Security

RSigma: write, lint and test Sigma rules with an agent

A Rust toolchain for Sigma detection rules with a built-in MCP server: agents parse and lint rules, test them on real events and convert them to SIEM queries.

Project and installation docs

View project

https://github.com/timescale/rsigma

The hard part of detection rules isn’t YAML syntax but verification: does the rule match the sample logs, where do false positives come from, does the meaning survive conversion to Splunk or Elastic queries? Ask a model for a Sigma rule and you may get one that looks right and matches nothing. RSigma is a Sigma toolchain written in Rust with a built-in MCP server, so an agent can parse, lint and test a rule against events right after writing it, with results returned as JSON. Timescale maintains it, and it had about 160 stars as of 2026-10-06.

What it does

  • Parse and lint: parse_rule turns a rule into a structured form, lint_rules applies 90 checks derived from the Sigma v2.1.0 specification, and validate_rules validates a rule set.
  • Test on events: evaluate_events runs rules over a batch of log events and shows what matched; the CLI’s engine explain says why something didn’t.
  • Convert: convert_rules produces native queries for a target backend, and list_fields lists the fields rules use.
  • Many log formats: JSON, syslog, logfmt, CEF, Windows EVTX, plain text and OTLP, auto-detected by default.
  • Runtime tools: point --daemon-url at a running RSigma daemon to add operations-stage tools.

Who it’s for

  • Detection engineers maintaining Sigma rule sets who want an agent to draft rules and test them automatically.
  • SOC analysts who need the same rule translated for several SIEMs.

Setup

Download a prebuilt binary from GitHub Releases or install with Cargo, then start the MCP server over stdio against your rules directory:

cargo install --locked rsigma
rsigma mcp serve --rules-dir rules/

Register that command as an MCP server in your client; see the MCP server guide.

Our take

Detection engineering is an easily overlooked corner of security tooling. Most security servers face attack surface or code; RSigma serves defenders who write and test rules every day. Behind the MCP server is a full toolchain, with parser, evaluation engine, converter and LSP sharing one intermediate representation, not a quick script wrapper. Its tools analyze rather than change anything, so your SIEM stays untouched. Note that MCP is one component of a project that’s really a standalone detection engine, so expect to spend time on its processing pipeline configuration. The project was created in February 2026 and its community is still small. Licensed MIT.