aisoc-detections — Python detection framework
Write detections as Python, unit-tested against their own fixtures. Complements
the YAML/Sigma corpus in detections/ — use Python when a
detection needs real logic (thresholds, correlation, stateful decisions) that is
awkward in a declarative DSL.
A detection
A detection is a .py module with a rule(event) -> bool and metadata:
ID = "py-okta-mfa-fatigue"
TITLE = "Okta MFA fatigue (push bombing)"
SEVERITY = "high" # info | low | medium | high | critical
MITRE = ["T1621"]
DESCRIPTION = "Many MFA push challenges to one user in a short window."
def rule(event: dict) -> bool:
return event.get("eventType") == "user.mfa.attempt" and event.get("attempts", 0) >= 5
# Optional: def title(event) -> str, def dedup(event) -> str
TESTS = [
{"name": "fires on 6 attempts", "event": {"eventType": "user.mfa.attempt", "attempts": 6}, "expect": True},
{"name": "quiet on 1 attempt", "event": {"eventType": "user.mfa.attempt", "attempts": 1}, "expect": False},
]
Every detection must ship at least one positive and one negative TESTS
case — the harness fails a blind rule (misses a positive) or a noisy one (fires
on a negative), the same non-circular guarantee the YAML corpus gets.
Running the fixture gate
# from packages/aisoc-detections/
python -m aisoc_detections.runner detections # aka `aisoc-detections`
PYTHONPATH=. python -m pytest tests/
CI runs this on every PR (.github/workflows/python-detections.yml).
Safety
Rules are first-party and reviewed via PR. evaluate() is fail-closed: a rule
that raises returns False (never fires, never crashes the batch).
Metadata
Release files for aisoc-detections 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aisoc_detections-0.1.0.tar.gz | 8.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aisoc_detections-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.7 kB
Release files / aisoc_detections-0.1.0.tar.gz
| Download URL | aisoc_detections-0.1.0.tar.gz |
|---|---|
| Size | 8.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
56e4872fcf19e8f8f19e455750da606680d0bed7375583ca10a49aea0c7a6e6a
|
|
BLAKE2b-256 checksum How to use checksums |
c4dfb304793a1a7182cf6b716165307cdcf96b0a29c05a490f89adab31c87ca2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / aisoc_detections-0.1.0-py3-none-any.whl
| Download URL | aisoc_detections-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
881999db5428c0a795cfd9ce9944cfb7280261f322f2b401b1e3c21605ddac58
|
|
BLAKE2b-256 checksum How to use checksums |
a34a51696557f21b610bf8a369b5cdefa782883754f05966c1278bf2962de44c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency log