pulsemcp Safe content atomic mcp-remote

Security Detections

An MCP server that provides unified access to security detection rules from Sigma, Splunk ESCU, Elastic Detection Rules, and KQL query repositories. The implementation indexes detection rules into a searchable SQLite database with full-text search capabilities, automatically parsing YAML and TOML formats to extract MITRE ATT&CK mappings, CVE references, process names, and other metadata. Supports advanced filtering by MITRE tactics, severity levels, data sources, and process names, making it useful for security analysts building detection coverage maps, threat hunters researching specific attack techniques, or security engineers comparing detection approaches across different SIEM platforms.

Cognium trust score
50%
Tier
Unverified

Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.

View full trust & usage report →

Metadata

Version
1.0.0
Skill type
atomic
Execution layer
mcp-remote
Category
database
Source
PulseMCP
Author type
human
Updated
2026-04-29
View source Find related skills

Use via MCP

MCP

Resolve Security Detections from your agent

Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.

One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.

claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Swap --scope user for --scope project to commit it to .mcp.json.

Search SkillsRegistry