Leveraging MCP for Context-Aware Detection Engineering in Sentio SIEM
Detection engineering is a constant balancing act. We as detection engineers must come up with sharp, highly specific detection rules, monitor daily threat intel to cover emerging attacks, and search different community forums for fresh ideas.
The primary strength of a SIEM is its versatility: it can ingest almost anything and extract value from virtually any data source. However, this flexibility often leads to compromising something else, niche log sources often lack support for detection rules, making custom detection rules difficult to build unlike other major log sources such as Windows or Linux.
Effective Detection Rules
To create effective detection rules, engineers need structured guidelines and a sustainable lifecycle that spans initial publishing through continuous tuning. Developing universal rules that work across different industry sectors is particularly difficult; what constitutes normal behavior in one environment may be an anomaly in another.
Connecting an LLM to the SIEM
To tackle this, we recently enabled Model Context Protocol (MCP) access within Sentio SIEM. This allows users to connect their custom AI models directly to Sentio and query their environment using predefined SIEM tools, driving significant efficiency gains in our detection engineering pipeline.

We put this setup to the test with a niche log source: Cloudflare API. While ingesting these logs into Sentio was straightforward, finding existing community detection content was challenging. Because administrative actions are inherently privileged and varied, our rules needed to be precise to avoid unwanted noise.
How we utilized MCP
Using our demo environment, we sent a prompt asking our LLM model to locate our cloudflare- log index and propose initial Lucene/KQL search queries (which we later map to JMESPath). The model automatically discovered the target indexes and analyzed the underlying log structure.


more thinking later……

Within minutes, the model generated 10 actionable detection rule ideas tailored directly to our ingested Cloudflare log schema. This gave us detection engineers an immediate baseline to evaluate, refine, and test.
Refining LLM Output for Production
While our LLM provided solid, context-aware suggestions, our evaluation revealed that most of the recommendations provided would produce high false-positive rates in a real-world setting. Every environment operates under different operational norms and service configurations. So we have to make our rules generic whilst also being precise.
We used the generated concepts as a launchpad to build a production-ready, tuned detection rules (published on rules.cybersift.io).
Taken from rules.cybersift.io

Conclusion
While LLM-generated detection rules shouldn't be pushed to production without us overseeing it, integration via MCP upgraded our engineering workflow. It made it easier to keep up and bridge the gap between cold-start research and practical evaluation, and rule development in real environment data from day one.
-Written by Emanuel Falzon



