Sync s1-secops-skills: plugin 1.3.11, MCP 1.4.0, image 1.4.10 (custom-rule MITRE and query slicing solutions, measured LRQ limits) - #109
Merged
marcorottigni-s1 merged 7 commits intoOct 5, 2026
Conversation
…-rule MITRE and query slicing solutions, measured LRQ limits) - sdl-solutions: two new solutions, custom rules with MITRE mapping (HA watchdog posts attacks[] on finding_info.related_events[]) and query slicing (parallel LRQ slices). - Measured LRQ limits replace the 2.5 rps / two-token guidance; long windows are a cost, not a wall; bare contains is valid and case-insensitive. - MCP 1.4.0 (powerquery_run edrStrict, node >=24); image 1.4.10 (Debian security updates, refreshed VT and purple-mcp forks). - Main README lists all ten SDL solutions and the current release. New solution guides and release notes 1.4.8 to 1.4.10. Hand-maintained docs updated by porting only the upstream delta. - Links: 0 broken in README, plugin and mcp trees (fixes six pre-existing). - Demo-tenant ids scrubbed to placeholders; bundles rebuilt from the sanitized tree.
…sync - Every reference to the private upstream repo is replaced with its public ai-siem equivalent: the MCP install and bridge curl commands, image labels and the versions manifest, package.json URLs, systemd and install.sh documentation links, the CLAUDE.md link in zero-to-hero, and the detection-as-code schema id. The docker README no longer points at source-only CI and vendoring scripts. - docs: 'Building from source' now describes what ai-siem can actually do (rebuild the plugin; review and verify the published image), instead of cloning the private repo. - Remove skills/sdl-api/tests/test_client.py: git-ignored at source, it should never have synced. Bundles rebuilt.
Synced from s1-secops-skills 590082d and df219c9: the guide, playbook, SKILL.md, READMEs, release notes, workflow template and renderer now say 'Custom detections with MITRE mapping'; the renderer's default product name is '<PREFIX> Custom Detection (MITRE)'. Main README and plugin README updated to match. Bundles rebuilt.
Synced from s1-secops-skills 7dbe1a3: the solution guide and the sdl-solutions playbook are renamed to match the solution, Custom detections with MITRE mapping. Links in the main README, plugin README and SKILL.md updated. Bundles rebuilt.
…ed)' section (synced from s1-secops-skills)
…s-skills ec2e88d) Text only: UEBA solution doc, zero-to-hero, behavioural-baselines example, UEBA savelookup asset and the baseliner/report/inspect script comments. Bundles rebuilt.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Syncs
s1-secops-skillsinto the monorepo: plugin 1.3.11,s1-secops-mcp1.4.0, Docker imagesentinelone/secops-mcps:1.4.10(already published, multi-arch, smoke test 20/20 on both architectures).Everything new below was measured on a live S-26.3.4 tenant on 2026-10-05.
Two new sdl-solutions solutions
mitre/mitreTechniqueswith 400) and their UAM alerts arrive with none. The solution renders a small JSON rule spec into a Hyperautomation watchdog that posts the alert withattacks[]onfinding_info.related_events[], the only path UAM reads, somitreTactics/mitreTechniquesare populated. Tested end to end: flow ran Completed and the alert carried its tactics and techniques. Shipsrender_mitre_watchdog.py, the workflow template, three example specs and tests.lrq_sliced.pywith tests.Measured, replacing documented guesses
containsis valid and case-insensitive on LRQ v2, SDL V1, s1-secops-mcp and Purple MCP; only:matchcaseis case-sensitive.not field contains 'x'silently returns 0 rows;!(...)works.entitiesAndFieldsare entity groups (OR within, AND across; the positional shape never fired), activities live indataSource.name='ActivityFeed', and INFORMATIONAL alerts and weekly snapshots are hidden unless filtered for.MCP 1.4.0
powerquery_rungainsedrStrict: a mistyped EDR field fails with HTTP 400 instead of returning 0 rows.engines.nodeis now>=24, matching the image.Docker image 1.4.10
libpcre2-8-0, CVE-2026-103111, HIGH).0305f3d(fast-uri3.1.8,ip-address10.7.1); purple-mcp fork at1390b8c(lock refreshed past the authlib, pyjwt, fastmcp, aiohttp, cryptography, urllib3, starlette advisories).Docs
docs/stays hand-maintained. Only this cycle's upstream delta was ported (a 3-way patch of the version and content changes), so ai-siem's own corrections from commit c358916 are preserved.curlcommands, the systemd andinstall.shdocumentation links and thezero-to-heroCLAUDE.md link previously pointed at a repo public readers cannot open. "Building from source" now covers what this repo supports: rebuilding the plugin, and reviewing and verifying the published image.Link check
A strict checker (file targets plus GitHub heading anchors, code blocks excluded) over
README.md,plugins/s1-secops-skillsandmcp: 0 broken links in 268 files. This also fixes six links that were already broken onmain(the MCP and Docker READMEs pointed at the source repo's layout and at a#installationanchor the root README does not have). Everygithub.comrepository referenced from these trees is public, and every mapped ai-siem path exists onmain.Repo-wide, 11 broken links remain, all in community
workflows/content (Okta and Cloudflare guides) and untouched here.Verified
npm test141/141.build.shandentrypoint.shpassbash -n.Upgrade
Change the tag in all three MCP entries in
claude_desktop_config.jsonfrom1.4.9to1.4.10, restart Claude Desktop, and install plugin 1.3.11 fromplugins/s1-secops-skills/dist/. Rollback: pin:1.4.9(immutable).