Skip to content

Latest commit

 

History

87 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

COPS — Copilot Operations Plugins for Security

COPS shield and copilot visor logo

Documentation Site Python 3.11+ License Offline First MITRE ATT&CK v18.0 Universal Portability

Welcome to COPS (Copilot Operations Plugins for Security)! COPS is an open-source, universal catalog of defensive cybersecurity plugins, 18 specialist agent profiles, and deterministic offline verification tools.

Whether your team works in GitHub Copilot, Claude Code, or Codex / ChatGPT, COPS provides production-grade cybersecurity capabilities without ecosystem lock-in. Everything is designed offline-first: you can explore tools, run demos, and validate detection logic directly from your local terminal using standard Python—no cloud credentials, assistant installations, or live tenant connections required.

📖 Visit the complete COPS Documentation Website for interactive guides, playbooks, and reference architectures.


Five-Minute Quickstart

All you need is Python 3.11 or newer. These commands use only the Python standard library and make zero external network calls:

# 1. Clone the repository and enter the directory
git clone https://github.com/sodejm/copilot-operation-plugin-for-security.git
cd copilot-operation-plugin-for-security

# 2. Check your local environment health
python3 -m cops doctor

# 3. List all 13 available security plugins and their status
python3 -m cops list

# 4. Route any natural language task to the best specialist agent
python3 -m cops route "Optimize Microsoft Sentinel KQL query for sign-in anomalies"

# 5. Inspect details and operational playbooks for a plugin
python3 -m cops info sentinel-hunt-workbench

# 6. Run a safe, offline demonstration with synthetic data
python3 -m cops demo sentinel-hunt-workbench

# 7. Run the plugin's complete offline test suite
python3 -m cops check sentinel-hunt-workbench

What these commands do for you

  • cops doctor: Quickly checks that your Python environment is ready and your package catalogs are in sync.
  • cops list: Displays the thirteen available security plugins, their maturity stage, and their validation status.
  • cops route: Deterministically routes any natural language task to the optimal specialist profile with zero LLM token cost.
  • cops demo: Runs a self-contained, offline walkthrough using synthetic test data.
  • cops check: Executes deterministic verification suites (syntax checks, schema tests, mutation tests) right on your machine.

Available Security Plugins (13 Packages)

Each package lives in its own self-contained directory under plugins/<category>/<plugin-id>/ and includes a complete practitioner playbook:

Security Plugin Category Maturity What it solves Try it out
Security Logging Advisor Logging & Telemetry Stable Audits codebases for security logging gaps, flags sensitive data leaks, and prioritizes CVE reachability. python3 -m cops demo security-logging-advisor
Telemetry Proof Pack Logging & Telemetry Beta Verifies end-to-end telemetry routes and pipeline health from Cribl Stream to Splunk and Sentinel. python3 -m cops check telemetry-proof-pack
SOC Investigation Workbench Detection & Hunting Beta Guides alert triage using competing hypotheses, question ranking, and evidence dependency graphs. python3 -m cops demo soc-investigation-workbench
Sentinel Hunt Workbench Detection & Hunting Beta Authors, adapts, and stress-tests 12 defensive Microsoft Sentinel and Defender KQL threat hunts offline. python3 -m cops demo sentinel-hunt-workbench
Attack Path Workbench Detection & Hunting Experimental Traces multi-hop cloud lateral movement paths from local exports to crown jewels and finds choke points. python3 -m cops demo attack-path-workbench
Detection Quality Workbench Detection & Hunting Beta Validates detection syntax, regressions, and quality metrics across Microsoft Sentinel KQL and Splunk SPL. python3 -m cops check detection-quality-workbench
Threat Intelligence Enrichment Detection & Hunting Experimental Enriches network, host, and hash indicators with provenance-tracked threat intelligence metadata. python3 -m cops check threat-intelligence-enrichment
Entra Identity Workbench Identity & Access Beta Evaluates Entra ID role assignments, service principals, consent grants, and credential exposures. python3 -m cops check entra-identity-workbench
Exposure Triage Workbench Vulnerability Management Beta Prioritizes vulnerability triage by correlating advisory CVEs, SBOM components, and call graph reachability. python3 -m cops check exposure-triage-workbench
Patch Security Review Vulnerability Management Beta Analyzes code patches and pull request diffs for dangerous patterns, authorization flaws, and regression risks. python3 -m cops check patch-security-review
Attack Surface Planner Offensive Security Experimental Translates authorized rules of engagement into bounded, passive review plans from local export manifests. python3 -m cops demo attack-surface-planner
Foundry Agent Harness Offensive Security Beta Evaluates AI agent behavior, prompt injection resistance, and safety boundaries in a simulated sandbox. python3 -m cops check foundry-agent-harness
Incident Response Sandbox Incident Response Beta Rehearses containment workflows, calculates blast radius, and generates cryptographic execution receipts. python3 -m cops check incident-response-sandbox

For in-depth guidance on choosing the right plugin for your operational scenario, see the When to Use Each Plugin Guide.


18 Specialist Cybersecurity Agent Profiles & Dynamic Routing

COPS centralizes 18 specialist cybersecurity agent profiles in agents/ across offensive, defensive, forensics, identity, and governance disciplines. The deterministic zero-token router dynamically matches incoming tasks to the best specialist profile:

# Route any security request or natural language task:
python3 -m cops route "Optimize this Sentinel KQL query for low ingestion cost"

# List all 18 specialist profiles:
python3 -m cops specialists

For high-risk operations (e.g. penetration testing, red team emulation, active containment, or cloud privilege escalation), COPS automatically activates Triad Orchestration (Primary Specialist + Domain Skeptic + Evidence Auditor) with mandatory interactive operator authorization. Read the Specialist Agents Guide for architecture details.


MITRE ATT&CK & Attack Flow Coverage

COPS capability logic, queries, and investigation workflows are formally mapped to the MITRE ATT&CK Enterprise Matrix (pinned v18.0) and MITRE Attack Flow:

  • MITRE ATT&CK Coverage Matrix: Explore normalized technique mappings, coverage roles, validation states, and known bypass confounders.
  • Coverage & Attack Flow Guide: Gap analysis separating missing telemetry from missing analytics, representative STIX 2.1 Attack Flow exports, and authoring guidelines.

How Universal Portability Works

Different AI assistants expect different file structures, manifests, and skill formats. COPS removes that headache through automated, drift-free synchronization:

  1. One Source of Truth: The central inventory in catalog/plugins.json defines all package metadata, versions, and categories.
  2. Standardized Packages: Each plugin maintains its core Agent Plugins v1.0.0 manifest (plugin.json), host manifests (.claude-plugin/, .codex-plugin/), and reusable skills.
  3. Automated Host Marketplaces: Running python3 -m cops generate automatically creates and synchronizes configuration files for:
    • GitHub Copilot: .github/plugin/marketplace.json
    • Claude Code: .claude-plugin/marketplace.json
    • Codex / ChatGPT: .agents/plugins/marketplace.json
  4. Guaranteed Consistency: Our test gates verify that host indexes never drift out of sync with the catalog.

Learn more in the Portability Architecture and Repository Layout guides.


Contributor Setup

If you want to contribute new plugins, skills, or core features:

# Set up a dedicated virtual environment
python3 -m venv .venv
source .venv/bin/activate

# Install development test dependencies
python3 -m pip install -r requirements.txt

# Run the complete test suite
make check-prerequisites
make check PYTHON=.venv/bin/python

(On Windows PowerShell, run .\.venv\Scripts\Activate.ps1 to activate your environment).

Before creating new plugins or modifying contracts, please review:


Evidence & Safety Principles

In security engineering, confidence comes from verification:

  • Offline Safety: Demos and checks run against local synthetic test data. They never make unreviewed network calls or write to remote production services.
  • Clear Status Separation: We clearly separate what has been validated locally from what remains unverified in a live cloud environment. A passing offline test proves code correctness—it does not claim your production SIEM is currently receiving live alerts.
  • Data Privacy: Tools treat all input code and logs as sensitive data. They do not store credentials or transmit telemetry to third parties.
  • Truth-in-Advertising: Capabilities are audited into four operational readiness modes (planned, import, laboratory, live-validated), with zero false live claims.

License & Attribution

Plugin execution cost analysis

Contributors can use plugin-run-cost to measure explicitly assigned COPS runs, estimate input scaling, and compare API, local-tool and employee costs. It runs locally with synthetic examples, preserves unknown charges, and distinguishes API-equivalent estimates from actual bills.

About

Universal offline-first cybersecurity plugin catalog & 18 specialist AI agent profiles for GitHub Copilot, Claude Code, and Codex. Offline demos, MITRE ATT&CK v18.0, and deterministic verification.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

1 watching

Forks

Releases

Used by

Contributors

Languages