MCP server · Security
WRG Sigma Rules MCP server
by WRG-11
Draft, check and convert Sigma detection rules into Splunk, Elastic, Kibana or Wazuh queries from your chat.

This is a helper for people who write detection rules for security monitoring. It lets your AI assistant turn a plain description of suspicious activity into a Sigma rule, check that rule for mistakes, and translate it into the query language your security platform uses. It is handy if you work in a security operations centre and spend time writing or reviewing rules.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to a tool, and here that tool is a Sigma rule workbench. Once it is connected, your AI can draft a rule, validate it against pySigma and a linter, and convert it into Splunk, Elastic, Kibana or Wazuh queries when you ask. You do not need to know how the helper works inside; you just ask in normal words.
What this MCP server does
You describe the activity you want to detect, for example a suspicious command run by a known threat actor. Your AI sends that description to this helper, which builds a Sigma rule scaffold in YAML, a plain text format used for detection rules. You can then ask the helper to validate the rule, and it checks the syntax plus common best-practice issues. Finally you can ask it to convert the rule into a query for Splunk, Elastic, Kibana or Wazuh, and the helper hands back the converted query along with any warnings about what the conversion could not express.
Click to zoomWhat you can do with it
- Turn a plain description of suspicious activity into a Sigma rule draft
- Check a Sigma rule for syntax errors and common mistakes
- Convert a Sigma rule into a Splunk SPL query
- Convert a Sigma rule into an Elastic, Kibana or OpenSearch query
- Produce a Wazuh-targeted query with a warning that it reuses the Elasticsearch backend
- Look up the corpus coverage rollup by MITRE ATT&CK tactic and technique
- Read canonical detection pattern definitions from the corpus
Try asking your AI
- “Draft a Sigma rule for npm package installs that reach out to a known command and control domain”
- “Validate this Sigma rule and tell me what is wrong with it”
- “Convert this rule to Splunk SPL and to Elasticsearch Lucene”
- “Show me the ATT&CK coverage rollup from the corpus”
What it gives back to you
You get back text in the chat: a YAML rule draft, a validation report listing errors and warnings, or a converted query in the target language. Conversion results also include a note about correlation semantics, which tells you where the query stops meaning the same thing as the rule, for example a dropped time window. Coverage lookups return counts of rules per ATT&CK tactic and technique, with a fingerprint of the corpus bytes behind the count.
Before you start
What you need
- Python installed on your computer
- The Python packages listed in requirements.txt (pySigma and its backends)
- An MCP-capable client such as Claude Code, Codex or Cursor
Good to know
The rules it produces are starting points, not production-ready detections, and the Wazuh target is really an Elasticsearch query with a warning, so always review and test before relying on anything.
Install it with your AI
Add WRG Sigma Rules MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check WRG Sigma Rules MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Security analysts, detection engineers and SOC teams who write or review Sigma rules and want help drafting, checking and converting them.





