Skip to main content

security-detections-mcp

Query unified Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike security detection rules via MCP server with MITRE ATT&CK mapping and coverage analysis

معلومات المصدر

المستودع
reason-machines/security-skills
آخر نشاط في المصدر
٢٠ مايو ٢٠٢٦ في ٠٣:١٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
١٢
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
security-detections-mcp
description
Query unified Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike security detection rules via MCP server with MITRE ATT&CK mapping and coverage analysis
triggers
["search for security detections covering technique","analyze MITRE ATT&CK coverage for ransomware","find detection gaps in our security stack","query Sigma rules for process injection","generate ATT&CK Navigator layer showing coverage","compare detection coverage across threat actors","build detections for lateral movement techniques","show me Splunk rules for credential dumping"]
# security-detections-mcp > Skill by [ara.so](https://ara.so) — Security Skills collection An MCP (Model Context Protocol) server providing LLM access to 8,200+ security detection rules across Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike CQL formats, with MITRE ATT&CK mapping, coverage analysis, and autonomous detection engineering. ## What It Does - **Unified detection search** across 6 major security platforms (Sigma, Splunk, Elastic, KQL, Sublime, CrowdStrike) - **MITRE ATT&CK integration** with 172 threat actors, 784 software, 4,362 actor-technique relationships - **Coverage analysis** identifying gaps in detection by tactic/technique/actor - **ATT&CK Navigator layers** exportable as JSON for visualization - **Autonomous detection pipeline** from CTI ingestion to draft PR generation - **81 MCP tools** for detection engineering (local) or ~25 tools (hosted) - **11 expert prompts** for ransomware assessment, APT emulation, purple teaming ## Installation ### Local Installation (Full Power) **Prerequisites:** - Node.js 18+ - Detection rule repositories cloned locally **Quick start with npx:** ```bash npx -y security-detections-mcp ``` **Configure in Claude Desktop** (`claude_desktop_config.json`): ```json { "mcpServers": { "security-detections": { "command": "npx", "args": ["-y", "security-detections-mcp"], "env": { "SIGMA_PATHS": "/path/to/sigma/rules,/path/to/sigma/rules-threat-hunting", "SPLUNK_PATHS": "/path/to/security_content/detections", "STORY_PATHS": "/path/to/security_content/stories", "ELASTIC_PATHS": "/path/to/detection-rules/rules", "KQL_PATHS": "/path/to/kql-rules", "SUBLIME_PATHS": "/path/to/sublime-rules/detection-rules", "CQL_HUB_PATHS": "/path/to/cql-hub/queries", "ATTACK_STIX_PATH": "/path/to/enterprise-attack.json" } } } } ``` **Configure in Cursor** (`.cursor/settings.json`): ```json { "mcp": { "servers": { "security-detections": { "command": "npx", "args": ["-y", "security-detections-mcp"], "env": { "SIGMA_PATHS": "/Users/you/detections/sigma/rules", "SPLUNK_PATHS": "/Users/you/detections/security_content/detections" } } } } } ``` **Configure in VS Code** (settings.json): ```json { "mcp.servers": { "security-detections": { "type": "stdio", "command": "npx", "args": ["-y", "security-detections-mcp"], "env": { "SIGMA_PATHS": "/home/you/detections/sigma/rules" } } } } ``` ### Hosted Installation (Zero Setup) **Prerequisites:** - API token from [detect.michaelhaag.org/account/tokens](https://detect.michaelhaag.org/account/tokens) - Free tier: 200 calls/day, read-only tools **Claude Desktop** (requires `mcp-remote`): ```json { "mcpServers": { "security-detections": { "command": "npx", "args": [ "-y", "mcp-remote", "https://detect.michaelhaag.org/api/mcp/mcp", "--header", "Authorization: Bearer ${SDMCP_TOKEN}" ] } } } ``` **VS Code / Cursor:** ```json { "mcp.servers": { "security-detections": { "type": "http", "url": "https://detect.michaelhaag.org/api/mcp/mcp", "headers": { "Authorization": "Bearer ${SDMCP_TOKEN}" } } } } ``` ## Getting Detection Content Download all detection sources with sparse checkout: ```bash mkdir -p ~/detections && cd ~/detections # Sigma rules git clone --depth 1 --filter=blob:none --sparse https://github.com/SigmaHQ/sigma.git cd sigma && git sparse-checkout set rules rules-threat-hunting && cd .. # Splunk ESCU git clone --depth 1 --filter=blob:none --sparse https://github.com/splunk/security_content.git cd security_content && git sparse-checkout set detections stories && cd .. # Elastic git clone --depth 1 --filter=blob:none --sparse https://github.com/elastic/detection-rules.git cd detection-rules && git sparse-checkout set rules && cd .. # KQL git clone --depth 1 https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules.git kql-bertjanp git clone --depth 1 https://github.com/jkerai1/KQL-Queries.git kql-jkerai1 # Sublime git clone --depth 1 --filter=blob:none --sparse https://github.com/sublime-security/sublime-rules.git cd sublime-rules && git sparse-checkout set detection-rules && cd .. # CrowdStrike CQL git clone --depth 1 https://github.com/ByteRay-Labs/Query-Hub.git cql-hub # MITRE ATT&CK STIX curl -o enterprise-attack.json https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json ``` Then update environment variables to point to these paths. ## Core MCP Tools ### Detection Search & Retrieval ```typescript // Full-text search across all detections { "name": "search", "arguments": { "query": "process injection", "limit": 10 } } // Get specific detection by ID { "name": "get_by_id", "arguments": { "id": "sigma_abc123" } } // List all detections with pagination { "name": "list_all", "arguments": { "limit": 50, "offset": 0 } } // Filter by source type { "name": "list_by_source", "arguments": { "source_type": "sigma" // sigma, splunk_escu, elastic, kql, sublime, crowdstrike_cql } } // Get index statistics { "name": "get_stats", "arguments": {} } ``` ### MITRE ATT&CK Filtering ```typescript // Find detections for specific technique { "name": "list_by_mitre", "arguments": { "technique_id": "T1059.001" // PowerShell } } // Filter by tactic { "name": "list_by_mitre_tactic", "arguments": { "tactic": "execution" // execution, persistence, privilege-escalation, etc. } } // Search by CVE { "name": "list_by_cve", "arguments": { "cve_id": "CVE-2021-34527" // PrintNightmare } } // Find by process name { "name": "list_by_process_name", "arguments": { "process_name": "powershell.exe" } } // Filter by severity { "name": "list_by_severity", "arguments": { "level": "critical" // critical, high, medium, low } } // Filter by data source { "name": "list_by_data_source", "arguments": { "data_source": "process_creation" } } ``` ### Coverage Analysis ```typescript // Analyze overall coverage (~2KB response) { "name": "analyze_coverage", "arguments": { "source_type": "sigma" // optional: analyze specific source } } // Identify gaps for threat profile (~500B response) { "name": "identify_gaps", "arguments": { "threat_profile": "ransomware" // ransomware, apt, persistence, lateral_movement } } // Get detection suggestions for technique (~2KB) { "name": "suggest_detections", "arguments": { "technique_id": "T1003.001" // LSASS Memory } } // Coverage summary by tactic (~200B) { "name": "get_coverage_summary", "arguments": { "source_type": "splunk_escu" } } // Analyze coverage against threat actor { "name": "analyze_actor_coverage", "arguments": { "actor": "APT29" } } // Compare coverage across multiple actors { "name": "compare_actor_coverage", "arguments": { "actors": ["APT29", "APT28", "Lazarus Group"] } } // Behavioral procedure breakdown for technique { "name": "analyze_procedure_coverage", "arguments": { "technique_id": "T1055" } } ``` ### ATT&CK Navigator Layer Generation ```typescript // Generate Navigator layer JSON { "name": "generate_navigator_layer", "arguments": { "name": "Current Coverage", "description": "Detection coverage as of 2024-01", "filter": { "source": "sigma", "tactic": "defense-evasion", "min_severity": "medium" }, "color_by": "coverage" // coverage, severity, source } } // Export to file (local only) { "name": "export_navigator_layer", "arguments": { "output_path": "./coverage-layer.json", "filter": { "actor": "APT29" } } } ``` ## Common Patterns ### Ransomware Readiness Assessment Use the built-in prompt: ``` Use the ransomware-readiness-assessment prompt to evaluate our coverage ``` Or manually: ```typescript // 1. Identify gaps { "name": "identify_gaps", "arguments": { "threat_profile": "ransomware" } } // 2. Get detections for weak areas { "name": "list_by_mitre", "arguments": { "technique_id": "T1486" // Data Encrypted for Impact } } // 3. Generate coverage layer { "name": "generate_navigator_layer", "arguments": { "name": "Ransomware Coverage", "filter": { "threat_profile": "ransomware" } } } ``` ### APT Threat Emulation ```typescript // 1. Analyze actor coverage { "name": "analyze_actor_coverage", "arguments": { "actor": "APT29" } } // 2. Get techniques used by actor { "name": "get_actor_techniques", "arguments": { "actor": "APT29" } } // 3. Find detections for each technique { "name": "list_by_mitre", "arguments": { "technique_id": "T1059.001" } } // 4. Compare with other actors {
عرض على GitHub
ملف SKILL.md هذا كبير جدا، لذلك يعرض SkillsMP القسم الاول فقط هنا. عرض على GitHub