Skip to main content

aisoc-detections — Python detection framework

Write detections as Python, unit-tested against their own fixtures. Complements the YAML/Sigma corpus in detections/ — use Python when a detection needs real logic (thresholds, correlation, stateful decisions) that is awkward in a declarative DSL.

A detection

A detection is a .py module with a rule(event) -> bool and metadata:

ID = "py-okta-mfa-fatigue"
TITLE = "Okta MFA fatigue (push bombing)"
SEVERITY = "high"  # info | low | medium | high | critical
MITRE = ["T1621"]
DESCRIPTION = "Many MFA push challenges to one user in a short window."


def rule(event: dict) -> bool:
    return event.get("eventType") == "user.mfa.attempt" and event.get("attempts", 0) >= 5


# Optional: def title(event) -> str, def dedup(event) -> str

TESTS = [
    {"name": "fires on 6 attempts", "event": {"eventType": "user.mfa.attempt", "attempts": 6}, "expect": True},
    {"name": "quiet on 1 attempt", "event": {"eventType": "user.mfa.attempt", "attempts": 1}, "expect": False},
]

Every detection must ship at least one positive and one negative TESTS case — the harness fails a blind rule (misses a positive) or a noisy one (fires on a negative), the same non-circular guarantee the YAML corpus gets.

Running the fixture gate

# from packages/aisoc-detections/
python -m aisoc_detections.runner detections    # aka `aisoc-detections`
PYTHONPATH=. python -m pytest tests/

CI runs this on every PR (.github/workflows/python-detections.yml).

Safety

Rules are first-party and reviewed via PR. evaluate() is fail-closed: a rule that raises returns False (never fires, never crashes the batch).

Metadata

Release files for aisoc-detections 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aisoc-detections 0.1.0
File Size Uploaded
aisoc_detections-0.1.0.tar.gz 8.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aisoc-detections 0.1.0
File Interpreter ABI Platform
aisoc_detections-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 14.7 kB

Release files / aisoc_detections-0.1.0.tar.gz

Download URL aisoc_detections-0.1.0.tar.gz
Size 8.4 kB
Tags Source
SHA-256 checksum
How to use checksums
56e4872fcf19e8f8f19e455750da606680d0bed7375583ca10a49aea0c7a6e6a
BLAKE2b-256 checksum
How to use checksums
c4dfb304793a1a7182cf6b716165307cdcf96b0a29c05a490f89adab31c87ca2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / aisoc_detections-0.1.0-py3-none-any.whl

Download URL aisoc_detections-0.1.0-py3-none-any.whl
Size 6.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
881999db5428c0a795cfd9ce9944cfb7280261f322f2b401b1e3c21605ddac58
BLAKE2b-256 checksum
How to use checksums
a34a51696557f21b610bf8a369b5cdefa782883754f05966c1278bf2962de44c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page