Repository navigation
GLAIVE v0.2: investigation platform - #1
Merged
Merged
Conversation
Store text files with LF endings and make every editor add a final newline, so diffs stay clean for contributors on Windows and Unix.
Nine files lacked a final newline (ruff W292). No code changes.
…d traversal Removes the dead duplicate Process class; adds Alert/ScriptBlock nodes and Triggered/Ran edges; lossless JSON (de)serialization with tagged keys; neighbours, shortest path, timeline; thread-safe mutation.
A second class TestFile in test_nodes.py shadowed the first, so pytest never collected its 14 tests. Rename the first class. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A claim ending in 'C:\Temp\a.exe).' produced the entity 'C:\Temp\a.exe)' and was wrongly rejected as ungrounded. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…indings - high and critical findings wait for analyst approval - Skeptic reviews can only lower confidence; analyst overrides too - findings serialize to and from dicts for the case file Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ed EVTX - commit_finding validates severity and technique IDs, returns finding_status - a damaged EVTX returns a structured parse_failed error instead of raising - ingest_artifact gains source_type 'auto' (folder/zip pipeline, lazily imported) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- SQLite file holding graph, findings, evidence manifest and an append-only audit log - atomic saves; refuses files from a newer schema version - GlaiveSession.save() and GlaiveSession.load()
- the Rust 'evtx' package is used when installed (about 1000x faster) - both readers produce identical output: hex, GUID, boolean and line-ending values are canonicalized - keep Channel, Provider, unnamed Data and UserData fields (needed for Security/System/Sysmon) - _record_id is the Windows EventRecordID, not the reader's own counter - a file the Rust reader refuses falls back to python-evtx
Accepts GLAIVE's own event shape and the nested or flat exports of EvtxECmd, Chainsaw and evtx_dump. Bad records are counted and skipped, never fatal.
…l events - logons, process creation, users and groups, scheduled tasks, services, network, files, registry, DNS and script blocks - a process seen by both Security 4688 and Sysmon 1 becomes one node with two confirmations - events that only know a PID resolve to the process alive at that time - events without evidence provenance are ignored; malformed events are counted, never fatal
- evaluates Sigma YAML directly against parsed events; no SIEM or model needed - modifiers contains/startswith/endswith/all/re/cidr/windash/exists/gt/lt, wildcards, 1-of/all-of conditions - Security 4688 fields are aliased to Sysmon names so process_creation rules match both - rules using unsupported features (aggregations, base64offset) are skipped and reported, never mis-evaluated - built-in rules cover Office-spawned shells, encoded PowerShell, Defender tampering, LSASS dumps, persistence, shadow-copy deletion and log clearing
…ese) - deterministic patterns: instruction override, role hijack, verdict tampering, suppression, chat markup - spotlight() wraps untrusted evidence in randomly tagged delimiters so it cannot close the block early
- brute force followed by a successful logon from the same source - security tooling disabled shortly before a high or critical alert on the same host - prompt-injection text planted in evidence fields becomes an alert - each hit is anchored to a real event so its alert keeps normal provenance
…wer key - two hosts, twelve attack steps (phishing document to log clearing) plus realistic background noise - deterministic for a given seed, so any investigation can be scored against the answer key - includes a prompt injection planted for AI investigators - uses reserved documentation addresses and .example domains only
… result - run() now delegates to a new integrate() method that the multi-file pipeline can call directly - edges whose endpoints are missing are counted as orphan_edges_skipped instead of silently dropped - per-event entity links are kept out of the ingest report's parser stats
- every file is hashed into the evidence store before it is read - format is detected from content; EVTX and JSON/JSONL are parsed, other files are kept for custody - all events are parsed in one time-sorted pass so a process seen in several logs becomes one node - Sigma and correlation hits become Alert nodes linked to the processes, users and hosts involved - one alert per rule and process, even when Sysmon and Security both record it - zip archives are checked for path traversal, zip bombs and symlinks before extraction - ingest_artifact's 'auto' source type now works end to end
- one adapter for the OpenAI Chat Completions protocol (OpenAI, DeepSeek, Qwen, Kimi, GLM, Doubao, Gemini, OpenRouter, SiliconFlow, Ollama, vLLM, SGLang, llama.cpp) - one adapter for the Anthropic Messages API (Claude) - reasoning_content (Kimi, DeepSeek) and Claude content blocks are echoed back on the next turn as those APIs require - invalid tool-call JSON from a model is reported on the call, never raised - rate limits, timeouts and 5xx are marked retryable; bad keys and unknown models are not - ScriptedProvider gives deterministic replies for tests and demos; only httpx is needed
…nd token budget - providers are tried in order; retryable failures back off exponentially, hard failures fall through immediately - a provider that keeps failing is skipped for a cooldown period - a token budget caps the cost of one investigation - per-provider calls, failures, tokens and latency are recorded
- presets for Claude, GPT, Gemini, DeepSeek, Qwen, Kimi, GLM, Doubao, OpenRouter, SiliconFlow, Ollama and any OpenAI-compatible server - every provider with a key in the environment joins the fallback chain; GLAIVE_PROVIDERS sets the order - per-provider <NAME>_MODEL and <NAME>_BASE_URL overrides, plus GLAIVE_TOKEN_BUDGET - default model names checked against provider documentation in October 2026 - .env.example documents every setting and is no longer ignored by git
- recall, a precision lower bound and ATT&CK technique coverage - independently re-checks that no committed finding is ungrounded - counts claims the gate blocked; findings an analyst rejected do not count
- case overview, alerts, graph query, node details, neighbours, timeline, commit_finding and finish - arguments are validated with Pydantic; invalid calls get a structured error the model can correct - results are size-limited and wrapped as untrusted data (spotlighting) - a read-only mode for reviewers removes commit_finding and finish
- rule triage turns medium-and-above alerts into gate-verified findings with no model - Hunter plans, then investigates in a tool loop; rejected claims come back as feedback - Skeptic tries to refute each finding and can only lower its confidence - Reporter keeps only sentences that cite a finding and are grounded in its evidence; falls back to a deterministic summary - prompts are versioned and treat everything inside tool results as data, never instructions
- triage always runs; Hunter and Skeptic run when a model is configured - every stage is written to the session audit log, then the case file is saved - a model outage keeps the offline findings and falls back to a deterministic report - integration test over the public EVTX-ATTACK-SAMPLES set (opt-in)
…rver - case_overview, list_alerts, get_neighbors, get_timeline and save_case - commit_finding accepts severity, ATT&CK techniques and a rationale; MCP findings are authored as 'mcp' - the commit_finding description lists every gate decision, including ungrounded claims - ingest_artifact defaults to 'auto' (file, folder or zip)
Path.read_text() without an encoding uses the system code page (cp1252 on Windows), which cannot decode UTF-8 source files containing non-ASCII text, such as the Chinese report headings. The static eval/exec bypass check crashed on glaive/reporting/html.py.
- one file with no external assets; light and dark themes - each finding shows its severity, evidence-derived confidence, ATT&CK tags, Skeptic review and analyst review - each cited item links to its source log record and the SHA-256 of its evidence file - detection timeline and a chain-of-custody table for re-verifying hashes - all case text is HTML-escaped (attacker-controlled log content cannot inject script)
… review findings - drag-and-drop evidence upload, live feed of gate decisions, findings with analyst approve/reject - timeline, attack graph, evidence table with hash re-verification, and Ask-the-case answers that must cite findings - localhost only by default; a token (GLAIVE_WEB_TOKEN) is required for any other address - without a token, Host and Origin checks block DNS rebinding and cross-site requests - upload names are sanitized and sizes limited; the page loads nothing from third parties
… and mcp commands - glaive demo builds the Operation Invoice case, investigates it and scores it against the answer key - glaive investigate takes a file, folder or zip and writes a case file plus HTML and Markdown reports - glaive verify re-hashes every evidence file and exits 1 if any changed - glaive serve requires an access token when listening beyond localhost - python -m glaive.mcp_server is kept as an alias of glaive mcp - the console never crashes on non-UTF-8 Windows code pages
- runs as an unprivileged user and always requires an access token - no compiler needed: every dependency installs from prebuilt wheels - .env, tests and evidence samples are kept out of the build context
- lint, full test suite, adversarial bypass tests and the offline demo on every combination - builds the Docker image, checks it refuses requests without the token and runs the demo inside it - read-only token permissions; superseded runs are cancelled
…red accuracy - README: quick start, models, MCP, Docker, security model and measured results - CHANGELOG for 0.2.0 - LIMITATIONS rewritten from the code (the v0.1 text described evidence types that are not supported) - ACCURACY_REPORT filled in from a real run of the demo case, including the two misses and why
- pyproject: use README.md as the package description - add the missing docstring to glaive.security - add missing final newlines
Docker requires container names of at least two characters; 'g' was rejected.
aliyaalias19
added a commit
that referenced
this pull request
Oct 2, 2026
GLAIVE v0.2: investigation platform
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
.glaivecase files; Windows Security/System/Sysmon/PowerShell parsing with cross-log process corroborationFixed from v0.1
See CHANGELOG.md (mcp 2.x install failure, gate grounding, 14 tests that never ran, and more).
How it was verified
Known limits
LIMITATIONS.md: Windows logs only for now; the gate checks entities, not wording.