add new func

This commit is contained in:
rootkit
2026-03-16 05:25:52 +08:00
parent 6a3878de70
commit 8bcc2ac887
3 changed files with 109 additions and 3 deletions
@@ -9,7 +9,6 @@ metadata:
category: cyber security
tags: [ case-management, soc ]
documentation: https://asp.viperrtp.com/
allowed-tools: [ "*" ]
---
# ASP Case
+106
View File
@@ -0,0 +1,106 @@
---
name: asp-siem
description: SIEM search and investigation operations for the Agentic SOC Platform, currently focused on keyword-based search across ELK and Splunk backends.
compatibility: connect to asp mcp server
metadata:
author: Funnywolf
version: 0.1.0
mcp-server: asp
category: cyber security
tags: [ siem, search, soc ]
documentation: https://asp.viperrtp.com/
---
# ASP SIEM
This skill provides SIEM search and investigation capabilities for the Agentic SOC Platform.
## Available Operations
Ask the user which operation they want to perform:
1. **Keyword search** - Search logs by IP, hostname, username, hash, or any arbitrary keyword across one or more SIEM
indices
This skill currently focuses on `siem_keyword_search`. More SIEM operations can be added later using the same structure.
## Operation Details
### 1. Keyword Search
**Required parameters:**
- `keyword` - Search keyword. Can be an IP address, hostname, username, email, hash, process name, domain, or any string
- `time_range_start` - Start time in UTC ISO8601 format, for example `2026-02-04T06:00:00Z`
- `time_range_end` - End time in UTC ISO8601 format, for example `2026-02-04T07:00:00Z`
**Optional parameters:**
- `time_field` - Time field used for the range filter. Default is `@timestamp`. Common alternatives include
`event.created` and `_time`
- `index_name` - Target SIEM index/source name. If omitted, search across all available indices and backends. If
provided, search only that specific index
**Process:**
1. Collect the keyword and time range from the user
2. If the user knows the target data source, collect `index_name`; otherwise leave it empty for cross-index search
3. If the target source uses a non-default time field, collect `time_field`; otherwise use `@timestamp`
4. Use MCP tool `siem_keyword_search` with the collected parameters
5. Parse each returned JSON string
6. If the result list is empty, state that no matching logs were found in the specified time range
7. Present results grouped by backend and index when multiple results are returned
**Behavior notes:**
- If `index_name` is not provided, the tool searches across available ELK and Splunk indices
- The tool returns adaptive results based on hit volume:
- `full` - complete matching records for smaller result sets
- `sample` - statistics plus representative sample records for medium result sets
- `summary` - statistics only for large result sets
- Time values must be UTC and end with `Z`
**Output format:**
**Search Overview**
- Keyword
- Time range start/end
- Time field
- Searched index or `all indices`
- Total result groups
**Per Result Group**
- Backend
- Index distribution
- Status
- Total hits
- Message
**Statistics**
- For each field statistic: field name and top values with counts
**Sample Records**
- Show representative records when `records` is not empty
- Prefer highlighting timestamp, source index, host, user, IP, process, event/action, and other directly relevant fields
when present
**Suggested rendering:**
| Backend | Status | Total Hits | Index Distribution | Message |
|---------|--------|------------|--------------------|---------|
| ... | ... | ... | ... | ... |
Then provide statistics and sample records under each result group.
## Usage Flow
1. Ask user which SIEM operation they want to perform
2. Collect required parameters for the chosen operation
3. Execute the appropriate MCP tool
4. Format and present the results according to the operation's output specification
5. Handle errors gracefully, such as invalid UTC time format, unsupported index, backend connection issues, or no
matching logs
+3 -2
View File
@@ -100,7 +100,8 @@ def siem_keyword_search(
def get_current_time(
time_format: Annotated[
Optional[str], "Optional datetime format string. If not provided, returns ISO 8601 time with timezone information accurate to seconds"] = None
Optional[str], "Optional datetime format string (e.g. '%Y/%m/%d %H:%M:%S' '%Y-%m-%dT%H:%M:%SZ'). "
"If not provided, returns ISO 8601 time with timezone information accurate to seconds"] = None
) -> Annotated[str, "Current system time string with timezone information"]:
current_time = datetime.now().astimezone()
if time_format:
@@ -115,7 +116,7 @@ if __name__ == "__main__":
import django
django.setup()
print(get_current_system_time())
print(get_current_time())
time_range_end = datetime.now(timezone.utc)
time_range_start = time_range_end - timedelta(minutes=10)
siem_results = siem_keyword_search(