Atlas / MCP servers / mhaggis / Security Detections

Security DetectionsBLOCK

mcp/mhaggis/security-detections

MCP to help Defenders Detection Engineer Harder and Smarter

Verdict
BLOCK
Grade
F
Trust score
35 /100
Exposed tools
113 97r · 11w · 5d
Transport
stdio
License
—
Stars
495
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server that lets LLMs query a unified database of Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike CQL security detection rules.

New here? Start with the Setup Guide -- covers macOS, Windows (WSL & native), and Linux step by step. Want it hosted? Skip the install entirely: Hosted MCP Setup Guide

Two Ways to Run It

Local (full power) — the npm package you're looking at. Runs on your machine, indexes your own detection repos, exposes all 81 tools. You need Node.js and ~10 minutes.

Hosted (zero setup) — a Streamable HTTP server at `detect.michaelhaag.org/api/mcp/mcp`. Sign up, generate a token, paste one URL into your MCP client. ~25 read-only tools, always in sync with the latest content, 200 calls/day free. Read on for quick-install buttons.

Install — Local

[](https://cursor.com/en/install-mcp?name=security-detections&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsInNlY3VyaXR5LWRldGVjdGlvbnMtbWNwIl0sImVudiI6eyJTSUdNQV9QQVRIUyI6Ii9wYXRoL3RvL3NpZ21hL3J1bGVzLC9wYXRoL3RvL3NpZ21hL3J1bGVzLXRocmVhdC1odW50aW5nIiwiU1BMVU5LX1BBVEhTIjoiL3BhdGgvdG8vc2VjdXJpdHlfY29udGVudC9kZXRlY3Rpb25zIiwiU1RPUllfUEFUSFMiOiIvcGF0aC90by9zZWN1cml0eV9jb250ZW50L3N0b3JpZXMiLCJFTEFTVElDX1BBVEhTIjoiL3BhdGgvdG8vZGV0ZWN0aW9uLXJ1bGVzL3J1bGVzIiwiS1FMX1BBVEhTIjoiL3BhdGgvdG8va3FsLXJ1bGVzIiwiU1VCTElNRV9QQVRIUyI6Ii9wYXRoL3RvL3N1YmxpbWUtcnVsZXMvZGV0ZWN0aW9uLXJ1bGVzIiwiQ1FMX0hVQl9QQVRIUyI6Ii9wYXRoL3RvL2NxbC1odWIvcXVlcmllcyJ9fQ==) [](https://vscode.dev/redirect?url=vscode:mcp/install?name=security-detections&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%

Read from source at commit 9d9365778ee7OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add security-detections-mcp -- npx -y [email protected]
03

Exposed tools (113)

97 read · 11 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_observationwriteAdd a fact or observation about an entity. Observations capture point-in-time knowledge that can be queried later. Examples: -
analyze_actor_coveragereadAnalyze detection coverage against a specific threat actor. Shows which of the actor\
analyze_coveragereadGet coverage analysis with stats by tactic, top covered techniques, and weak spots. Returns summary data, not raw detections. Use this instead of listing detections and processing manually.
analyze_procedure_coveragereadAnalyze procedure-level coverage for a MITRE technique. Goes beyond
apt-threat-emulationreadAPT group threat emulation planning with detection mapping
audiencereadTarget audience:
check_sampling_statusreadCheck if MCP sampling is available for LLM-enhanced analysis. Sampling allows the server to request LLM completions from the client, enabling richer autonomous analysis. Not all MCP clients support this feature. Use this tool to check capability before using llm_enhanced_analysis.
compare_actor_coveragereadCompare detection coverage across multiple threat actors. Shows shared technique gaps and unique risks per actor. Requires STIX data (ATTACK_STIX_PATH env var).
compare_againstreadAPT group name, threat profile, or
compare_procedure_coveragereadCompare procedure-level detection coverage across sources for a technique. Shows which source catches which specific behaviors — two orgs can both tag T1059.001 but detect completely different procedures. Returns a matrix of source × procedure.
compare_sourcesreadCompare detection coverage between sources (Sigma vs Splunk vs Elastic vs KQL) for a topic. Returns a clean breakdown with counts and names per source.
contextreadAdditional context about the alert
count_by_sourcereadGet quick counts of detections by source for a topic. Returns just the numbers, no detection details.
create_entitywriteCreate a knowledge entity representing a security concept. Use this to build the knowledge graph with threat actors, techniques, detections, campaigns, tools, vulnerabilities, and data sources. Entity types: - threat_actor: APT groups, criminal gangs (e.g.,
create_relationwriteCreate a relationship between two entities WITH reasoning explaining WHY they
create_tablewriteCreate a new custom table to store analysis data. Use this to persist findings, research results, or any structured data you want to retrieve later. Pre-built tables available: gap_analyses, source_comparisons, threat_actor_profiles, detection_recommendations
cve-response-assessmentreadAssess detection coverage for a CVE or named vulnerability
cve_or_threatreadCVE ID or threat name
data-source-gap-analysisreadAnalyze data source requirements vs available detections
delete_entitydestructiveRemove an entity from the knowledge graph. This also removes all relations and observations associated with the entity.
delete_observationdestructiveRemove a specific observation by its ID. Use open_entity first to find observation IDs.
delete_templatedestructiveDelete a saved query template by name.
describe_tablereadGet detailed schema information and statistics for a dynamic table.
detection-coverage-diffreadCompare your detection coverage against threats
detection-engineering-sprintreadPlan a detection engineering sprint with prioritized work
detection-quality-reviewreadReview detection quality for a specific technique
detection_recommendationsreadStore detection recommendations and their implementation status
drop_tabledestructiveRemove a dynamic table and all its data. Use with caution - this is irreversible.
environmentreadTarget environment:
executive-security-briefingreadGenerate executive-level security posture summary
extract_patternswriteExtract and store patterns from all indexed detections. Run this to populate the pattern database for template generation.
find_similar_detectionswriteFind existing detections similar to what you want to create. Use this to learn from existing detection logic and structure.
gap_analysesreadStore gap analysis results including technique coverage, missing detections, and recommendations
generate_navigator_layerreadGenerate a MITRE ATT&CK Navigator layer JSON from detection coverage. Returns valid Navigator JSON ready for import at https://mitre-attack.github.io/attack-navigator/. Filter by source, tactic, or severity.
generate_rba_structurereadGenerate RBA (Risk-Based Alerting) structure for a detection based on learned patterns and best practices.
get_actor_coveragereadAnalyze detection coverage against a MITRE ATT&CK threat actor/APT group. Shows covered and uncovered techniques.
get_actor_profilereadGet full threat actor dossier: description, aliases, known techniques, software employed, and detection coverage status. Requires STIX data (ATTACK_STIX_PATH env var).
get_by_idreadGet a single detection by its ID
get_coverage_summaryreadGet a lightweight coverage summary (~200 bytes) with tactic percentages. Use this for quick overviews instead of full analyze_coverage.
get_detection_listreadGet a lightweight list of detection names and IDs matching a search query. Returns ONLY name, id, source, mitre_ids - no queries or raw yaml. Use this when you need a simple list.
get_field_referencereadGet available fields for a Splunk data model with usage examples. Use this to understand what fields are available when writing a detection query.
get_learningsreadGet applicable learnings for the current task. Returns patterns and insights that may help with the current analysis. Use this to: - Apply proven patterns to new situations - Remember user preferences - Avoid known pitfalls
get_macro_referencereadGet common Splunk macros and their usage patterns. Essential for writing detections that follow repository conventions.
get_query_patternsreadGet common query patterns for a MITRE technique based on existing detections. Returns SPL structure, common fields, macros used, and example queries. Use this before writing a detection to learn the conventions.
get_raw_yamlreadGet the original YAML content for a detection
get_relevant_decisionsreadGet past decisions relevant to the current context. Uses full-text search to find tribal knowledge that applies to your current analysis. Use this to: - See how similar situations were handled before - Understand reasoning behind past recommendations - Maintain consistency with previous decisions
get_saved_queryreadRetrieve a previously saved query result by name.
get_statsreadGet statistics about the indexed detections and stories
get_storyreadGet detailed information about a specific analytic story by name
get_tactic_summaryreadGet a summary of detection coverage across all MITRE ATT&CK tactics.
get_technique_countreadGet just the detection count for a technique (~50 bytes). Use this for quick coverage checks.
get_technique_coveragereadGet detection coverage for a specific MITRE ATT&CK technique. Shows which sources have detections.
get_technique_fullread
get_technique_idsreadGet ONLY unique MITRE technique IDs (lightweight - no full detection data). Use this for Navigator layer generation or coverage analysis.
get_technique_intelligenceread
get_templatereadGet the full details of a saved query template including the template string and parameters.
get_top_gapsreadGet just the top 5 gaps (~300 bytes) for a threat profile. Use this for quick gap checks.
identify_gapsreadIdentify detection gaps based on a threat profile (ransomware, apt, initial-access, persistence, credential-access, defense-evasion). Returns prioritized gaps with recommendations.
include_benchmarksreadInclude industry benchmark comparisons
include_test_planreadGenerate atomic test recommendations
indicatorreadAlert name, process name, technique, or IOC
industryreadYour industry vertical for threat relevance
insert_rowwriteInsert a row of data into a dynamic table. Data is validated against the table schema.
learn_from_feedbackreadStore user preference or correction to improve future suggestions. Call this when user modifies generated content to build tribal knowledge.
list_actorsreadList all known MITRE ATT&CK threat actors with aliases and technique counts. Requires STIX data (ATTACK_STIX_PATH env var).
list_allreadList all detections with pagination. Use for browsing the detection index.
list_by_analytic_storyreadList Splunk detections that belong to a specific analytic story (e.g.,
list_by_cvereadList detections that cover a specific CVE vulnerability
list_by_data_sourcereadList detections that use a specific data source (e.g.,
list_by_detection_typereadList detections by type (TTP, Anomaly, Hunting, Correlation)
list_by_kql_categoryreadList KQL detections filtered by category (e.g.,
list_by_kql_datasourcereadList KQL detections that use a specific Microsoft data source (e.g.,
list_by_kql_tagreadList KQL detections filtered by tag (e.g.,
list_by_logsourcereadList Sigma detections filtered by logsource (category, product, or service)
list_by_mitrereadList detections that map to a specific MITRE ATT&CK technique
list_by_mitre_tacticreadList detections by MITRE ATT&CK tactic (e.g.,
list_by_name_patternreadList detections whose NAME matches a pattern, grouped by source. Returns just name + ID pairs.
list_by_process_namereadList detections that reference a specific process name (e.g.,
list_by_severityreadList detections filtered by severity level
list_by_sourcereadList detections filtered by source type
list_saved_queriesreadList all saved queries, optionally filtered by type.
list_storiesreadList all analytic stories with pagination
list_stories_by_categoryreadList analytic stories by category (e.g.,
list_tablesreadList all dynamic tables created by the LLM, including pre-built analysis tables and their statistics.
list_templatesreadList all saved query templates with their names, descriptions, and usage statistics.
llm_enhanced_analysisreadRequest LLM-enhanced analysis of security detection data using MCP sampling. This tool leverages MCP sampling to request the client
open_entityreadGet complete information about a specific entity including all its relations and observations. This is the detailed view of a single knowledge node.
priority_focusreadFocus area:
purple-team-exercisereadDesign a purple team exercise targeting specific tactics/techniques
query_tablereadQuery data from a dynamic table with optional filtering, sorting, and pagination. Filter examples: - Exact match: {
ransomware-readiness-assessmentreadComprehensive ransomware detection coverage assessment
read_graphreadRead the entire knowledge graph or a filtered subgraph. Returns entities, relations, and observations. Use this to: - Get an overview of all stored knowledge - Filter by entity type to focus on specific concepts - Understand the structure of captured tribal knowledge
rebuild_indexdestructiveForce re-index all detections and stories from configured paths. WARNING: This is a destructive operation that deletes the current index.
run_templatewriteExecute a saved query template with the provided parameters. Returns the query results.
save_querywriteSave a query result for quick retrieval later. Useful for caching frequently needed data.
save_templatewriteSave a reusable query template with {{placeholders}}. Templates can contain SQL queries or tool-chain definitions for future execution.
scopereadMITRE tactic or technique ID
searchreadFull-text search across all detection fields (name, description, query, MITRE IDs, tags, CVEs, analytic stories, process names, file paths, registry paths)
search_detectionsreadSearch for security detections by keyword, technique ID, or description. Returns matching detection rules.
search_knowledgereadSearch across all knowledge types: entities, relations, observations, decisions, and learnings. Uses full-text search to find relevant tribal knowledge. Search examples: -
search_storiesreadSearch analytic stories by narrative, description, or name. Stories provide rich context about threat campaigns and detection strategies.
smart_comparereadCompare detections across sources, tactics, or techniques for a given topic. Returns breakdown by source, tactic, and severity.
soc-investigation-assistreadHelp investigate an alert with relevant detections and context
source_comparisonsreadStore detection source comparison results (Sigma vs Splunk vs Elastic)
sprint_capacityreadNumber of detections to target
suggest_detection_templatereadGenerate a detection template based on technique, learned patterns, and conventions. Returns YAML structure ready for customization.
suggest_detectionsreadGet detection suggestions for a specific technique. Returns existing detections, required data sources, and detection ideas.
target_coveragereadSpecific tactic, technique, or
technique_idreadMITRE technique ID to review
threat-landscape-syncwriteSync detection priorities with current threat landscape
threat_actorreadAPT group name (e.g., APT29, Lazarus Group, Volt Typhoon)
threat_actor_profilesreadStore threat actor research including TTPs, campaigns, and detection mappings
threat_focusreadFocus:
04

Trust audit

BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (11 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
agents/nodes/fp-analyst.ts:26
return yaml.load(content) as Record<string, unknown>;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
agents/nodes/qa-reviewer.ts:26
return yaml.load(content) as Record<string, unknown>;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
agents/nodes/verifier.ts:38
parsed = yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
agents/nodes/attack-range-builder.ts:262
private_key_path: process.env.ATTACK_RANGE_PRIVATE_KEY || '~/.ssh/id_rsa',
Why it matters. touches a credential store
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/supply-chain-analyst/SKILL.md:77
| Git credential access | Audit logs | Monitor `.git-credentials`, `~/.ssh/` access |
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/supply-chain-analyst/SKILL.md:110
- Access to `process.env` collecting CI secrets
Why it matters. asks the agent to read credentials
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
agents/nodes/atomic-executor.ts:40
'T1567.002': true,   // Exfiltration to Cloud Storage
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
agents/nodes/atomic-executor.ts:49
'T9999.003': { name: 'SHEETCREEP GitHub Exfil', description: 'Document exfiltration to GitHub' },
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/db.ts:1042
'exfiltration', 'impact'
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/db.ts:1069
'exfiltration': 9, 'impact': 14
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/db/detections.ts:862
'exfiltration', 'impact'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/atomic-red-team-testing/SKILL.md:103
powershell.exe -NoProfile -Command "(New-Object Net.WebClient).DownloadString('http://127.0.0.1/test')"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/custom-atomics-deployment/SKILL.md:70
default: "http://127.0.0.1:8080/test.txt"
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.claude/skills/supply-chain-analyst/SKILL.md:172
- `RUN curl ... | sh` patterns in Dockerfiles
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_entity, delete_observation, delete_template, drop_table, rebuild_index
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agents/tests/e2e/dry-run.test.ts:2
import { setConfig, loadConfig, resetConfig } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agents/tests/e2e/dry-run.test.ts:3
import { createInitialState, createDetectionPipeline } from '../../graphs/detection-pipeline.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agents/tests/e2e/mocked-pipeline.test.ts:2
import { setConfig, loadConfig, resetConfig } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agents/tests/e2e/mocked-pipeline.test.ts:26
const { createInitialState } = await import('../../graphs/detection-pipeline.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agents/tests/e2e/setup-check.test.ts:2
import { loadConfig, validateConfig } from '../../config.js';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
reports/voidlink_cloud_native_malware_coverage_analysis.md:82
- No specific detection for 169.254.169.254 access patterns from containers
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
reports/voidlink_cloud_native_malware_coverage_analysis.md:216
**Description:** Detects repeated queries to cloud metadata endpoints (169.254.169.254) from containers, indicating potential credential harvesting.
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
reports/voidlink_cloud_native_malware_coverage_analysis.md:222
WHERE All_Traffic.dest_ip="169.254.169.254"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
reports/voidlink_cloud_native_malware_coverage_analysis.md:603
- Implement detection #3 for 169.254.169.254 access
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass, no_license.

Audited 2026-09-30 · audit v0.4.1 · source sha 9d9365778ee7full audit observations/trust-audit/mcp-server/mhaggis__security-detections.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-309d9365778ee7BLOCKF35first audit
06

Questions

What is the Security Detections MCP server?

MCP to help Defenders Detection Engineer Harder and Smarter

What tools does Security Detections expose?

113 in total: 97 read-only, 11 that write, and 5 that can delete or overwrite (delete_entity, delete_observation, delete_template, drop_table, rebuild_index). Every one is listed on this page with its risk.

Is Security Detections safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (35/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Security Detections need?

It reads ANTHROPIC_API_KEY, ATTACK_RANGE_KEY_NAME, ATTACK_RANGE_PASSWORD, ATTACK_RANGE_PRIVATE_KEY, ENCRYPTION_KEY, NEXT_PUBLIC_SUPABASE_ANON_KEY, NEXT_PUBLIC_TURNSTILE_SITE_KEY, OPENROUTER_API_KEY, SUPABASE_SERVICE_ROLE_KEY and TURNSTILE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Security Detections run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as security-detections-web at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (9d9365778ee7), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement