qmedr-1258344699.cos.ap-guangzhou.myqcloud.com

qmedr-secops

QMEDR 安?

First seen Jul 14, 2026

Installation

$ npx skills add https://qmedr-1258344699.cos.ap-guangzhou.myqcloud.com

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from qmedr-1258344699.cos.ap-guangzhou.myqcloud.com.

npx skills add https://qmedr-1258344699.cos.ap-guangzhou.myqcloud.com

Browse all from qmedr-1258344699.cos.ap-guangzhou.myqcloud.com

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Version0.2.4
More metadata
requires
{"bins":["qmedr"]}
cliHelp
qmedr endpoint --help; qmedr signal --help; qmedr incident --help
qmedr
{"testedCliVersion":"0.2.4","cliVersion":">=0.2.0 <0.3.0"}

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,930 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 48 installs

SKILL.md

QMEDR 安全运营调查

开始前必须先读取 [../qmedr-shared/SKILL.md](../qmedr-shared/SKILL.md),或执行 qmedr skills read qmedr-shared;未读取不得执行 qmedr 命令。使用 binary reader 时以该命令 stdout 的正文为准,同时保留 stderr guidance。

精确边界

处理 QMEDR 安全运营链:

Endpoint → collect → Record → detect → Signal → aggregate → Incident
  • endpoint:受管主机/Agent 资产。
  • signal:聚合为事件前的检测发现。
  • incident:由信号聚合形成的威胁事件。
  • overview:服务端 metadata 提供的安全态势概览。

不处理普通 shell 终端、命令行窗口、日历事件、埋点事件或一般业务事件。遥测 SQL 转 qmedr-hunt(先执行 qmedr skills read qmedr-hunt);策略转 qmedr-policy(先执行 qmedr skills read qmedr-policy);灰度任务、失败统计、崩溃与 dump 转 qmedr-devops(先执行 qmedr skills read qmedr-devops)。

标识符

  • Endpoint API:EID。
  • Incident API:incident UUID。
  • Signal API:signal UUID。
  • Hunt 按终端过滤:` device.uid ,值与 EID 相同;不存在 eid` 列。
  • 单条遥测:` metadata.uid `,不是 endpoint EID。

详情与跨域传递规则见 [实体与标识符](references/entities-and-ids.md)。

查询流程

每次先确认当前资源和参数:

qmedr describe endpoint --format json
qmedr describe incident --format json
qmedr describe signal --format json

只读取任务需要的资源描述。典型稳定只读底座:

qmedr endpoint get <EID> --format json
qmedr incident get <INCIDENT_UUID> --format json
qmedr signal get <SIGNAL_UUID> --format json

筛选、分页、count 与 group-by 先读 [列表与统计](references/list-and-count.md),并以 describe 返回的当前 flag 为准。overview 不是离线能力;必须先 qmedr describe overview --format json。

调查工作流

endpoint +investigate、incident +investigate、signal +investigate 当前都是占位命令,调用会返回 exit 2。不要把它们当作自动调查能力。

可用替代编排:

识别输入 ID 类型
→ get 主实体
→ 从响应提取 EID、RuleID、关联 UUID 与时间范围
→ describe 后用 list/count 查询关联 endpoint/signal/incident
→ hunt 可用时,先执行 qmedr skills read qmedr-hunt,再按 EID + UTC 时间窗补充遥测
→ 区分事实、关联和推断,输出证据链

具体步骤见 [调查编排](references/investigation.md)。

写操作

assign、judge、edit 等写 verb 只在服务端 metadata 提供且本地为 operate 时出现。不得因文档示例假定存在,必须按 shared 的 dry-run → 展示 plan → 用户确认 → --apply 流程。任务确需写入时读取 [写操作](references/write-actions.md)。

References

  • ID 解析或跨域关联:[entities-and-ids.md](references/entities-and-ids.md)
  • list/count、时间和分页:[list-and-count.md](references/list-and-count.md)
  • 告警/实体调查:[investigation.md](references/investigation.md)
  • 用户明确要求处置写入:[write-actions.md](references/write-actions.md)