UNPKG

stellar-cyber-mcp-agents

Version:

Model Context Protocol (MCP) server for Stellar Cyber security operations with specialized multi-agent analysis capabilities

229 lines 6.04 kB
import { BaseAgent } from '../core/base-agent.js'; import { AgentMetadata, AgentRegistry, AgentCommunicationChannel, AgentLogger, AgentMetrics, AgentHealth, AgentRequest, AgentContext } from '../types/agent.js'; export interface InvestigationConfig { apiUrl: string; apiToken: string; requestTimeout?: number; maxRetries?: number; retryDelay?: number; } export interface CaseDetails { id: string; name: string; description: string; severity: string; status: string; createdAt: string; updatedAt: string; assignee?: string; tags: string[]; score: number; observables: Observable[]; activities: Activity[]; comments: Comment[]; alerts: Alert[]; threatIntel?: ThreatIntelligence; } export interface Observable { id: string; type: string; value: string; tlp: string; metadata?: any; confidence: number; tags: string[]; firstSeen: string; lastSeen: string; count: number; } export interface Activity { id: string; timestamp: string; type: string; actor: string; action: string; details: any; severity: string; } export interface Comment { id: string; author: string; content: string; timestamp: string; type: string; } export interface Alert { id: string; name: string; description: string; severity: string; status: string; timestamp: string; source: string; details: any; } export interface ThreatIntelligence { indicators: ThreatIndicator[]; campaigns: Campaign[]; actors: ThreatActor[]; recommendations: string[]; sources?: string[]; } export interface ThreatIndicator { type: string; value: string; confidence: number; tags: string[]; context: string; } export interface Campaign { id: string; name: string; description: string; firstSeen: string; lastSeen: string; confidence: number; relatedCases: string[]; } export interface ThreatActor { id: string; name: string; aliases: string[]; description: string; motivations: string[]; capabilities: string[]; } export interface InvestigationResult { caseId: string; investigationId: string; timestamp: string; summary: { threatType: string; severity: string; confidence: number; status: string; riskScore: number; }; findings: Finding[]; recommendations: Recommendation[]; nextSteps: string[]; relatedCases: string[]; timeline: TimelineEvent[]; artifacts: Artifact[]; workflow?: WorkflowSuggestion; } export interface Finding { id: string; category: string; description: string; severity: 'CRITICAL' | 'HIGH' | 'MEDIUM' | 'LOW'; confidence: number; evidence: string[]; indicators: string[]; mitre: { tactics: string[]; techniques: string[]; }; } export interface Recommendation { id: string; priority: 'IMMEDIATE' | 'HIGH' | 'MEDIUM' | 'LOW'; category: string; description: string; rationale: string; effort: string; impact: string; resources: string[]; } export interface TimelineEvent { timestamp: string; type: string; description: string; severity: string; source: string; details: any; } export interface Artifact { id: string; type: string; name: string; hash?: string; size?: number; mimeType?: string; extractedAt: string; analysis?: ArtifactAnalysis; } export interface ArtifactAnalysis { verdict: 'MALICIOUS' | 'SUSPICIOUS' | 'CLEAN' | 'UNKNOWN'; confidence: number; signatures: string[]; behaviors: string[]; family?: string; variant?: string; } export interface WorkflowSuggestion { type: string; name: string; description: string; steps: string[]; estimatedTime: string; requiredSkills: string[]; tools: string[]; } export declare class InvestigationAgent extends BaseAgent { private config; private accessToken; private tokenExpiresAt; private refreshPromise; constructor(metadata: AgentMetadata, registry: AgentRegistry, channel: AgentCommunicationChannel, logger: AgentLogger, metrics: AgentMetrics, config: InvestigationConfig); protected onInitialize(): Promise<void>; protected onStart(): Promise<void>; protected onStop(): Promise<void>; protected onDestroy(): Promise<void>; protected onHealthCheck(): Promise<AgentHealth>; protected handleRequest(request: AgentRequest, context: AgentContext): Promise<any>; private investigateCase; private getCaseDetails; private getCaseScores; private getCaseObservables; private getCaseActivities; private getCaseComments; private getCaseAlerts; private getThreatIntelligence; private analyzeCaseObservables; private getCaseTimeline; private getCaseArtifacts; private suggestWorkflow; private searchCases; private getRelatedCases; private updateCaseStatus; private addCaseComment; private refreshToken; private performTokenRefresh; private isTokenValid; private getAccessToken; private makeRequest; private startTokenRefreshMonitoring; private getSettledValue; private combineInvestigationData; private analyzeFindings; private analyzeObservables; private analyzeActivities; private analyzeAlerts; private generateRecommendations; private generateNextSteps; private findRelatedCases; private buildTimeline; private extractArtifacts; private generateInvestigationSummary; private identifyThreatType; private calculateOverallSeverity; private calculateOverallConfidence; private calculateRiskScore; private groupObservablesByType; private generateObservableRecommendations; private getWorkflowDefinitions; private selectWorkflow; } export declare function createInvestigationAgentMetadata(): AgentMetadata; //# sourceMappingURL=investigation-agent.d.ts.map