aisoc-plugin-sdk · Python
The official Python SDK for building AiSOC plugins — custom enrichers, response actions, and data-source connectors.
Status — monorepo today, not yet on PyPI.
pip install aisoc-plugin-sdkdoes not resolve; install from the monorepo source path below. The import path (aisoc_plugin_sdk) and API surface stay identical once it ships.
Installation
# Today (from this monorepo):
git clone https://github.com/beenuar/AiSOC.git
cd AiSOC && pip install -e "packages/plugin-sdk-py[dev]"
# Not yet on PyPI — the upload is blocked on registry credentials,
# which is an account action rather than a code change. Until then, install
# from source with the command above.
# pip install aisoc-plugin-sdk
Quick Start
Enricher (function style)
from aisoc_plugin_sdk import enricher, EnrichmentRequest, EnrichmentResult, PluginContext
@enricher(id="myorg.virustotal", name="VirusTotal Enricher", author="myorg")
async def vt_enrich(request: EnrichmentRequest, ctx: PluginContext) -> EnrichmentResult:
# call VirusTotal API here …
return EnrichmentResult(
indicator_type=request.indicator_type,
indicator_value=request.indicator_value,
enrichments={"vt_score": 72},
malicious=True,
confidence=0.9,
)
Response Action (class style)
from aisoc_plugin_sdk import (
ActionPlugin,
ActionRequest,
ActionResult,
PluginManifest,
PluginContext,
)
class BlockIPAction(ActionPlugin):
@property
def manifest(self) -> PluginManifest:
return PluginManifest(
id="myorg.block-ip",
name="Block IP on Firewall",
version="1.0.0",
plugin_type="action",
)
def supported_actions(self) -> list[str]:
return ["block_ip", "unblock_ip"]
async def execute(self, request: ActionRequest, ctx: PluginContext) -> ActionResult:
ip = request.params.get("ip")
if request.dry_run:
return ActionResult(
action_id=request.action_id, success=True, dry_run=True, summary=f"Would block {ip}"
)
# … firewall API call …
return ActionResult(action_id=request.action_id, success=True, summary=f"Blocked {ip}")
Connector
from typing import AsyncIterator, Any
from aisoc_plugin_sdk import ConnectorPlugin, ConnectorConfig, PluginManifest, PluginContext
from aisoc_plugin_sdk.decorators import connector
@connector(id="myorg.splunk-connector", name="Splunk Connector")
class SplunkConnector(ConnectorPlugin):
async def test_connection(self, ctx: PluginContext) -> bool:
# ping Splunk …
return True
async def fetch_events(
self, ctx: PluginContext, since: str | None = None
) -> AsyncIterator[dict[str, Any]]:
# query Splunk and yield normalised events …
yield {"event_type": "alert", "source": "splunk", …}
Plugin Registry
from aisoc_plugin_sdk import PluginRegistry, PluginContext
registry = PluginRegistry()
registry.register(BlockIPAction())
registry.register(SplunkConnector())
ctx = PluginContext(api_base_url="http://api:8000", api_token="…")
await registry.load_all(ctx)
Development
cd packages/plugin-sdk-py
pip install -e ".[dev]"
pytest
mypy src
ruff check src
License
MIT — see LICENSE.
Metadata
Release files for aisoc-plugin-sdk 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aisoc_plugin_sdk-0.1.0.tar.gz | 14.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aisoc_plugin_sdk-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.8 kB
Release files / aisoc_plugin_sdk-0.1.0.tar.gz
| Download URL | aisoc_plugin_sdk-0.1.0.tar.gz |
|---|---|
| Size | 14.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c66076c0240ac624c8f995c0b7b07476c52443ab2c07dc100df90755ec8266a2
|
|
BLAKE2b-256 checksum How to use checksums |
6981dd1ec6687f24d9b5bb02803ba9b5dddfdc9a8d1f0d6df98600dda2eeeb25
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / aisoc_plugin_sdk-0.1.0-py3-none-any.whl
| Download URL | aisoc_plugin_sdk-0.1.0-py3-none-any.whl |
|---|---|
| Size | 11.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
130c4709c3107f653b420efcfb7217278bdb94fd7e1c15ea6bb3bdffce2f6966
|
|
BLAKE2b-256 checksum How to use checksums |
df77920b475b0ea3b8175d09ecd7c9b61c9c14a2dce6670c4052c0bd872408e1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency log