一个 MCP(Model Context Protocol)服务器,让 LLM 查询 Sigma、Splunk ESCU、Elastic、KQL、Sublime 和 CrowdStrike CQL 安全检测规则的统一数据库。
初次使用?从设置指南开始——涵盖 macOS、Windows(WSL 和原生)和 Linux 的逐步说明。
想要托管版本?完全跳过安装:托管 MCP 设置指南
本地版(全功能)——就是你看到的这个 npm 包。在你自己的机器上运行,索引你自己的检测仓库,暴露所有 81 个工具。需要 Node.js 和大约 10 分钟。
托管版(零设置)——位于 detect.michaelhaag.org/api/mcp/mcp 的 Streamable HTTP 服务器。注册账号,生成令牌,将 URL 粘贴到你的 MCP 客户端中。约 25 个只读工具,始终与最新内容同步,每天免费 200 次调用。继续阅读获取快速安装按钮。
Claude Code(CLI 单行命令):
claude mcp add security-detections -- npx -y security-detections-mcp
Claude Desktop——添加到 claude_desktop_config.json:
{
"mcpServers": {
"security-detections": {
"command": "npx",
"args": ["-y", "security-detections-mcp"]
}
}
}
OpenAI Codex(CLI):
codex mcp add security-detections -- npx -y security-detections-mcp
安装后,配置环境变量(
SIGMA_PATHS、SPLUNK_PATHS等)指向你的检测仓库。详见设置指南。
sdmcp_YOUR_TOKEN_HERE 替换为你刚刚生成的令牌。Claude Code(CLI 单行命令):
claude mcp add --transport http security-detections https://detect.michaelhaag.org/api/mcp/mcp --header "Authorization: Bearer sdmcp_YOUR_TOKEN_HERE"
Claude Desktop(通过 mcp-remote —— Desktop 尚不支持原生远程 HTTP):
{
"mcpServers": {
"security-detections": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://detect.michaelhaag.org/api/mcp/mcp",
"--header",
"Authorization: Bearer sdmcp_YOUR_TOKEN_HERE"
]
}
}
}
OpenAI Codex(CLI):
export SDMCP_TOKEN="sdmcp_YOUR_TOKEN_HERE" && codex mcp add security-detections --url https://detect.michaelhaag.org/api/mcp/mcp --bearer-token-env-var SDMCP_TOKEN
查看托管 MCP 设置指南获取完整客户端表格、全部工具清单和故障排除提示。
Web 聊天支持免费、专业/管理员和 BYOK(自带密钥)路由。你也可以在聊天界面顶部看到当前激活的模型。
nvidia/nemotron-3-super-120b-a12b:freenvidia/nemotron-3-super-120b-a12b:freenousresearch/hermes-3-llama-3.1-405b:freemeta-llama/llama-3.3-70b-instruct:freeopenai/gpt-oss-120b:free使用应用管理的 OpenRouter 路由,依据你在 /account 中的首选模型设置:
| 首选模型 | 路由模型 |
|---|---|
auto | 免费模型池(默认:nvidia/nemotron-3-super-120b-a12b:free) |
claude | anthropic/claude-sonnet-4-6 |
claude-opus | anthropic/claude-opus-4-6 |
gpt | openai/gpt-5.4 |
gpt-codex | openai/gpt-5.3-codex |
如果你设置了自定义 API 密钥,路由优先级如下:
sk-ant-...) -> 通过 Anthropic 使用 claude-sonnet-4-6-20250514sk-...) -> 通过 OpenAI 使用 gpt-5.4sk-or-...) -> 使用上面的首选模型映射表如果存在多个密钥,则按此顺序使用第一个匹配项。
npx -y security-detections-mcp
或者克隆并构建:git clone https://github.com/MHaggis/Security-Detections-MCP.git && cd Security-Detections-MCP && npm install && npm run build
配置环境变量指向你的检测仓库:
| 变量 | 描述 |
|---|---|
SIGMA_PATHS | Sigma 规则目录 |
SPLUNK_PATHS | Splunk ESCU 检测目录 |
ELASTIC_PATHS | Elastic 检测规则目录 |
KQL_PATHS | KQL 狩猎查询目录 |
SUBLIME_PATHS | Sublime Security 规则目录 |
CQL_HUB_PATHS | CQL Hub(CrowdStrike)查询目录 |
JAMF_PROTECT_PATHS | Jamf Protect 自定义分析检测目录(macOS) |
STORY_PATHS | Splunk 分析故事目录(可选) |
ATTACK_STIX_PATH | enterprise-attack.json 的路径,用于威胁行为者数据(可选) |
查看设置指南获取每个客户端的完整配置示例(Cursor、VS Code、Claude Desktop、WSL)。
使用稀疏检出下载所有源(仅规则,非完整仓库):