Enables querying and analysis of a unified database of security detection rules across multiple formats, including Sigma, Splunk, Elastic, KQL, and CrowdStrike CQL.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEYATTACK_RANGE_IP_WHITELISTATTACK_RANGE_KEY_NAMEATTACK_RANGE_PASSWORDATTACK_RANGE_PRIVATE_KEYATTACK_STIX_PATH— Path to enterprise-attack.json for threat actor data (optional)AWS_REGIONCQL_HUB_PATHS— CQL Hub (CrowdStrike) query directoriesDETECTIONS_DB_PATHDRY_RUNELASTIC_PATHS— Elastic detection rule directoriesENCRYPTION_KEYJAMF_PROTECT_PATHS— Jamf Protect custom analytic detection directories (macOS)KQL_PATHS— KQL hunting query directoriesNEXT_PUBLIC_APP_URLNEXT_PUBLIC_SUPABASE_ANON_KEYNEXT_PUBLIC_SUPABASE_URLNEXT_PUBLIC_TURNSTILE_SITE_KEYOPENROUTER_API_KEYSIEM_PLATFORMSIGMA_PATHS— After install, configure env vars (, SPLUNK_PATHS, etc.) to point at your detection repos. See the [Setup Guide](./SETUP.md) for full details.SLACK_WEBHOOK_URLSPLUNK_MCP_ENABLEDSPLUNK_PATHS— After install, configure env vars (SIGMA_PATHS, , etc.) to point at your detection repos. See the [Setup Guide](./SETUP.md) for full details.STORY_PATHS— Splunk analytic story directories (optional)SUBLIME_PATHS— Sublime Security rule directoriesSUPABASE_SERVICE_ROLE_KEYSYNC_SOURCE_TYPETURNSTILE_SECRET_KEY[](https://m8ven.ai/mcp/mhaggis-security-detections-mcp-silmwh)