SuricataMCP is an MCP server that connects AI assistants like Cursor and Claude Desktop to the Suricata network threat detection engine for traffic analysis. Built for security researchers, SOC analysts, and network engineers, this integration enables large language models to inspect packet capture files and query network security diagnostics directly through standard Model Context Protocol tooling. By wrapping the local Suricata binary, the server allows clients to inspect installed versions, access command-line help documentation, and parse PCAP files to surface security alerts written to Suricata fast log outputs. Users can extend the detection engine by adding custom rule files to the local configuration directory, allowing language models to evaluate tailored intrusion detection signatures against recorded network traffic. SuricataMCP acts as a bridge between automated threat analysis workflows and AI development environments, eliminating the need to manually execute command-line packet replays and parse raw log files outside the primary chat interface during security investigations.
Category: Monitoring & Observability
Tags: ids, ips, network security, suricata, traffic-analysis
Follow these steps to install and set up SuricataMCP: 1. Ensure Suricata is installed on your host system via your package manager (such as sudo apt install suricata) or the official Suricata downloads. 2. Clone the repository: bash git clone https://github.com/medinios/SuricataMCP.git cd SuricataMCP 3. Install the required Python dependencies: bash pip install -r requirements.txt 4. Open config.py and configure your Suricata binary path using SURICATA_DIR and SURICATA_EXE_FILE. 5. Register the server in your MCP client configuration (such as Claude Desktop or Cursor): json { "mcpServers": { "SuricataMcp": { "command": "cmd", "args": ["/c", "mcp", "run", "[YourPath]\\SuricataMcp\\suricata-mcp.py"] } } } Alternatively, install it for Claude Desktop via Smithery: bash npx -y @smithery/cli install @Medinios/SuricataMCP --client claude
Part of MCP Servers
SuricataMCP is an open-source Model Context Protocol server that connects AI clients with the Suricata network security and threat detection engine. It enables conversational agents to inspect network captures, verify engine versions, review command-line help options, and extract intrusion detection alerts directly from generated log files without manual command-line execution.
SuricataMCP provides three primary tools: get_suricata_version to return the installed Suricata version string, get_suricata_help to retrieve the command-line help documentation, and get_alerts_from_pcap_file to process a specific PCAP file and output alert records from the resulting fast.log file.
SuricataMCP works with any standard Model Context Protocol client capable of spawning local process servers. It is commonly used inside AI code editors like Cursor and desktop assistants such as Claude Desktop by adding the execution script to the client server configuration file.
Yes, SuricataMCP requires a standalone installation of Suricata on your operating system. You must install the Suricata binary via your system package manager or download it from the official site, then specify the binary and installation paths in the server config.py file before running it.
You can extend Suricata detection capabilities by adding custom rule files directly into the suricata/rules directory of your installation. When the MCP server executes Suricata on PCAP files, it evaluates the traffic against your custom signatures alongside default rule sets.