Complete AI Training

MCP server · Security

WRG Sigma Rules MCP server

by WRG-11

Draft, check and convert Sigma detection rules into Splunk, Elastic, Kibana or Wazuh queries from your chat.

Flow diagram: you ask your AI “Turn this suspicious activity into a detection rule”, the WRG Sigma Rules MCP server works in steps: draft the rule, then check the rule, then convert the rule, and you get back A rule, a report or a query.

This is a helper for people who write detection rules for security monitoring. It lets your AI assistant turn a plain description of suspicious activity into a Sigma rule, check that rule for mistakes, and translate it into the query language your security platform uses. It is handy if you work in a security operations centre and spend time writing or reviewing rules.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to a tool, and here that tool is a Sigma rule workbench. Once it is connected, your AI can draft a rule, validate it against pySigma and a linter, and convert it into Splunk, Elastic, Kibana or Wazuh queries when you ask. You do not need to know how the helper works inside; you just ask in normal words.

What this MCP server does

You describe the activity you want to detect, for example a suspicious command run by a known threat actor. Your AI sends that description to this helper, which builds a Sigma rule scaffold in YAML, a plain text format used for detection rules. You can then ask the helper to validate the rule, and it checks the syntax plus common best-practice issues. Finally you can ask it to convert the rule into a query for Splunk, Elastic, Kibana or Wazuh, and the helper hands back the converted query along with any warnings about what the conversion could not express.

Flow diagram: you ask your AI “Turn this suspicious activity into a detection rule”, the WRG Sigma Rules MCP server works in steps: draft the rule, then check the rule, then convert the rule, and you get back A rule, a report or a query. Click to zoom

What you can do with it

  • Turn a plain description of suspicious activity into a Sigma rule draft
  • Check a Sigma rule for syntax errors and common mistakes
  • Convert a Sigma rule into a Splunk SPL query
  • Convert a Sigma rule into an Elastic, Kibana or OpenSearch query
  • Produce a Wazuh-targeted query with a warning that it reuses the Elasticsearch backend
  • Look up the corpus coverage rollup by MITRE ATT&CK tactic and technique
  • Read canonical detection pattern definitions from the corpus

Try asking your AI

  • “Draft a Sigma rule for npm package installs that reach out to a known command and control domain”
  • “Validate this Sigma rule and tell me what is wrong with it”
  • “Convert this rule to Splunk SPL and to Elasticsearch Lucene”
  • “Show me the ATT&CK coverage rollup from the corpus”

What it gives back to you

You get back text in the chat: a YAML rule draft, a validation report listing errors and warnings, or a converted query in the target language. Conversion results also include a note about correlation semantics, which tells you where the query stops meaning the same thing as the rule, for example a dropped time window. Coverage lookups return counts of rules per ATT&CK tactic and technique, with a fingerprint of the corpus bytes behind the count.

Before you start

What you need

  • Python installed on your computer
  • The Python packages listed in requirements.txt (pySigma and its backends)
  • An MCP-capable client such as Claude Code, Codex or Cursor

Good to know

The rules it produces are starting points, not production-ready detections, and the Wazuh target is really an Elasticsearch query with a warning, so always review and test before relying on anything.

Install it with your AI

Add WRG Sigma Rules MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check WRG Sigma Rules MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Security analysts, detection engineers and SOC teams who write or review Sigma rules and want help drafting, checking and converting them.