SigmaLineage MCP

SigmaLineage MCP

Enables context-aware EVTX hunting with process lineage tracing and rarity baselining to surface real threats from security logs, transforming raw alerts into actionable kill chain intelligence.

Category
访问服务器

README

<div align="center">

⚔️ SigmaLineage MCP

Context-Aware EVTX Hunting · Lineage-First Triage · Zero Noise Tolerance

Python FastMCP Chainsaw Sigma


"A Sigma hit means nothing without its story. The process lineage chain is the story."

</div>


🎯 Why SigmaLineage?

EVTX triage in modern SOCs is a race against noise. You have millions of events, hundreds of alerts, and seconds to decide what's real.

<table> <tr> <td width="50%" valign="top">

🔍 For the SOC Analyst

Generic alerts drown true incidents in false positives. You don't need more alerts — you need signal from noise.

SigmaLineage's rarity baseline engine automatically surfaces:

  • 🚨 Anomalous process-to-port connections
  • 👤 Suspicious user-log event signatures
  • 🌐 Weird URL lookups no one else made

Find the real threat. Fast.

</td> <td width="50%" valign="top">

🧬 For the Detection Engineer

A Sigma rule fires. But is it a sysadmin doing their job, or an attacker moving laterally?

The process lineage chain is our core moat.

SigmaLineage traces the full parent→child execution tree — up to 5+ generations — turning isolated alerts into a visual kill chain. You instantly see:

  • Was this cmd.exe spawned by services.exe or w3wp.exe?
  • Is rundll32 being launched from ProgramData?
  • Did WmiPrvSE.exe just spawn a reverse shell?

Stop chasing ghosts. Confirm the kill chain.

</td> </tr> </table>


🧠 By combining rapid Sigma matching, automated lineage graphing, and multi-dimensional rarity baselining, SigmaLineage MCP transforms raw EVTX logs into actionable, context-rich intelligence — for AI agents and human analysts alike.


🔧 Built On

Component Role
src/sigmalineage_mcp/mappings/sigma-event-logs-all.yml Chainsaw field-mapping definition
sigma_lineage.py Process lineage runner script
src/sigmalineage_mcp/ FastMCP server orchestration

Tool Overview

1) run_sigma

Runs the Chainsaw Sigma hunt command and returns a summary of rule hits.

Inputs:

  • evtx_path (file or folder of logs to scan)
  • sigma_rules_path (directory containing Sigma rules)
  • mapping_path (Chainsaw mapping yaml, defaults to src/sigmalineage_mcp/mappings/sigma-event-logs-all.yml)
  • output_dir (directory where hunt.json is written)

Output Highlights:

  • hunt_json_path
  • hit_count
  • top_rules
  • top_source_files

2) run_sigma_lineage

Runs the Sigma hunt (or loads existing results) and traces the parent/child process lineage for hit processes.

Inputs:

  • All run_sigma inputs
  • levels (number of ancestor levels to trace, default 5)
  • skip_hunt (skip running Chainsaw hunt, loading existing hunt.json instead, default false)

Output Highlights:

  • hunt_json_path
  • process_lineage_json_path
  • process_lineage_md_path
  • sigma_hit_count
  • indexed_evtx_files
  • indexed_events

Example Lineage Highlights Output: Lineage Highlights


3) rare_events_baseline

Computes rare tuple combinations from parsed CSV event logs with baseline comparison to highlight anomalies.

Inputs:

  • target_csv_path (CSV file or folder to analyze)
  • baseline_csv_path (optional, defaults to target scope itself)
  • max_results (default 25)
  • max_baseline_count (filter threshold for baseline occurrence, default 2)

Tuple Families Analyzed:

  • process_dst_port_protocol: Maps unique combinations of process name, destination port, and protocol.
  • user_channel_event_id: Maps unique combinations of user, log channel, and event ID.
  • url_host_process: Maps unique combinations of accessed URL/domain, host computer, and initiating process name.

Example Rarity Baseline Analysis Output: Rarity Analysis


Folder Structure

sigmalineage-mcp/
  sigma_lineage.py            # Lineage tracer CLI script
  pyproject.toml              # Project configuration & dependencies
  README.md                   # This file
  src/
    sigmalineage_mcp/
      __init__.py
      __main__.py             # Standard script entrypoint
      config.py               # Paths configuration
      server.py               # FastMCP server orchestration
      mappings/
        sigma-event-logs-all.yml  # Chainsaw mapping file
      services/
        chainsaw_runner.py    # Subprocess runner for Chainsaw
        lineage_runner.py     # Subprocess runner for lineage tracer
        rarity.py             # Pure Python CSV rarity baseline engine

Installation

Prerequisites

  1. Chainsaw CLI: Ensure chainsaw is installed and available in your PATH (e.g. at ~/.local/bin/chainsaw).
  2. Python: Python 3.10+ is required.

Setup

From the repository root:

uv sync

Running the Server

Direct Execution

Start the FastMCP stdio server:

uv run sigmalineage-mcp

MCP Client Configurations

To wire this MCP server into different AI clients, use the standard JSON configuration snippet below, placing it in the tool-specific configuration file location.

Standard JSON Snippet

{
  "mcpServers": {
    "sigmalineage-mcp": {
      "command": "uv",
      "args": [
        "run",
        "--project",
        "/absolute/path/to/sigmalineage_mcp",
        "sigmalineage-mcp"
      ],
      "env": {
        "SIGMALINEAGE_PROJECT_ROOT": "/absolute/path/to/sigmalineage_mcp"
      }
    }
  }
}

Note: Replace /absolute/path/to/sigmalineage_mcp with the actual path where this repository is cloned on your system.

Client Configuration File Paths

  • Cursor: Add to the Cursor GUI settings panel (Settings -> Features -> MCP) or edit ~/.cursor/mcp.json (Linux/macOS) or %USERPROFILE%\.cursor\config\mcp.json (Windows).
  • Antigravity: Add to the mcp_config.json configuration file located at ~/.gemini/antigravity/mcp_config.json.
  • OpenCode: Add to ~/.config/opencode/opencode.json (Linux/macOS) or a project-level opencode.json file in the root of the repository.
  • Claude Desktop: Add to the global configuration file:
    • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
    • Windows: %APPDATA%\Claude\claude_desktop_config.json
    • Linux: ~/.config/Claude/claude_desktop_config.json

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选
mcp-server-qdrant

mcp-server-qdrant

这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。

官方
精选
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选