DetectMateLibrary
Main library to run the different components in DetectMate.
Main structure
The library contains the next components:
- Parsers: parse the logs received from the reader.
- Detectors: return alerts if anomalies are detected.
- Alert Aggregation: aggregate the alerts produced by the detectors.
- Schemas: standard data classes use in DetectMate.
+--------+ +-----------+ +-------------------+
| Parser | --> | Detector | -> | Alert Aggregation |
+--------+ +-----------+ +-------------------+
Developer setup:
Step 1: Install python dependencies
Set up the dev environment and install pre-commit hooks:
uv sync --dev
uv run prek install
Step 2: Install Protobuf dependencies
To install in Linux do:
sudo apt install -y protobuf-compiler
protoc --version
This dependency is only needed if a proto file is modified. To compile the proto file do:
protoc --proto_path=src/detectmatelibrary/schemas/ --python_out=src/detectmatelibrary/schemas/ src/detectmatelibrary/schemas/schemas.proto
Step 3: Run unit tests
Run the tests:
uv run --dev pytest -q
Run the tests with coverage (add --cov-report=html to generate an HTML report):
uv run --dev pytest --cov=. --cov-report=term-missing
Workspace generator (mate create)
DetectMateLibrary includes a small CLI helper to bootstrap standalone workspaces for custom parsers and detectors. This is useful if you want to develop and test components in isolation while still using the same library and schemas.
Usage
The CLI entry point is mate with a create command:
mate create --type <parser|detector> --name <workspace_name> --dir <target_dir>
| Option | Description |
|---|---|
--type |
Component type to generate: - parser: CoreParser-based template- detector: CoreDetector-based template |
--name |
Name of the component and package: - Creates package dir: <target_dir>/<name>/- Creates main file: <name>.py- Derives class names: <Name> and <Name>Config |
--dir |
Directory where the workspace will be created |
What gets generated
For example:
mate create --type parser --name custom_parser --dir ./workspaces/custom_parser
will create:
workspaces/custom_parser/ # workspace root
├── custom_parser/ # Python package
│ ├── __init__.py
│ └── custom_parser.py # CoreParser-based template
├── tests/
│ └── test_custom_parser.py # generated from template to test custom_parser
├── data.json # example data to run the code
├── LICENSE.md # copied from main project
├── .gitignore # copied from main project
├── .pre-commit-config.yaml # copied from main project
├── pyproject.toml # minimal project + dev extras
└── README.md # setup instructions
Documentation
Contribution
We're happily taking patches and other contributions. Please see the following links for how to get started:
If you encounter any bugs, please create an issue on Github.
License
Release files for detectmatelibrary 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| detectmatelibrary-0.5.0.tar.gz | 105.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| detectmatelibrary-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 253.1 kB
Release files / detectmatelibrary-0.5.0.tar.gz
| Download URL | detectmatelibrary-0.5.0.tar.gz |
|---|---|
| Size | 105.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
444a433cc47884598d7ad1eddfa4856f3d99d5ca52cf0d175c2ac840e900660b
|
|
BLAKE2b-256 checksum How to use checksums |
e04ae3a2db55ea8ea95d645974b3a89402bb0632728abac54042512fbd83de95
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency logRelease files / detectmatelibrary-0.5.0-py3-none-any.whl
| Download URL | detectmatelibrary-0.5.0-py3-none-any.whl |
|---|---|
| Size | 147.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
84ea1232df100478cddda2265f9251b6d1220d3306bd4ecfb752745f311b1e3b
|
|
BLAKE2b-256 checksum How to use checksums |
57cefae1acc4783e854f2bb63b89d8e945cd5b7f5f2584c97f027e139eb87ff0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency log