Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Wrg Sigma Rules
Wrg Sigma Rules logo
Health: ActiveRecent health check succeeded.Last checked 9/11/2026, 5:03:08 PM

Wrg Sigma Rules

User RatingsBe the first to rate and review this MCP server!
View Repository2 GitHub StarsTotal stargazers on GitHub for the source repository (2 stars).Visit Website
sigmasecuritydetection-engineeringsiemmitre-attack

MCP tools for drafting, validating, and converting Sigma detection rules across five SIEM query formats.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "wrg-11-wrg-sigma-rules": {
      "command": "uvx",
      "args": [
        "pysigma"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (3) Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

WRG Sigma Rules provides three MCP tools for creating Sigma YAML scaffolds from natural-language descriptions, checking rules, and converting them into backend-specific queries. Use it for detection engineering workflows involving Splunk, Elastic, OpenSearch, Wazuh, or Kibana. It also includes a 101-rule corpus covering 14 MITRE ATT&CK tactic categories.

Use cases

โ€ขDraft Sigma rule YAML from a detection description
โ€ขValidate Sigma schema, pySigma compatibility, and rule quality
โ€ขConvert Sigma rules into SIEM-specific queries
โ€ขReview detection coverage against MITRE ATT&CK tactics
โ€ขAdapt rules to log sources such as Sysmon

Key features

โ€ขNatural-language to Sigma YAML scaffolding
โ€ขYAML schema and pySigma compatibility validation
โ€ขBest-practice rule linting
โ€ขSplunk SPL conversion
โ€ขElastic, Kibana, OpenSearch, and Wazuh conversion
โ€ข101-rule corpus across 14 ATT&CK tactic categories

Capabilities & Tool Schemas (3) ~77 tokensApproximate context cost of this serverโ€™s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server โ€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by Wrg Sigma Rules.

mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__draft_rule

NL description โ†’ sigma YAML scaffold

mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__validate_rule

YAML schema + pySigma compat + best-practice linter

mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__convert_rule

sigma โ†’ Splunk/Elastic/OpenSearch/Wazuh/Kibana query

Documentation Overview

WRG Sigma Rules

tests release last commit sigma rules license python 3.12+

Sigma detection-rule authoring, validation and multi-backend conversion, delivered as a Model Context Protocol (MCP) server with a published rule corpus. It runs under Claude Code, Codex, Cursor and any MCP-capable client.

What it does

  • Three MCP tools. draft_rule turns a natural-language description into a Sigma YAML scaffold. validate_rule checks a rule against pySigma plus a best-practice linter. convert_rule compiles a rule to a Splunk, Elastic, OpenSearch, Wazuh or Kibana query.
  • Three Claude Code skills: sigma-rule-writer, sigma-rule-reviewer and threat-coverage-gap-analyzer.
  • A published corpus of 296 rules across 14 MITRE ATT&CK tactic categories. Every rule carries an honest Sigma status: (see Rule status).
  • Multi-backend conversion on pySigma 1.x: Splunk SPL, Elastic and Kibana Lucene, OpenSearch Lucene and PPL, plus Wazuh. The Lucene-family targets cannot express Sigma correlation rules, so convert_rule reports the 52 correlation rules in the corpus as a capability gap and names the backends that can convert them.

The plugin is installed directly from this repository; it is not yet listed in a plugin marketplace.

Install

The server is a single stdio MCP process (server.py). Each client points at it in its own way.

Claude Code

bash
git clone https://github.com/WRG-11/wrg-sigma-rules.git
cd wrg-sigma-rules
pip install -r requirements.txt
claude plugin validate .

requirements.txt is not optional: validate_rule needs pySigma, convert_rule needs the backend packages, and the pipeline packages drive the logsource mapping. The repo ships .claude-plugin/plugin.json and .mcp.json (which wires server.py through ${CLAUDE_PLUGIN_ROOT}). Point your Claude Code plugin configuration at this checkout per the plugin docs.

Codex

bash
codex plugin marketplace add .
codex plugin add wrg-sigma-rules@wrg-11

The Codex plugin carries a self-contained runtime snapshot of the server and corpus, so its installed cache does not rely on checkout-relative paths. Keep it current with python scripts/sync_codex_runtime.py; CI fails if it drifts.

Cursor

Cursor speaks MCP directly, so the same server works with no plugin manifest. Add it to your project .cursor/mcp.json (or the global ~/.cursor/mcp.json):

config.json
{
  "mcpServers": {
    "wrg-sigma-rules": {
      "command": "python",
      "args": ["/path/to/wrg-sigma-rules/server.py"],
      "cwd": "/path/to/wrg-sigma-rules",
      "env": { "PYTHONPATH": "/path/to/wrg-sigma-rules" }
    }
  }
}

Replace the path with your clone, then reload Cursor's MCP servers.

Any MCP client

server.py is a standard stdio MCP server, so Cline, Continue, Zed and Windsurf load it with the same mcpServers block shown for Cursor. MCP is model-agnostic: the client's backend model does not change what the server exposes.

Quick example

Validate and convert a corpus rule end to end, from the repo root:

Terminal
pip install pysigma pysigma-backend-splunk pysigma-backend-elasticsearch
server.ts
import sys, json
sys.path.insert(0, '.')
from tools.validate_rule.validate_rule import validate_rule_body
from tools.convert_rule.convert_rule import convert_rule_body

rule = open('resources/examples/command_and_control/observed_mini_shai_hulud_npm_supply_chain_c2_t1071.yml', encoding='utf-8').read()

print(json.dumps(validate_rule_body(rule), indent=2))
print(json.dumps(convert_rule_body(rule, target='splunk'), indent=2))
print(json.dumps(convert_rule_body(rule, target='elasticsearch'), indent=2))

Full captured output (validate JSON, Splunk SPL, Elasticsearch Lucene) is in DEMO.md.

The corpus

Every rule lives under resources/examples/<tactic>/ and is one of two kinds:

  • template_*: a canonical detection shape to adapt to your own environment.
  • observed_*: derived from a specific, cited incident. CONTRIBUTING.md sets the bar these must clear.

resources/examples/INDEX.json enumerates every rule, and the wrg-sigma://coverage/mitre-attack-matrix resource computes the technique-by-tactic breakdown from the corpus at read time. Some rules add a prose write-up under docs/detection-notes/.

Rule status

This corpus uses Sigma's status: field literally rather than aspirationally:

status:CountMeaning here
test82Derived from a real, cited incident (the observed_* rules)
experimental214Canonical detection shapes, many self-described as synthetic exemplars
stable0Unused, deliberately

stable in the Sigma specification means a rule runs in production and is well tested. Nothing here has earned that, so nothing claims it. Treat every rule as a starting point to bind to your own logsource and tune; each rule's falsepositives: block names the benign activity to expect first.

Resources

  • wrg-sigma://patterns/canonical-5 and wrg-sigma://patterns/canonical-5/{01..05}: canonical detection-pattern definitions.
  • wrg-sigma://coverage/mitre-attack-matrix: an ATT&CK coverage rollup computed from the corpus at read time.

Quality and testing

  • 22 Python test modules cover rule validation and tool-integration smoke tests.
  • pySigma 1.x compatibility is verified against the Splunk, Elasticsearch and OpenSearch backend packages.
  • CI runs the full suite on Ubuntu, Windows and macOS runners on every push.
  • README counts are stamped from ground truth: python readme_stamp.py --check fails CI on any drift, so the numbers here cannot silently go stale.

Contributing

Contributions are welcome. Add YAML under resources/examples/<tactic>/ with an ATT&CK mapping in tags: (for example attack.t1071), the observed_* or template_* prefix, and a passing validate_rule. Corpus CI rejects broad empty matches, unsafe regex, unroutable logsource blocks, draft scaffolding and deprecated aggregation-pipe syntax.

Read CONTRIBUTING.md before submitting an observed_* rule. It sets the sourcing bar (attribution, platform and manifestation, each matched against the cited source) and documents the three upstream rejections that produced it.

License

MIT; see LICENSE. One license covers both the tooling (server.py, tools/, scripts/) and the corpus (resources/). That is a deliberate choice for frictionless reuse by SOC teams adapting a rule into their own tooling, over the attribution-preserving split that some Sigma corpora use.

Runtime dependencies bring in LGPL-2.1/3.0 packages (pySigma and its backends) alongside MIT, BSD and Apache ones. Importing an LGPL library does not make this repo's own code LGPL. The dependency-licenses CI job carries the re-derivable list.

Part of the WRG-11 ecosystem

  • mcp-objauthz-lab: a vulnerable-by-design MCP server for learning BOLA and IDOR.
  • osint-trust-envelope: honest trust envelopes for OSINT results.

Full index at github.com/WRG-11.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Rsigma logoRsigma

    Exposes the RSigma Sigma detection-engineering toolkit to AI agents over stdio or Streamable HTTP with rsigma mcp serve. Tools to author, lint, validate, and convert Sigma detection rules, evaluate and explain detections against log events, and inspect correlation state, all backed by a native Rust engine.

    ๐Ÿ”’ Security4 views
    Compare vs Rsigma โ†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    ๐Ÿ”’ Security3 views
    Compare vs Jadx AI MCP โ†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    ๐Ÿ”’ Security3 views
    Compare vs Apktool MCP Server โ†’
  • MCP Maigret logoMCP Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    ๐Ÿ”’ Security4 views
    Compare vs MCP Maigret โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
2
Stargazers on the source repository.
Last commit
1mo ago
Most recent push to the default branch.
Tools exposed
3
Callable tools this server registers over MCP.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Wrg Sigma Rules

It exposes draft_rule, validate_rule, and convert_rule for Sigma rule drafting, validation, and conversion.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewWrg Sigma Rules AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/wrg-11-wrg-sigma-rules?style=directory)](https://allmcps.com/mcp/wrg-11-wrg-sigma-rules)
HTML Embed
<a href="https://allmcps.com/mcp/wrg-11-wrg-sigma-rules"><img src="https://allmcps.com/api/badge/wrg-11-wrg-sigma-rules?style=directory" alt="Wrg Sigma Rules on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
PricingFree
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
AuthNo auth required
Last updatedAug 9, 2026
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars2
GitHub Star CountTotal stargazers on GitHub representing community popularity (2 stars).
Last commit1mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 6, 2026
55Quality signal: Good ยท 55/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools28/30
Adoption & activity3/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 22d ago via OSV.dev ยท pysigma (PyPI)

โ˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server โ†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Wrg Sigma Rules โ†’Install in Claude DesktopInstall in CursorInstall in VS Code