# Suricata MCP

> Use this tool when you need to automate Suricata rule testing and validation, solving problems of manual rule verification and alert matching. It takes Suricata rules and pcap files as input and outputs validated rule syntax and alert matching results, streamlining the testing process. Ideal for use in network security and intrusion detection contexts where accurate rule configuration is critical.

Canonical page: https://skillsregistry.net/skills/fairyming-suricata-mcp  
JSON: https://api.skillsregistry.net/v1/skills/fairyming-suricata-mcp

## Description

An MCP server for validating Suricata rule syntax and testing rules against pcap files to verify alert matching. It automates the testing process by running Suricata and parsing generated alert logs to confirm signature IDs.

## Trust

- **Trust score (0–1):** 0.88
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** file-system
- **Updated:** 2026-09-28

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/fkcay561oq)
- **Repository:** <https://github.com/fairyming/suricata_mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "fairyming-suricata-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/fairyming-suricata-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/fairyming-suricata-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
