-
Notifications
You must be signed in to change notification settings - Fork 8.6k
Security attachments in Agent Builder #243574
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
stephmilovic
merged 118 commits into
elastic:main
from
stephmilovic:security_alert_attachment_with_tool
Dec 4, 2025
Merged
Changes from 52 commits
Commits
Show all changes
118 commits
Select commit
Hold shift + click to select a range
682a7e1
wip
stephmilovic a15330a
wip more, graph instructions
stephmilovic 7bc16c0
wip
stephmilovic 4ece3ed
working?
stephmilovic be8e838
idk
stephmilovic 9eb85ed
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 81da0e6
evaluate alert tool
stephmilovic 801522b
Alert attachments specific workflow
stephmilovic fbcd6db
security specific tools
stephmilovic 35c03a2
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 2b41a64
fixings
stephmilovic 372ffc9
add core alert attachment type
stephmilovic 8a302de
Pierre change
stephmilovic f104122
core alert index hardcoded
stephmilovic bcc390e
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic 469dc18
attack discovery tool improvements
stephmilovic 832b747
fixing
stephmilovic fe9b3cf
fixing
stephmilovic 37256be
alert attachment works
stephmilovic a43976d
entities
stephmilovic 8294772
cases tool added to platform
stephmilovic c3ce0e9
by alert id
stephmilovic b092f5b
cases tool better
stephmilovic 5500486
improvements
stephmilovic 5fb7169
attack discovery
stephmilovic 1a0d535
revert
stephmilovic 3fed38a
cases tool improvments
stephmilovic a088b66
fixing
stephmilovic 2f49c63
agentBuilderEnabled
stephmilovic 7ebc3c0
useAgentBuilderAttachment
stephmilovic 348b504
add risk entity
stephmilovic 1c2fa8a
fix entity risk
stephmilovic f925a78
entity risk done
stephmilovic 866f483
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic e5e90c7
move attachment definitons
stephmilovic 3441fc9
fix whitespace
stephmilovic 2786c24
fixing
stephmilovic 34f4f1f
rm logs
stephmilovic 627773d
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic 8738c0e
add product reference attachment
stephmilovic 42c3fc2
rules agent step
stephmilovic 141fbcc
pre rule creation attachment
stephmilovic 47fa1de
coreSecurity => security
stephmilovic 7d10732
query help added
stephmilovic 70257fc
use query help
stephmilovic 3124311
generic entity
stephmilovic c1b915e
EASE
stephmilovic 1929c9d
cleanup
stephmilovic a30c59c
risk_entity => entity_risk
stephmilovic fc8eefe
simplify
stephmilovic eff1f4a
rm outdated tool refs
stephmilovic fcaf3d0
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic d4f8c09
use actual AB flyout!
stephmilovic fbd4bd8
rm mandatory workflow, include sessionTag
stephmilovic a922634
entity risk conditional
stephmilovic 3aec4f1
better
stephmilovic 83c1709
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic e11d926
fix structure
stephmilovic 75adb9c
registration cleanup
stephmilovic 19435a7
make security agent
stephmilovic ee63b8b
one alert attachment
stephmilovic 8cb1c6e
simplify attachment descriptions
stephmilovic 86bdf41
tweak
stephmilovic 89170f3
fixes
stephmilovic 8e667c0
move fn
stephmilovic cb5730d
risk_entity => entity
stephmilovic 49f0f67
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic 6b26745
testing
stephmilovic e7e4f2e
zIndex
stephmilovic f710744
Changes from node scripts/lint_ts_projects --fix
kibanamachine 83697e6
Changes from node scripts/regenerate_moon_projects.js --update
kibanamachine 95afa72
fix import
stephmilovic 0e2c037
Merge branch 'security_alert_attachment_with_tool' of github.com:step…
stephmilovic 1b2a73c
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic 583cffd
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 6a3aecd
use real platformCoreTools.productDocumentation tool
stephmilovic 97797ab
Changes from node scripts/eslint_all_files --no-cache --fix
kibanamachine 2763503
fixing
stephmilovic f9cbc4d
Merge branch 'security_alert_attachment_with_tool' of github.com:step…
stephmilovic 3f95673
new agent builder dirs to CODEOWNERS
stephmilovic 0ca2a14
ownFocus={false}
stephmilovic cf2090a
fix lint
stephmilovic 12d5723
fixes
stephmilovic 8f7807f
more fixies
stephmilovic a556166
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic de68208
fixing
stephmilovic d8d5013
rm unused file
stephmilovic 6456fda
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic 742b6d9
Changes from node scripts/lint_ts_projects --fix
kibanamachine 4854790
Changes from node scripts/regenerate_moon_projects.js --update
kibanamachine b70225b
roles
stephmilovic db2a842
Merge branch 'security_alert_attachment_with_tool' of github.com:step…
stephmilovic 6fb5cc0
rule attachment type
stephmilovic 22fb29a
type fix
stephmilovic 73db09d
test fix
stephmilovic 46d3e3b
type fixing
stephmilovic 99d4ca3
moar
stephmilovic 2efe7e3
another
stephmilovic 5359728
nother
stephmilovic 1751dbe
rm export file
stephmilovic 1abd9e1
Merge remote-tracking branch 'upstream/main' into security_alert_atta…
stephmilovic d886267
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 8f183ee
rm unused prompt
stephmilovic 5e29ae0
attack discovery availability
stephmilovic 33c6c19
Changes from node scripts/eslint_all_files --no-cache --fix
kibanamachine 56079e4
role fix
stephmilovic 3ac7821
Merge branch 'security_alert_attachment_with_tool' of github.com:step…
stephmilovic 4bc5f23
rm todo
stephmilovic 7cece48
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 03a8729
maxim PR comments
stephmilovic 63e3b9e
robot button!
stephmilovic b49a60f
better entity tool
stephmilovic 43a2c38
update onechat limits
stephmilovic 1b7fdc3
test fixing
stephmilovic f89221c
Merge branch 'main' into security_alert_attachment_with_tool
elasticmachine 3babba1
fix type
stephmilovic 13a5e8a
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic 3372463
Merge branch 'main' into security_alert_attachment_with_tool
stephmilovic File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -34,6 +34,7 @@ | |
| "kibanaReact" | ||
| ], | ||
| "optionalPlugins": [ | ||
| "cases", | ||
| "cloud", | ||
| "licenseManagement", | ||
| "workflowsManagement", | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
73 changes: 73 additions & 0 deletions
73
...tform/plugins/shared/onechat/server/services/attachments/definitions/product_reference.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,73 @@ | ||
| /* | ||
| * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one | ||
| * or more contributor license agreements. Licensed under the Elastic License | ||
| * 2.0; you may not use this file except in compliance with the Elastic License | ||
| * 2.0. | ||
| */ | ||
|
|
||
| import type { ProductReferenceAttachmentData } from '@kbn/onechat-common/attachments'; | ||
| import { | ||
| AttachmentType, | ||
| productReferenceAttachmentDataSchema, | ||
| } from '@kbn/onechat-common/attachments'; | ||
| import type { AttachmentTypeDefinition } from '@kbn/onechat-server/attachments'; | ||
| import { sanitizeToolId } from '@kbn/onechat-genai-utils/langchain'; | ||
|
|
||
| /** | ||
| * Creates the definition for the `product_reference` attachment type. | ||
| */ | ||
| export const createProductReferenceAttachmentType = (): AttachmentTypeDefinition< | ||
| AttachmentType.product_reference, | ||
| ProductReferenceAttachmentData | ||
| > => { | ||
| return { | ||
| id: AttachmentType.product_reference, | ||
| validate: (input) => { | ||
| const parseResult = productReferenceAttachmentDataSchema.safeParse(input); | ||
| if (parseResult.success) { | ||
| return { valid: true, data: parseResult.data }; | ||
| } else { | ||
| return { valid: false, error: parseResult.error.message }; | ||
| } | ||
| }, | ||
| format: (attachment) => { | ||
| return { | ||
| getRepresentation: () => { | ||
| return { type: 'text', value: formatProductReferenceData(attachment.data) }; | ||
| }, | ||
| }; | ||
| }, | ||
| // TODO use real tool once https://github.com/elastic/kibana/pull/242598 merges, same in description below | ||
| getTools: () => [`platformCoreTools.productDocumentation`], | ||
| getAgentDescription: () => { | ||
| const description = `You have access to a product reference that needs to be queried for documentation. | ||
|
|
||
| PRODUCT REFERENCE DATA: | ||
| {productReferenceData} | ||
|
|
||
| --- | ||
| MANDATORY WORKFLOW: | ||
|
|
||
| 1. Extract the query or topic from the product reference data above. | ||
|
|
||
| 2. Query PRODUCT DOCUMENTATION for relevant documentation: | ||
| Tool: ${sanitizeToolId(`platformCoreTools.productDocumentation`)} | ||
| Parameters: { | ||
| query: "[extracted query or topic from the product reference]", | ||
| product: "[optional: 'kibana' | 'elasticsearch' | 'observability' | 'security']", | ||
| max: 3 | ||
| }`; | ||
| return description; | ||
| }, | ||
| }; | ||
| }; | ||
|
|
||
| /** | ||
| * Formats product reference data for display. | ||
| * | ||
| * @param data - The product reference attachment data containing the text | ||
| * @returns Formatted string representation of the product reference data | ||
| */ | ||
| const formatProductReferenceData = (data: ProductReferenceAttachmentData): string => { | ||
| return data.text; | ||
| }; |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just for context:
For 9.4, we plan to remove the
entity_risk_scoretool and replace it with a natural-language threat-hunting agent/tool. Read more in the POC: #240398There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ok, you will need to do this for both assistant and the new agent builder tool I've added here. I can help