Skip to main content

aisoc-plugin-sdk · Python

The official Python SDK for building AiSOC plugins — custom enrichers, response actions, and data-source connectors.

Status — monorepo today, not yet on PyPI. pip install aisoc-plugin-sdk does not resolve; install from the monorepo source path below. The import path (aisoc_plugin_sdk) and API surface stay identical once it ships.

Installation

# Today (from this monorepo):
git clone https://github.com/beenuar/AiSOC.git
cd AiSOC && pip install -e "packages/plugin-sdk-py[dev]"

# Not yet on PyPI — the upload is blocked on registry credentials,
# which is an account action rather than a code change. Until then, install
# from source with the command above.
#   pip install aisoc-plugin-sdk

Quick Start

Enricher (function style)

from aisoc_plugin_sdk import enricher, EnrichmentRequest, EnrichmentResult, PluginContext


@enricher(id="myorg.virustotal", name="VirusTotal Enricher", author="myorg")
async def vt_enrich(request: EnrichmentRequest, ctx: PluginContext) -> EnrichmentResult:
    # call VirusTotal API here …
    return EnrichmentResult(
        indicator_type=request.indicator_type,
        indicator_value=request.indicator_value,
        enrichments={"vt_score": 72},
        malicious=True,
        confidence=0.9,
    )

Response Action (class style)

from aisoc_plugin_sdk import (
    ActionPlugin,
    ActionRequest,
    ActionResult,
    PluginManifest,
    PluginContext,
)


class BlockIPAction(ActionPlugin):
    @property
    def manifest(self) -> PluginManifest:
        return PluginManifest(
            id="myorg.block-ip",
            name="Block IP on Firewall",
            version="1.0.0",
            plugin_type="action",
        )

    def supported_actions(self) -> list[str]:
        return ["block_ip", "unblock_ip"]

    async def execute(self, request: ActionRequest, ctx: PluginContext) -> ActionResult:
        ip = request.params.get("ip")
        if request.dry_run:
            return ActionResult(
                action_id=request.action_id, success=True, dry_run=True, summary=f"Would block {ip}"
            )
        # … firewall API call …
        return ActionResult(action_id=request.action_id, success=True, summary=f"Blocked {ip}")

Connector

from typing import AsyncIterator, Any
from aisoc_plugin_sdk import ConnectorPlugin, ConnectorConfig, PluginManifest, PluginContext
from aisoc_plugin_sdk.decorators import connector

@connector(id="myorg.splunk-connector", name="Splunk Connector")
class SplunkConnector(ConnectorPlugin):
    async def test_connection(self, ctx: PluginContext) -> bool:
        # ping Splunk …
        return True

    async def fetch_events(
        self, ctx: PluginContext, since: str | None = None
    ) -> AsyncIterator[dict[str, Any]]:
        # query Splunk and yield normalised events …
        yield {"event_type": "alert", "source": "splunk", …}

Plugin Registry

from aisoc_plugin_sdk import PluginRegistry, PluginContext

registry = PluginRegistry()
registry.register(BlockIPAction())
registry.register(SplunkConnector())

ctx = PluginContext(api_base_url="http://api:8000", api_token="…")
await registry.load_all(ctx)

Development

cd packages/plugin-sdk-py
pip install -e ".[dev]"
pytest
mypy src
ruff check src

License

MIT — see LICENSE.

Metadata

Release files for aisoc-plugin-sdk 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aisoc-plugin-sdk 0.1.0
File Size Uploaded
aisoc_plugin_sdk-0.1.0.tar.gz 14.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aisoc-plugin-sdk 0.1.0
File Interpreter ABI Platform
aisoc_plugin_sdk-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 25.8 kB

Release files / aisoc_plugin_sdk-0.1.0.tar.gz

Download URL aisoc_plugin_sdk-0.1.0.tar.gz
Size 14.0 kB
Tags Source
SHA-256 checksum
How to use checksums
c66076c0240ac624c8f995c0b7b07476c52443ab2c07dc100df90755ec8266a2
BLAKE2b-256 checksum
How to use checksums
6981dd1ec6687f24d9b5bb02803ba9b5dddfdc9a8d1f0d6df98600dda2eeeb25
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / aisoc_plugin_sdk-0.1.0-py3-none-any.whl

Download URL aisoc_plugin_sdk-0.1.0-py3-none-any.whl
Size 11.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
130c4709c3107f653b420efcfb7217278bdb94fd7e1c15ea6bb3bdffce2f6966
BLAKE2b-256 checksum
How to use checksums
df77920b475b0ea3b8175d09ecd7c9b61c9c14a2dce6670c4052c0bd872408e1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page