{"repo":"MHaggis/Security-Detections-MCP","free":true,"listed":false,"github":"https://github.com/MHaggis/Security-Detections-MCP","clone":"git clone https://github.com/MHaggis/Security-Detections-MCP.git","description":"MCP to help Defenders Detection Engineer Harder and Smarter","language":"TypeScript","stars":471,"topics":["detection-engineering","mcp"],"license":null,"category":"mcp-servers","readme_excerpt":"Security Detections MCP An MCP (Model Context Protocol) server that lets LLMs query a unified database of Sigma , Splunk ESCU , Elastic , KQL , Sublime , and CrowdStrike CQL security detection rules. New here? Start with the Setup Guide -- covers macOS, Windows (WSL & native), and Linux step by step. Want it hosted? Skip the install entirely: Hosted MCP Setup Guide Two Ways to Run It Local (full power) — the npm package you're looking at. Runs on your machine, indexes your own detection repos, exposes all 81 tools. You need Node.js and 10 minutes. Hosted (zero setup) — a Streamable HTTP server at detect.michaelhaag.org/api/mcp/mcp . Sign up, generate a token, paste one URL into your MCP client. 25 read-only tools, always in sync with the latest content, 200 calls/day free. Read on for quick-install buttons. Install — Local Claude Code (CLI one-liner): Claude Desktop — add to claude desktop config.json : OpenAI Codex (CLI): After install, configure env vars ( SIGMA PATHS , SPLUNK PATHS , etc.) to point at your detection repos. See the Setup Guide for full details. Install — Hosted (no setup, token required) 1. Create a token at detect.michaelhaag.org/account/tokens. Free tier: 200 calls/day, all read-only tools. 2. Click the button for your client — replace sdmcp YOUR TOKEN HERE in the resulting config with the token you just generated. Claude Code (CLI one-liner): Claude Desktop (via mcp-remote — Desktop doesn't speak remote HTTP natively yet): OpenAI Codex (CLI): See the Hos","default_branch":null,"files":null,"tree":[],"storefront":"/r/MHaggis","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/MHaggis/Security-Detections-MCP/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}