security-detections-mcp
Skill by ara.so — Security Skills collection
An MCP (Model Context Protocol) server providing LLM access to 8,200+ security detection rules across Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike CQL formats, with MITRE ATT&CK mapping, coverage analysis, and autonomous detection engineering.
What It Does
- Unified detection search across 6 major security platforms (Sigma, Splunk, Elastic, KQL, Sublime, CrowdStrike)
- MITRE ATT&CK integration with 172 threat actors, 784 software, 4,362 actor-technique relationships
- Coverage analysis identifying gaps in detection by tactic/technique/actor
- ATT&CK Navigator layers exportable as JSON for visualization
- Autonomous detection pipeline from CTI ingestion to draft PR generation
- 81 MCP tools for detection engineering (local) or ~25 tools (hosted)
- 11 expert prompts for ransomware assessment, APT emulation, purple teaming
Installation
Local Installation (Full Power)
Prerequisites:
- Node.js 18+
- Detection rule repositories cloned locally
Quick start with npx:
Configure in Claude Desktop (claude_desktop_config.json):
Configure in Cursor (.cursor/settings.json):
Configure in VS Code (settings.json):
Hosted Installation (Zero Setup)
Prerequisites:
- API token from detect.michaelhaag.org/account/tokens
- Free tier: 200 calls/day, read-only tools
Claude Desktop (requires mcp-remote):
VS Code / Cursor:
Getting Detection Content
Download all detection sources with sparse checkout:
Then update environment variables to point to these paths.
Core MCP Tools
Detection Search & Retrieval
MITRE ATT&CK Filtering
Coverage Analysis
ATT&CK Navigator Layer Generation
Common Patterns
Ransomware Readiness Assessment
Use the built-in prompt:
Or manually:
APT Threat Emulation
Detection Gap Analysis
Building Detection Content
Cross-Platform Detection Comparison
Configuration Reference
Environment Variables
Source Type Values
sigma- Sigma rules (YAML)splunk_escu- Splunk Enterprise Security Content Updateelastic- Elastic Security detection ruleskql- Kusto Query Language hunting queriessublime- Sublime Security detection rulescrowdstrike_cql- CrowdStrike Query Language (CQL)
Tactic Values (MITRE ATT&CK)
reconnaissanceresource-developmentinitial-accessexecutionpersistenceprivilege-escalationdefense-evasioncredential-accessdiscoverylateral-movementcollectioncommand-and-controlexfiltrationimpact
Troubleshooting
MCP Server Not Indexing Rules
Problem: get_stats shows 0 detections
Solution:
- Verify paths exist:
ls -la /path/to/sigma/rules - Check environment variables are set correctly in MCP config
- Rebuild index manually:
- Check MCP server logs in Claude Desktop:
~/Library/Logs/Claude/mcp*.log
Permission Denied Errors
Problem: Cannot read detection files
Solution:
Hosted MCP 401 Unauthorized
Problem: Token authentication failing
Solution:
- Verify token starts with
sdmcp_ - Check token is not expired at detect.michaelhaag.org/account/tokens
- Ensure
Authorization: Bearerheader format is correct - Free tier rate limit: 200 calls/day
Missing MITRE ATT&CK Data
Problem: Actor/technique queries return empty
Solution:
- Download STIX bundle:
- Set
ATTACK_STIX_PATHenvironment variable - Rebuild index
Sigma Rules Not Parsing
Problem: Some Sigma rules show errors
Solution:
- Ensure you're using the official SigmaHQ repo
- Update to latest rules:
cd sigma && git pull - Some experimental rules may have schema issues - this is expected
- Check parsing errors in MCP logs
Slow Initial Index Build
Problem: First startup takes 30+ seconds
Solution:
- Expected behavior with 8,200+ detections
- Subsequent startups use cached index (~2 seconds)
- Use hosted MCP for zero startup time
- Reduce
PATHSto only needed sources
Advanced Usage
Custom Detection Repositories
Add your private detections:
Autonomous Detection Pipeline
Enable autonomous CTI → detection generation:
See Autonomous docs for full pipeline details.
Exporting for SIEM
Expert Prompts
Built-in workflows accessible by name:
ransomware-readiness-assessment- Full kill-chain coverage analysisapt-threat-emulation- Actor-specific detection mappingpurple-team-exercise- Combined offensive/defensive planningexecutive-briefing- High-level coverage summarydetection-sprint-planning- Engineering backlog prioritizationinsider-threat-detection- Privilege abuse coveragecloud-security-assessment- Cloud-specific technique coveragesupply-chain-security- Third-party risk detectiondata-exfiltration-defense- Exfiltration technique coverageinitial-access-hardening- Entry point detection reviewcredential-theft-protection- Credential access coverage
Usage:
Resources
- GitHub: https://github.com/MHaggis/Security-Detections-MCP
- Web App: https://detect.michaelhaag.org
- Setup Guide: https://github.com/MHaggis/Security-Detections-MCP/blob/main/SETUP.md
- Hosted MCP Guide: https://github.com/MHaggis/Security-Detections-MCP/blob/main/docs/HOSTED_MCP.md
- Tools Reference: https://github.com/MHaggis/Security-Detections-MCP/blob/main/docs/wiki/Tools-Reference.md
- API Token: https://detect.michaelhaag.org/account/tokens


