaggis-security-detections-mcp.svg)](https://getagentictools.com/mcp/mhaggis-security-detections-mcp?ref=badge)