# Security Detections

> Use this tool when you need to unify and search security detection rules from multiple repositories, such as Sigma, Splunk ESCU, and Elastic Detection Rules. It solves problems like building detection coverage maps, researching attack techniques, and comparing detection approaches across SIEM platforms. The tool takes in detection rules in YAML and TOML formats and outputs searchable metadata, including MITRE ATT&CK mappings and CVE references, with advanced filtering capabilities.

Canonical page: https://skillsregistry.net/skills/mhaggis-security-detections  
JSON: https://api.skillsregistry.net/v1/skills/mhaggis-security-detections

## Description

An MCP server that provides unified access to security detection rules from Sigma, Splunk ESCU, Elastic Detection Rules, and KQL query repositories. The implementation indexes detection rules into a searchable SQLite database with full-text search capabilities, automatically parsing YAML and TOML formats to extract MITRE ATT&CK mappings, CVE references, process names, and other metadata. Supports advanced filtering by MITRE tactics, severity levels, data sources, and process names, making it useful for security analysts building detection coverage maps, threat hunters researching specific attack techniques, or security engineers comparing detection approaches across different SIEM platforms.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-29

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/mhaggis-security-detections)
- **Repository:** <https://github.com/mhaggis/security-detections-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "mhaggis-security-detections"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/mhaggis-security-detections` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/mhaggis-security-detections/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
