nsm-ids-triage
Installation
SKILL.md
NSM IDS Triage (read-only)
MCP Server
- Server:
nsm-mcp(NetClaw-authored, spec 091) - Tools:
nsm_status,nsm_update_rules,nsm_alerts,nsm_analyze - Engine: Suricata 8.0.6, pinned by image digest
- Input: a
.pcap/.pcapngfile already on disk. Nothing sniffs an interface.
The rule that matters most here
Zero alerts is not a clean result until you have checked the signature count.
Stock Suricata loads 0 signatures and reports 0 alerts, announcing it with two
non-fatal warnings. Measured: 0 signatures on stock config versus 52,205 after
nsm_update_rules. A detector that loaded nothing inspected nothing.
nsm_alerts attaches suricata_posture to every response for exactly this reason: