Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Varpulis

FreeNot checked

MCP server exposing Varpulis CEP engine to AI agents

GitHubEmbed

About

MCP server exposing Varpulis CEP engine to AI agents

README

Varpulis

Open-source SASE+ engine for SIEM correlation and MITRE ATT&CK kill-chain detection.

CI crates.io docs.rs License

Documentation · Live Demo · Quick Start · Security Demo · SIEM Evasion Lab


  • Sequence detection SIEMs can't model. Multi-step kill chains (A -> all B -> C within 5m) — Sigma and KQL match single events; behavioral patterns survive renamed binaries, swapped C2, novel evasions.
  • 250K events/sec real-time on a single core, end-to-end (file → match → emit). 1.5M evt/s on the SASE+ core. Single 15 MB Rust binary, no JVM.
  • VPL: rules a blue team can read. Declarative, auditable, version-controlled. Compiles to a Rust state machine — no DSL-on-DSL, no XML, no Spark job to babysit.
# Lateral movement: SMB connect → remote service exec within 2 minutes
# MITRE T1021.002 — catches PsExec, renamed PsExec, WMI remote exec, same pattern
stream LateralMovement = SysmonNetworkConnect .where(DestinationPort == 445) as smb
    -> SysmonProcessCreate .where(ParentImage.contains("services.exe")) as remote_exec
    .within(2m)
    .emit(rule: "lateral_movement_smb", mitre: "T1021.002",
          source: smb.Hostname, target: smb.DestinationIp,
          process: remote_exec.Image, cmdline: remote_exec.CommandLine)

A SIEM rule sees services.exe start a child — looks normal in isolation. Varpulis sees the SMB→exec sequence within 2 minutes — that's the behavioral signature of remote execution, regardless of which tool executed it.

Security: Kill Chain Detection

# Blue mode: detect kill chains in Sysmon logs
varpulis detect --rules rules/ --events sysmon.jsonl

# Red mode: test which rules survive evasion (Sigma vs. behavioral, head-to-head)
varpulis analyze --rules rules/ --baseline normal.jsonl --evasion evasion.jsonl
┌───────────────────┬─────────────────────┬────────────┬────────────┬───────────┐
│ Rule              ┆ MITRE               ┆ Baseline   ┆ Evasion    ┆ Verdict   │
╞═══════════════════╪═════════════════════╪════════════╪════════════╪═══════════╡
│ sigma_psexec      ┆ T1021.002           ┆ DETECT (1) ┆ MISS       ┆ EVADABLE  │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌┤
│ behavioral_psexec ┆ T1021.002,T1036.003 ┆ DETECT (1) ┆ DETECT (1) ┆ RESILIENT │
└───────────────────┴─────────────────────┴────────────┴────────────┴───────────┘

Validated against real MORDOR APT29 datasets at 25K+ events/sec.

Quick Start

cargo install varpulis-cli
varpulis interactive --no-tui
vpl> event Tick: price: float
vpl> stream Spike = Tick .where(price > 100) .emit(alert: "spike", price: price)
vpl> Tick { price: 42.0 }
vpl> Tick { price: 150.0 }
→ Spike: {"alert":"spike","price":150}

The default varpulis interactive opens a split-pane TUI with topology, live events, input, and metrics. Add --no-tui for a plain text shell, --json for agent automation.

Varpulis TUI

Why Varpulis?

Varpulis Flink CEP Esper Siddhi
Temporal patterns (Kleene +/*, negation, within) Native (SASE+) Limited Yes Partial
Predictive forecasting .forecast() built-in No No No
Deployment Single binary (15 MB) JVM cluster Embedded JVM Embedded JVM
DSL VPL (dedicated) Java API EPL SiddhiQL
Throughput 1.5M evt/s (single core) ~500K evt/s¹ ~1M evt/s¹ ~300K evt/s¹

¹ Approximate figures from published benchmarks and vendor documentation; workload-dependent.

.forecast() is unique. It uses Probabilistic Suffix Trees to predict that a pattern is about to complete — before the final event arrives. Combined with Hawkes process intensity estimation and conformal prediction intervals, it turns reactive detection into proactive alerting.

Performance

What Speed
Core SASE+ pattern matching 1.5M evt/s
Full VPL pipeline (filter + emit) 410K evt/s
CLI end-to-end (file → process → output) 256K evt/s
Multi-query Hamlet (50 concurrent) 950K evt/s
Single-symbol prediction 51 ns

Single core. Detailed benchmarks →

Connectors

Status Direction
MQTT, Kafka, NATS, HTTP Battle-tested In/Out
PostgreSQL/MySQL/SQLite, Redis Tested In/Out
Kinesis, S3, Elasticsearch, Pulsar, CDC Available Varies
Sysmon, Splunk HEC, Slack Security-focused Varies

Each connector is an independent crate. The default binary includes all; build with --features mqtt,kafka for a minimal binary.

Features

Language
  • Pipeline operators: .where(), .window(), .aggregate(), .emit(), .to(), .alert()
  • SASE+ patterns: sequences (->), Kleene closures (+, *), negation (AND NOT)
  • Forecasting: .forecast() — PST-based prediction with confidence and horizon
  • Alert webhooks: .alert(webhook: "url", message: "{field}") — fire-and-forget
  • Windows: tumbling, sliding, session, count-based
  • Aggregations: 15+ functions (sum, avg, ema, percentile, stddev, ...) — SIMD-accelerated
  • Joins: inner, LEFT, RIGHT, FULL outer with null-fill
  • Imperative: var, if/else, while, for, functions, lambdas
  • Compile-time meta-programming: for row in 0..4: generates streams
Developer Experience
  • Interactive TUI with split-pane topology/events/metrics (varpulis interactive)
  • Schema inference from sample data (varpulis infer --input data.jsonl)
  • Pipeline trace / explain mode (--trace)
  • Watch mode with auto-reload (--watch)
  • VS Code extension (LSP: diagnostics, completion, hover, go-to-definition)
  • MCP server for AI-assisted development
  • JSON-line protocol for agent automation (--json)
Operations
  • Single binary, Docker, Kubernetes (Helm chart included)
  • Coordinator/worker cluster with Raft consensus
  • Multi-tenant SaaS mode with RBAC and SSO/OIDC
  • Prometheus metrics, OpenTelemetry tracing, Grafana dashboards
  • RocksDB state persistence with optional AES-256-GCM encryption
  • Circuit breaker, dead letter queue, backpressure signaling

Beyond Security

Varpulis is a general SASE+ engine — fraud detection, IoT anomalies, trend prediction. The playground shows .increasing(temperature) detecting rising HVAC sensor values; .forecast() predicts pattern completion before the final event. See examples/ for fraud, finance, and sensor pipelines.

Documentation

Getting Started Interactive Shell Tutorial
VPL Language Tutorial SASE+ Patterns Guide
Forecasting Architecture CLI Reference
Cluster Tutorial Production Deployment
System Architecture All Tutorials →

Build & Test

cargo build               # build the workspace
cargo test                # unit + integration tests
cargo clippy              # lint
make verify               # full local gate: fmt + clippy + audit + deny

make verify is a thin wrapper around scripts/verify.sh and runs the same gates as CI. Subsets are available: make verify-fmt, make verify-clippy, make verify-audit, make verify-deny. See CONTRIBUTING.md for the full development workflow.

Contributing

Contributions welcome — see CONTRIBUTING.md.

License

Dual-licensed under MIT or Apache-2.0.

Acknowledgments

SASE/SASE+ — Wu et al. SIGMOD 2006, Agrawal et al. SIGMOD 2008 · Hamlet — Poppe et al. SIGMOD 2021 · Built with Pest and Tower-LSP


Production deployment · managed cloud · enterprise connectors → varpulis-cep.com/poc

from github.com/varpulis/varpulis

Installing Varpulis

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/varpulis/varpulis

FAQ

Is Varpulis MCP free?

Yes, Varpulis MCP is free — one-click install via Unyly at no cost.

Does Varpulis need an API key?

No, Varpulis runs without API keys or environment variables.

Is Varpulis hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Varpulis in Claude Desktop, Claude Code or Cursor?

Open Varpulis on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Varpulis with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All ai MCPs