Security-Detections-MCP
Security detection search, coverage analysis, and adversary testing
All Skills in This Repository (15)
Pure Emerald Level IndicatorsCustom Atomics Deployment
Create, deploy, and execute custom Atomic Red Team YAML tests.
Atomic Red Team Testing
Execute and validate Atomic Red Team adversary emulation tests across SIEMs.
detection-test-engineer
Generate and execute security detection test scenarios across SIEM platforms.
Supply Chain Attack Analyst
Analyze software supply chain attacks and generate SIEM detection rules.
detection-coverage-analysis
Analyze security detection coverage against MITRE ATT&CK using Sigma, Splunk, and Elastic rules.
Data Source Mapper
Map MITRE ATT&CK techniques to data sources across SIEM schemas.
PR Extension Workflow
Analyze pull requests for security detection coverage gaps and recommend extensions.
detection-yaml-engineer
Generate and validate security detection rules for Splunk, Sigma, Elastic, and KQL.
detection-reviewer
Validate security detection rules in SPL, KQL, Sigma, and Elastic formats.
Test Environment Builder
Build adversary emulation lab environments across Splunk, Elastic Security, and Microsoft Sentinel.
cti-detection-engineer
Generate multi-SIEM detection logic from threat intelligence and MITRE ATT&CK mappings.
ATT&CK Navigator Layer Generator
Generate MITRE ATT&CK Navigator JSON layers for detection coverage and gap analysis.
Frequently Asked Questions
FAQPage SchemaHow to install Security-Detections-MCP?โผ
Run `npx skills add MHaggis/Security-Detections-MCP --all -g -y` in your terminal to install all skills in this suite globally.
What does Security-Detections-MCP do?โผ
It gives you a unified, searchable database of over 8,200 detection rules from Sigma, Splunk ESCU, Elastic, KQL, Sublime, and CrowdStrike, plus MITRE ATT&CK threat actor mappings and coverage analysis.
How to find detection coverage gaps?โผ
Use the coverage analysis skills to score your detections by tactic and technique, identify gaps against threat profiles like ransomware or APT groups, and export ATT&CK Navigator layers for visualization.
Can it help write and test new detection rules?โผ
Yes. It includes skills for authoring rules in Splunk YAML, Sigma, KQL, and Elastic TOML formats, plus Atomic Red Team testing workflows to validate that detections actually fire on real attack telemetry.
Does it work with Claude Code and Cursor?โผ
Yes. All skills follow the standard SKILL.md format and run in Claude Code, Cursor, and other compatible coding environments.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core