Skip to content

Sync s1-secops-skills: plugin 1.3.11, MCP 1.4.0, image 1.4.10 (custom-rule MITRE and query slicing solutions, measured LRQ limits) - #109

Merged
marcorottigni-s1 merged 7 commits into
Sentinel-One:mainfrom
pmoses-s1:sync/skills-1.3.11-mcp-1.4.0-image-1.4.10
Oct 5, 2026
Merged

marcorottigni-s1 merged 7 commits into
Sentinel-One:mainfrom
pmoses-s1:sync/skills-1.3.11-mcp-1.4.0-image-1.4.10

Conversation

@pmoses-s1

@pmoses-s1 pmoses-s1 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Syncs s1-secops-skills into the monorepo: plugin 1.3.11, s1-secops-mcp 1.4.0, Docker image sentinelone/secops-mcps:1.4.10 (already published, multi-arch, smoke test 20/20 on both architectures).

Everything new below was measured on a live S-26.3.4 tenant on 2026-10-05.

Two new sdl-solutions solutions

  • Custom detections with MITRE mapping (guide). STAR rules cannot carry MITRE ATT&CK (the API rejects mitre / mitreTechniques with 400) and their UAM alerts arrive with none. The solution renders a small JSON rule spec into a Hyperautomation watchdog that posts the alert with attacks[] on finding_info.related_events[], the only path UAM reads, so mitreTactics / mitreTechniques are populated. Tested end to end: flow ran Completed and the alert carried its tactics and techniques. Ships render_mitre_watchdog.py, the workflow template, three example specs and tests.
  • Query slicing (guide). Long-window PowerQueries run as parallel time slices through the LRQ API and merge client-side. A 30-day aggregate: 21 to 40 s as one query, about 5 s as 15 slices, identical totals. Zero-dependency runner lrq_sliced.py with tests.

Measured, replacing documented guesses

  • LRQ limits. One token sustains about 30 calls/s; 429s start near 35 calls/s and hit only launches. The "about 2.5 rps per user" guidance and the two-token round-robin are retired (skill references and the plugin CLAUDE.md).
  • Long windows are a cost, not a wall. The "15 to 30 days does not complete" figure was inferred, never measured. A broad count over 15, 30 and 90 days completed in 3 to 12 s sliced and 5 to 18 s as one query.
  • Bare contains is valid and case-insensitive on LRQ v2, SDL V1, s1-secops-mcp and Purple MCP; only :matchcase is case-sensitive. not field contains 'x' silently returns 0 rows; !(...) works.
  • Corrections: correlation entitiesAndFields are entity groups (OR within, AND across; the positional shape never fired), activities live in dataSource.name='ActivityFeed', and INFORMATIONAL alerts and weekly snapshots are hidden unless filtered for.

MCP 1.4.0

  • powerquery_run gains edrStrict: a mistyped EDR field fails with HTTP 400 instead of returning 0 rows.
  • engines.node is now >=24, matching the image.

Docker image 1.4.10

  • Debian security updates applied in the image (libpcre2-8-0, CVE-2026-103111, HIGH).
  • VirusTotal fork pinned at 0305f3d (fast-uri 3.1.8, ip-address 10.7.1); purple-mcp fork at 1390b8c (lock refreshed past the authlib, pyjwt, fastmcp, aiohttp, cryptography, urllib3, starlette advisories).
  • Trivy: no fixable HIGH or CRITICAL findings.

Docs

  • Main README: the SecOps skills section now lists all ten SDL solutions with links to their guides, plus the current release (plugin 1.3.11, image 1.4.10) and links to install, upgrade and the release notes.
  • New: both solution guides, and release notes 1.4.8, 1.4.9 (previously missing here) and 1.4.10.
  • docs/ stays hand-maintained. Only this cycle's upstream delta was ported (a 3-way patch of the version and content changes), so ai-siem's own corrections from commit c358916 are preserved.
  • Every link, install command, image label and package URL now points at public ai-siem paths. The MCP install and bridge curl commands, the systemd and install.sh documentation links and the zero-to-hero CLAUDE.md link previously pointed at a repo public readers cannot open. "Building from source" now covers what this repo supports: rebuilding the plugin, and reviewing and verifying the published image.
  • Version references moved to image 1.4.10 / MCP 1.4.0 / plugin 1.3.11 across the plugin README, installation, upgrading, Docker docs and the systemd unit (which was still pinned to 1.4.9).

Link check

A strict checker (file targets plus GitHub heading anchors, code blocks excluded) over README.md, plugins/s1-secops-skills and mcp: 0 broken links in 268 files. This also fixes six links that were already broken on main (the MCP and Docker READMEs pointed at the source repo's layout and at a #installation anchor the root README does not have). Every github.com repository referenced from these trees is public, and every mapped ai-siem path exists on main.

Repo-wide, 11 broken links remain, all in community workflows/ content (Okta and Cloudflare guides) and untouched here.

Verified

  • MCP: npm test 141/141.
  • Skills: all eight unit-test suites pass; every SKILL.md frontmatter under 1024 characters; 0 unresolved skill references.
  • JSON manifests parse; build.sh and entrypoint.sh pass bash -n.

Upgrade

Change the tag in all three MCP entries in claude_desktop_config.json from 1.4.9 to 1.4.10, restart Claude Desktop, and install plugin 1.3.11 from plugins/s1-secops-skills/dist/. Rollback: pin :1.4.9 (immutable).

…-rule MITRE and query slicing solutions, measured LRQ limits)

- sdl-solutions: two new solutions, custom rules with MITRE mapping (HA watchdog posts
  attacks[] on finding_info.related_events[]) and query slicing (parallel LRQ slices).
- Measured LRQ limits replace the 2.5 rps / two-token guidance; long windows are a cost,
  not a wall; bare contains is valid and case-insensitive.
- MCP 1.4.0 (powerquery_run edrStrict, node >=24); image 1.4.10 (Debian security
  updates, refreshed VT and purple-mcp forks).
- Main README lists all ten SDL solutions and the current release. New solution guides
  and release notes 1.4.8 to 1.4.10. Hand-maintained docs updated by porting only the
  upstream delta.
- Links: 0 broken in README, plugin and mcp trees (fixes six pre-existing).
- Demo-tenant ids scrubbed to placeholders; bundles rebuilt from the sanitized tree.
…sync

- Every reference to the private upstream repo is replaced with its public ai-siem
  equivalent: the MCP install and bridge curl commands, image labels and the versions
  manifest, package.json URLs, systemd and install.sh documentation links, the CLAUDE.md
  link in zero-to-hero, and the detection-as-code schema id. The docker README no longer
  points at source-only CI and vendoring scripts.
- docs: 'Building from source' now describes what ai-siem can actually do (rebuild the
  plugin; review and verify the published image), instead of cloning the private repo.
- Remove skills/sdl-api/tests/test_client.py: git-ignored at source, it should never
  have synced. Bundles rebuilt.
Synced from s1-secops-skills 590082d and df219c9: the guide, playbook, SKILL.md,
READMEs, release notes, workflow template and renderer now say 'Custom detections with
MITRE mapping'; the renderer's default product name is '<PREFIX> Custom Detection
(MITRE)'. Main README and plugin README updated to match. Bundles rebuilt.
Synced from s1-secops-skills 7dbe1a3: the solution guide and the sdl-solutions
playbook are renamed to match the solution, Custom detections with MITRE mapping.
Links in the main README, plugin README and SKILL.md updated. Bundles rebuilt.
…s-skills ec2e88d)

Text only: UEBA solution doc, zero-to-hero, behavioural-baselines example, UEBA
savelookup asset and the baseliner/report/inspect script comments. Bundles rebuilt.

@marcorottigni-s1 marcorottigni-s1 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@marcorottigni-s1
marcorottigni-s1 merged commit 7cd1d64 into Sentinel-One:main Oct 5, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants