RSigma: write, lint and test Sigma rules with an agent
A Rust toolchain for Sigma detection rules with a built-in MCP server: agents parse and lint rules, test them on real events and convert them to SIEM queries.
Project and installation docs
View projecthttps://github.com/timescale/rsigma
The hard part of detection rules isn’t YAML syntax but verification: does the rule match the sample logs, where do false positives come from, does the meaning survive conversion to Splunk or Elastic queries? Ask a model for a Sigma rule and you may get one that looks right and matches nothing. RSigma is a Sigma toolchain written in Rust with a built-in MCP server, so an agent can parse, lint and test a rule against events right after writing it, with results returned as JSON. Timescale maintains it, and it had about 160 stars as of 2026-10-06.
What it does
- Parse and lint:
parse_ruleturns a rule into a structured form,lint_rulesapplies 90 checks derived from the Sigma v2.1.0 specification, andvalidate_rulesvalidates a rule set. - Test on events:
evaluate_eventsruns rules over a batch of log events and shows what matched; the CLI’sengine explainsays why something didn’t. - Convert:
convert_rulesproduces native queries for a target backend, andlist_fieldslists the fields rules use. - Many log formats: JSON, syslog, logfmt, CEF, Windows EVTX, plain text and OTLP, auto-detected by default.
- Runtime tools: point
--daemon-urlat a running RSigma daemon to add operations-stage tools.
Who it’s for
- Detection engineers maintaining Sigma rule sets who want an agent to draft rules and test them automatically.
- SOC analysts who need the same rule translated for several SIEMs.
Setup
Download a prebuilt binary from GitHub Releases or install with Cargo, then start the MCP server over stdio against your rules directory:
cargo install --locked rsigma
rsigma mcp serve --rules-dir rules/
Register that command as an MCP server in your client; see the MCP server guide.
Our take
Detection engineering is an easily overlooked corner of security tooling. Most security servers face attack surface or code; RSigma serves defenders who write and test rules every day. Behind the MCP server is a full toolchain, with parser, evaluation engine, converter and LSP sharing one intermediate representation, not a quick script wrapper. Its tools analyze rather than change anything, so your SIEM stays untouched. Note that MCP is one component of a project that’s really a standalone detection engine, so expect to spend time on its processing pipeline configuration. The project was created in February 2026 and its community is still small. Licensed MIT.