
This is essentially a unified API for security detection rules across six major platforms, giving you programmatic access to 8,200+ detections from Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike. The real utility is in the MITRE ATT&CK integration: you can query coverage by technique, identify gaps for specific threat actors like APT29, and generate ATT&CK Navigator layers showing where your detections actually exist. It comes with 81 tools for local use or around 25 if you use the hosted version, which offers a free tier with 200 calls per day. Most useful when you're doing threat modeling, need to answer "do we detect this technique" questions quickly, or building detection coverage reports without manually parsing YAML files across multiple repositories.
npx -y skills add aradotso/security-skills --skill security-detections-mcp --agent claude-codeInstalls into .claude/skills of the current project.
Select a file.