top of page

Leveraging MCP for Context-Aware Detection Engineering in Sentio SIEM

1 day ago
2 min read

Detection engineering is a constant balancing act. We as detection engineers must come up with sharp, highly specific detection rules, monitor daily threat intel to cover emerging attacks, and search different community forums for fresh ideas.


The primary strength of a SIEM is its versatility: it can ingest almost anything and extract value from virtually any data source. However, this flexibility often leads to compromising something else, niche log sources often lack support for detection rules, making custom detection rules difficult to build unlike other major log sources such as Windows or Linux.



Effective Detection Rules

To create effective detection rules, engineers need structured guidelines and a sustainable lifecycle that spans initial publishing through continuous tuning. Developing universal rules that work across different industry sectors is particularly difficult; what constitutes normal behavior in one environment may be an anomaly in another.



Connecting an LLM to the SIEM

To tackle this, we recently enabled Model Context Protocol (MCP) access within Sentio SIEM. This allows users to connect their custom AI models directly to Sentio and query their environment using predefined SIEM tools, driving significant efficiency gains in our detection engineering pipeline.




We put this setup to the test with a niche log source: Cloudflare API. While ingesting these logs into Sentio was straightforward, finding existing community detection content was challenging. Because administrative actions are inherently privileged and varied, our rules needed to be precise to avoid unwanted noise.



How we utilized MCP

Using our demo environment, we sent a prompt asking our LLM model to locate our cloudflare- log index and propose initial Lucene/KQL search queries (which we later map to JMESPath). The model automatically discovered the target indexes and analyzed the underlying log structure.




more thinking later……



Within minutes, the model generated 10 actionable detection rule ideas tailored directly to our ingested Cloudflare log schema. This gave us detection engineers an immediate baseline to evaluate, refine, and test.



Refining LLM Output for Production

While our LLM provided solid, context-aware suggestions, our evaluation revealed that most of the recommendations provided would produce high false-positive rates in a real-world setting. Every environment operates under different operational norms and service configurations. So we have to make our rules generic whilst also being precise.


We used the generated concepts as a launchpad to build a production-ready, tuned detection rules (published on rules.cybersift.io).




Conclusion

While LLM-generated detection rules shouldn't be pushed to production without us overseeing it, integration via MCP upgraded our engineering workflow. It made it easier to keep up and bridge the gap between cold-start research and practical evaluation, and rule development in real environment data from day one.


-Written by Emanuel Falzon

bottom of page