Metadata-Version: 2.5
Name: aisoc-cli
Version: 0.1.0
Summary: AiSOC Developer CLI — scaffold, validate, and publish plugins and detections
Project-URL: Homepage, https://github.com/beenuar/AiSOC
Project-URL: Documentation, https://github.com/beenuar/AiSOC#readme
Project-URL: Repository, https://github.com/beenuar/AiSOC
Author-email: Beenu Arora <beenu@cyble.com>
License: MIT
Keywords: aisoc,cli,plugin,security,soc
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Requires-Python: >=3.11
Requires-Dist: click>=8.1
Requires-Dist: cryptography<51,>=46
Requires-Dist: httpx>=0.27
Requires-Dist: jsonschema>=4.21
Requires-Dist: pyyaml>=6.0
Requires-Dist: rich>=13.7
Requires-Dist: structlog>=24.1
Provides-Extra: dev
Requires-Dist: mypy<3,>=2.3.1; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff<0.17,>=0.16.8; extra == 'dev'
Description-Content-Type: text/markdown

# aisoc-cli

Developer CLI for building, validating, and publishing AiSOC plugins and detection rules.

> **Status — monorepo today, not yet on PyPI.** The CLI ships from this monorepo and is fully functional today. `pip install aisoc-cli` does not resolve: the upload is blocked on registry credentials, which is an account action rather than a code change. The CLI name (`aisoc`) and command surface stay identical once it ships.

## Installation

```bash
# Today (from this monorepo):
git clone https://github.com/beenuar/AiSOC.git
cd AiSOC && pip install -e packages/aisoc-cli

# Not yet on PyPI — the upload is blocked on registry credentials,
# which is an account action rather than a code change. Until then, install
# from source with the command above.
#   pipx install aisoc-cli     # recommended (isolated venv)
#   pip install aisoc-cli
```

## Commands

### Plugin Scaffold
```bash
aisoc plugin scaffold my-enricher
aisoc plugin scaffold my-connector --type connector
```

### Plugin Validate
```bash
aisoc plugin validate ./my-enricher
aisoc plugin validate ./my-enricher/plugin.yaml
```

### Plugin Publish
```bash
export AISOC_API_URL=https://api.example.com
export AISOC_API_KEY=sk-...
aisoc plugin publish ./my-enricher
```

### Detection Validate
```bash
aisoc detection validate ./detections/brute-force.yaml
```

### Key Generation
```bash
aisoc keygen              # generates ~/.aisoc/signing.key + signing.pub
```

## Environment Variables

| Variable | Description |
|---|---|
| `AISOC_API_URL` | AiSOC API base URL (default: `http://localhost:8000`) |
| `AISOC_API_KEY` | API key for authentication |
| `AISOC_SIGNING_KEY` | Path to Ed25519 private key (default: `~/.aisoc/signing.key`) |
