mcp-hayabusa

mcp-hayabusa

Enables scanning Windows EVTX event log files with Hayabusa, returning structured detection results through an MCP tool.

Category
访问服务器

README

mcp-hayabusa

An MCP server that wraps Hayabusa for EVTX (Windows event log) analysis, exposing scan_evtx and get_hayabusa_rules tools to Claude.

Setup

  1. Install dependencies:

    pip install -r requirements.txt
    
  2. Download the Hayabusa binary and Sigma rules into ./hayabusa/:

    python download_hayabusa.py
    

    This fetches the latest release for your OS/architecture and extracts it to ./hayabusa/ (binary at ./hayabusa/hayabusa.exe on Windows or ./hayabusa/hayabusa elsewhere, plus rules/ and rules/config/).

  3. Keep the ruleset current (recommended before each scanning session):

    ./hayabusa/hayabusa.exe update-rules      # Windows
    ./hayabusa/hayabusa update-rules          # Linux/macOS
    

Running the server

python server.py

This starts the MCP server over stdio. Point an MCP client at it, e.g. in Claude Desktop's config:

{
  "mcpServers": {
    "hayabusa": {
      "command": "python",
      "args": ["C:\\path\\to\\mcp-hayabusa\\server.py"]
    }
  }
}

Tool: scan_evtx

Scans an EVTX file (or a directory of EVTX files) with Hayabusa and returns detections as structured JSON.

Parameters:

  • evtx_path (string, required) — path to a .evtx file or a directory containing them
  • min_severity (string, optional, default "informational") — minimum severity to include: informational, low, medium, high, critical
  • rule_filter (string, optional) — case-insensitive substring match against each detection's rule title (e.g. "lateral" or "mimikatz"); only matching detections are returned. Hayabusa has no native rule-title filter, so this is applied after the scan.
  • output_format (string, optional, default "summary") — "summary" returns condensed detections (Timestamp, RuleTitle, Level, Computer, Channel, EventID, RecordID); "full" includes the complete Details/ExtraFieldInfo payload for each detection
  • max_results (integer, optional) — caps the number of detections returned, applied after rule_filter

Returns:

{
  "evtx_path": "...",
  "min_severity": "...",
  "rule_filter": "...",
  "output_format": "...",
  "total_count": 68,
  "count": 42,
  "truncated": false,
  "detections": [ { "Timestamp": "...", "RuleTitle": "...", "Level": "...", "...": "..." } ]
}

total_count is the number of matching detections before max_results is applied; count is the number actually returned; truncated is true if max_results cut off results.

On failure (missing file, missing Hayabusa binary, invalid min_severity/output_format/max_results, scan timeout, or a Hayabusa scan error), it returns {"error": "..."} instead of raising.

Tool: get_hayabusa_rules

Lists available Hayabusa/Sigma detection rules from ./hayabusa/rules/, optionally filtered by keyword. Useful for seeing what detections exist before scanning, or for finding a good rule_filter value for scan_evtx. Hayabusa has no built-in rule-listing command, so this reads and parses the rule YAML files directly.

Parameters:

  • keyword (string, optional) — case-insensitive substring matched against each rule's title, description, tags, and id. If omitted, all rules are listed (subject to max_results)
  • max_results (integer, optional, default 100) — caps the number of rules returned

Returns:

{
  "keyword": "...",
  "total_count": 66,
  "count": 66,
  "truncated": false,
  "rules": [
    {
      "id": "...",
      "title": "...",
      "level": "...",
      "status": "...",
      "description": "...",
      "logsource": { "product": "windows", "service": "..." },
      "tags": ["attack.lateral-movement", "..."],
      "file": "hayabusa\\builtin\\System\\Sys_7045_Med_LateralMovement-PSEXEC.yml"
    }
  ]
}

total_count is the number of matching rules before max_results is applied; count is the number actually returned; truncated is true if max_results cut off results.

A keyword search checks a raw-text prefilter before parsing each rule's YAML, so it typically runs in ~1-2 seconds. Listing all ~5,000 rules with no keyword takes several seconds longer since every rule file must be parsed.

On failure (missing rules directory or invalid max_results), it returns {"error": "..."} instead of raising.

Requirements

  • Python with the mcp and pyyaml libraries (see requirements.txt)
  • The Hayabusa CLI, installed via download_hayabusa.py

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选
mcp-server-qdrant

mcp-server-qdrant

这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。

官方
精选
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选