Security DetectionsBLOCK
MCP to help Defenders Detection Engineer Harder and Smarter
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server that lets LLMs query a unified database of Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike CQL security detection rules.
New here? Start with the Setup Guide -- covers macOS, Windows (WSL & native), and Linux step by step. Want it hosted? Skip the install entirely: Hosted MCP Setup Guide
Two Ways to Run It
Local (full power) — the npm package you're looking at. Runs on your machine, indexes your own detection repos, exposes all 81 tools. You need Node.js and ~10 minutes.
Hosted (zero setup) — a Streamable HTTP server at `detect.michaelhaag.org/api/mcp/mcp`. Sign up, generate a token, paste one URL into your MCP client. ~25 read-only tools, always in sync with the latest content, 200 calls/day free. Read on for quick-install buttons.
Install — Local
[](https://cursor.com/en/install-mcp?name=security-detections&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsInNlY3VyaXR5LWRldGVjdGlvbnMtbWNwIl0sImVudiI6eyJTSUdNQV9QQVRIUyI6Ii9wYXRoL3RvL3NpZ21hL3J1bGVzLC9wYXRoL3RvL3NpZ21hL3J1bGVzLXRocmVhdC1odW50aW5nIiwiU1BMVU5LX1BBVEhTIjoiL3BhdGgvdG8vc2VjdXJpdHlfY29udGVudC9kZXRlY3Rpb25zIiwiU1RPUllfUEFUSFMiOiIvcGF0aC90by9zZWN1cml0eV9jb250ZW50L3N0b3JpZXMiLCJFTEFTVElDX1BBVEhTIjoiL3BhdGgvdG8vZGV0ZWN0aW9uLXJ1bGVzL3J1bGVzIiwiS1FMX1BBVEhTIjoiL3BhdGgvdG8va3FsLXJ1bGVzIiwiU1VCTElNRV9QQVRIUyI6Ii9wYXRoL3RvL3N1YmxpbWUtcnVsZXMvZGV0ZWN0aW9uLXJ1bGVzIiwiQ1FMX0hVQl9QQVRIUyI6Ii9wYXRoL3RvL2NxbC1odWIvcXVlcmllcyJ9fQ==) [](https://vscode.dev/redirect?url=vscode:mcp/install?name=security-detections&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%
9d9365778ee7OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add security-detections-mcp -- npx -y [email protected]
Exposed tools (113)
97 read · 11 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_observation | write | Add a fact or observation about an entity. Observations capture point-in-time knowledge that can be queried later. Examples: - |
analyze_actor_coverage | read | Analyze detection coverage against a specific threat actor. Shows which of the actor\ |
analyze_coverage | read | Get coverage analysis with stats by tactic, top covered techniques, and weak spots. Returns summary data, not raw detections. Use this instead of listing detections and processing manually. |
analyze_procedure_coverage | read | Analyze procedure-level coverage for a MITRE technique. Goes beyond |
apt-threat-emulation | read | APT group threat emulation planning with detection mapping |
audience | read | Target audience: |
check_sampling_status | read | Check if MCP sampling is available for LLM-enhanced analysis. Sampling allows the server to request LLM completions from the client, enabling richer autonomous analysis. Not all MCP clients support this feature. Use this tool to check capability before using llm_enhanced_analysis. |
compare_actor_coverage | read | Compare detection coverage across multiple threat actors. Shows shared technique gaps and unique risks per actor. Requires STIX data (ATTACK_STIX_PATH env var). |
compare_against | read | APT group name, threat profile, or |
compare_procedure_coverage | read | Compare procedure-level detection coverage across sources for a technique. Shows which source catches which specific behaviors — two orgs can both tag T1059.001 but detect completely different procedures. Returns a matrix of source × procedure. |
compare_sources | read | Compare detection coverage between sources (Sigma vs Splunk vs Elastic vs KQL) for a topic. Returns a clean breakdown with counts and names per source. |
context | read | Additional context about the alert |
count_by_source | read | Get quick counts of detections by source for a topic. Returns just the numbers, no detection details. |
create_entity | write | Create a knowledge entity representing a security concept. Use this to build the knowledge graph with threat actors, techniques, detections, campaigns, tools, vulnerabilities, and data sources. Entity types: - threat_actor: APT groups, criminal gangs (e.g., |
create_relation | write | Create a relationship between two entities WITH reasoning explaining WHY they |
create_table | write | Create a new custom table to store analysis data. Use this to persist findings, research results, or any structured data you want to retrieve later. Pre-built tables available: gap_analyses, source_comparisons, threat_actor_profiles, detection_recommendations |
cve-response-assessment | read | Assess detection coverage for a CVE or named vulnerability |
cve_or_threat | read | CVE ID or threat name |
data-source-gap-analysis | read | Analyze data source requirements vs available detections |
delete_entity | destructive | Remove an entity from the knowledge graph. This also removes all relations and observations associated with the entity. |
delete_observation | destructive | Remove a specific observation by its ID. Use open_entity first to find observation IDs. |
delete_template | destructive | Delete a saved query template by name. |
describe_table | read | Get detailed schema information and statistics for a dynamic table. |
detection-coverage-diff | read | Compare your detection coverage against threats |
detection-engineering-sprint | read | Plan a detection engineering sprint with prioritized work |
detection-quality-review | read | Review detection quality for a specific technique |
detection_recommendations | read | Store detection recommendations and their implementation status |
drop_table | destructive | Remove a dynamic table and all its data. Use with caution - this is irreversible. |
environment | read | Target environment: |
executive-security-briefing | read | Generate executive-level security posture summary |
extract_patterns | write | Extract and store patterns from all indexed detections. Run this to populate the pattern database for template generation. |
find_similar_detections | write | Find existing detections similar to what you want to create. Use this to learn from existing detection logic and structure. |
gap_analyses | read | Store gap analysis results including technique coverage, missing detections, and recommendations |
generate_navigator_layer | read | Generate a MITRE ATT&CK Navigator layer JSON from detection coverage. Returns valid Navigator JSON ready for import at https://mitre-attack.github.io/attack-navigator/. Filter by source, tactic, or severity. |
generate_rba_structure | read | Generate RBA (Risk-Based Alerting) structure for a detection based on learned patterns and best practices. |
get_actor_coverage | read | Analyze detection coverage against a MITRE ATT&CK threat actor/APT group. Shows covered and uncovered techniques. |
get_actor_profile | read | Get full threat actor dossier: description, aliases, known techniques, software employed, and detection coverage status. Requires STIX data (ATTACK_STIX_PATH env var). |
get_by_id | read | Get a single detection by its ID |
get_coverage_summary | read | Get a lightweight coverage summary (~200 bytes) with tactic percentages. Use this for quick overviews instead of full analyze_coverage. |
get_detection_list | read | Get a lightweight list of detection names and IDs matching a search query. Returns ONLY name, id, source, mitre_ids - no queries or raw yaml. Use this when you need a simple list. |
get_field_reference | read | Get available fields for a Splunk data model with usage examples. Use this to understand what fields are available when writing a detection query. |
get_learnings | read | Get applicable learnings for the current task. Returns patterns and insights that may help with the current analysis. Use this to: - Apply proven patterns to new situations - Remember user preferences - Avoid known pitfalls |
get_macro_reference | read | Get common Splunk macros and their usage patterns. Essential for writing detections that follow repository conventions. |
get_query_patterns | read | Get common query patterns for a MITRE technique based on existing detections. Returns SPL structure, common fields, macros used, and example queries. Use this before writing a detection to learn the conventions. |
get_raw_yaml | read | Get the original YAML content for a detection |
get_relevant_decisions | read | Get past decisions relevant to the current context. Uses full-text search to find tribal knowledge that applies to your current analysis. Use this to: - See how similar situations were handled before - Understand reasoning behind past recommendations - Maintain consistency with previous decisions |
get_saved_query | read | Retrieve a previously saved query result by name. |
get_stats | read | Get statistics about the indexed detections and stories |
get_story | read | Get detailed information about a specific analytic story by name |
get_tactic_summary | read | Get a summary of detection coverage across all MITRE ATT&CK tactics. |
get_technique_count | read | Get just the detection count for a technique (~50 bytes). Use this for quick coverage checks. |
get_technique_coverage | read | Get detection coverage for a specific MITRE ATT&CK technique. Shows which sources have detections. |
get_technique_full | read | |
get_technique_ids | read | Get ONLY unique MITRE technique IDs (lightweight - no full detection data). Use this for Navigator layer generation or coverage analysis. |
get_technique_intelligence | read | |
get_template | read | Get the full details of a saved query template including the template string and parameters. |
get_top_gaps | read | Get just the top 5 gaps (~300 bytes) for a threat profile. Use this for quick gap checks. |
identify_gaps | read | Identify detection gaps based on a threat profile (ransomware, apt, initial-access, persistence, credential-access, defense-evasion). Returns prioritized gaps with recommendations. |
include_benchmarks | read | Include industry benchmark comparisons |
include_test_plan | read | Generate atomic test recommendations |
indicator | read | Alert name, process name, technique, or IOC |
industry | read | Your industry vertical for threat relevance |
insert_row | write | Insert a row of data into a dynamic table. Data is validated against the table schema. |
learn_from_feedback | read | Store user preference or correction to improve future suggestions. Call this when user modifies generated content to build tribal knowledge. |
list_actors | read | List all known MITRE ATT&CK threat actors with aliases and technique counts. Requires STIX data (ATTACK_STIX_PATH env var). |
list_all | read | List all detections with pagination. Use for browsing the detection index. |
list_by_analytic_story | read | List Splunk detections that belong to a specific analytic story (e.g., |
list_by_cve | read | List detections that cover a specific CVE vulnerability |
list_by_data_source | read | List detections that use a specific data source (e.g., |
list_by_detection_type | read | List detections by type (TTP, Anomaly, Hunting, Correlation) |
list_by_kql_category | read | List KQL detections filtered by category (e.g., |
list_by_kql_datasource | read | List KQL detections that use a specific Microsoft data source (e.g., |
list_by_kql_tag | read | List KQL detections filtered by tag (e.g., |
list_by_logsource | read | List Sigma detections filtered by logsource (category, product, or service) |
list_by_mitre | read | List detections that map to a specific MITRE ATT&CK technique |
list_by_mitre_tactic | read | List detections by MITRE ATT&CK tactic (e.g., |
list_by_name_pattern | read | List detections whose NAME matches a pattern, grouped by source. Returns just name + ID pairs. |
list_by_process_name | read | List detections that reference a specific process name (e.g., |
list_by_severity | read | List detections filtered by severity level |
list_by_source | read | List detections filtered by source type |
list_saved_queries | read | List all saved queries, optionally filtered by type. |
list_stories | read | List all analytic stories with pagination |
list_stories_by_category | read | List analytic stories by category (e.g., |
list_tables | read | List all dynamic tables created by the LLM, including pre-built analysis tables and their statistics. |
list_templates | read | List all saved query templates with their names, descriptions, and usage statistics. |
llm_enhanced_analysis | read | Request LLM-enhanced analysis of security detection data using MCP sampling. This tool leverages MCP sampling to request the client |
open_entity | read | Get complete information about a specific entity including all its relations and observations. This is the detailed view of a single knowledge node. |
priority_focus | read | Focus area: |
purple-team-exercise | read | Design a purple team exercise targeting specific tactics/techniques |
query_table | read | Query data from a dynamic table with optional filtering, sorting, and pagination. Filter examples: - Exact match: { |
ransomware-readiness-assessment | read | Comprehensive ransomware detection coverage assessment |
read_graph | read | Read the entire knowledge graph or a filtered subgraph. Returns entities, relations, and observations. Use this to: - Get an overview of all stored knowledge - Filter by entity type to focus on specific concepts - Understand the structure of captured tribal knowledge |
rebuild_index | destructive | Force re-index all detections and stories from configured paths. WARNING: This is a destructive operation that deletes the current index. |
run_template | write | Execute a saved query template with the provided parameters. Returns the query results. |
save_query | write | Save a query result for quick retrieval later. Useful for caching frequently needed data. |
save_template | write | Save a reusable query template with {{placeholders}}. Templates can contain SQL queries or tool-chain definitions for future execution. |
scope | read | MITRE tactic or technique ID |
search | read | Full-text search across all detection fields (name, description, query, MITRE IDs, tags, CVEs, analytic stories, process names, file paths, registry paths) |
search_detections | read | Search for security detections by keyword, technique ID, or description. Returns matching detection rules. |
search_knowledge | read | Search across all knowledge types: entities, relations, observations, decisions, and learnings. Uses full-text search to find relevant tribal knowledge. Search examples: - |
search_stories | read | Search analytic stories by narrative, description, or name. Stories provide rich context about threat campaigns and detection strategies. |
smart_compare | read | Compare detections across sources, tactics, or techniques for a given topic. Returns breakdown by source, tactic, and severity. |
soc-investigation-assist | read | Help investigate an alert with relevant detections and context |
source_comparisons | read | Store detection source comparison results (Sigma vs Splunk vs Elastic) |
sprint_capacity | read | Number of detections to target |
suggest_detection_template | read | Generate a detection template based on technique, learned patterns, and conventions. Returns YAML structure ready for customization. |
suggest_detections | read | Get detection suggestions for a specific technique. Returns existing detections, required data sources, and detection ideas. |
target_coverage | read | Specific tactic, technique, or |
technique_id | read | MITRE technique ID to review |
threat-landscape-sync | write | Sync detection priorities with current threat landscape |
threat_actor | read | APT group name (e.g., APT29, Lazarus Group, Volt Typhoon) |
threat_actor_profiles | read | Store threat actor research including TTPs, campaigns, and detection mappings |
threat_focus | read | Focus: |
Trust audit
BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
return yaml.load(content) as Record<string, unknown>;
return yaml.load(content) as Record<string, unknown>;
parsed = yaml.load(content);
private_key_path: process.env.ATTACK_RANGE_PRIVATE_KEY || '~/.ssh/id_rsa',
| Git credential access | Audit logs | Monitor `.git-credentials`, `~/.ssh/` access |
- Access to `process.env` collecting CI secrets
'T1567.002': true, // Exfiltration to Cloud Storage
'T9999.003': { name: 'SHEETCREEP GitHub Exfil', description: 'Document exfiltration to GitHub' },'exfiltration', 'impact'
'exfiltration': 9, 'impact': 14
'exfiltration', 'impact'
powershell.exe -NoProfile -Command "(New-Object Net.WebClient).DownloadString('http://127.0.0.1/test')"default: "http://127.0.0.1:8080/test.txt"
- `RUN curl ... | sh` patterns in Dockerfiles
delete_entity, delete_observation, delete_template, drop_table, rebuild_index
import { setConfig, loadConfig, resetConfig } from '../../config.js';import { createInitialState, createDetectionPipeline } from '../../graphs/detection-pipeline.js';import { setConfig, loadConfig, resetConfig } from '../../config.js';const { createInitialState } = await import('../../graphs/detection-pipeline.js');import { loadConfig, validateConfig } from '../../config.js';- No specific detection for 169.254.169.254 access patterns from containers
**Description:** Detects repeated queries to cloud metadata endpoints (169.254.169.254) from containers, indicating potential credential harvesting.
WHERE All_Traffic.dest_ip="169.254.169.254"
- Implement detection #3 for 169.254.169.254 access
Gates applied: no_behavioural_pass, no_license.
9d9365778ee7full audit observations/trust-audit/mcp-server/mhaggis__security-detections.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 9d9365778ee7 | BLOCK | F | 35 | first audit |
Questions
What is the Security Detections MCP server?
MCP to help Defenders Detection Engineer Harder and Smarter
What tools does Security Detections expose?
113 in total: 97 read-only, 11 that write, and 5 that can delete or overwrite (delete_entity, delete_observation, delete_template, drop_table, rebuild_index). Every one is listed on this page with its risk.
Is Security Detections safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (35/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Security Detections need?
It reads ANTHROPIC_API_KEY, ATTACK_RANGE_KEY_NAME, ATTACK_RANGE_PASSWORD, ATTACK_RANGE_PRIVATE_KEY, ENCRYPTION_KEY, NEXT_PUBLIC_SUPABASE_ANON_KEY, NEXT_PUBLIC_TURNSTILE_SITE_KEY, OPENROUTER_API_KEY, SUPABASE_SERVICE_ROLE_KEY and TURNSTILE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Security Detections run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as security-detections-web at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (9d9365778ee7), read on 2026-09-30. The repository is watched and re-audited when it changes.