SKILL.md
QMEDR 安全运营调查
开始前必须先读取 [../qmedr-shared/SKILL.md](../qmedr-shared/SKILL.md),或执行 qmedr skills read qmedr-shared;未读取不得执行 qmedr 命令。使用 binary reader 时以该命令 stdout 的正文为准,同时保留 stderr guidance。
精确边界
处理 QMEDR 安全运营链:
Endpoint → collect → Record → detect → Signal → aggregate → Incident
endpoint:受管主机/Agent 资产。signal:聚合为事件前的检测发现。incident:由信号聚合形成的威胁事件。overview:服务端 metadata 提供的安全态势概览。
不处理普通 shell 终端、命令行窗口、日历事件、埋点事件或一般业务事件。遥测 SQL 转 qmedr-hunt(先执行 qmedr skills read qmedr-hunt);策略转 qmedr-policy(先执行 qmedr skills read qmedr-policy);灰度任务、失败统计、崩溃与 dump 转 qmedr-devops(先执行 qmedr skills read qmedr-devops)。
标识符
- Endpoint API:EID。
- Incident API:incident UUID。
- Signal API:signal UUID。
- Hunt 按终端过滤:`
device.uid,值与 EID 相同;不存在eid` 列。 - 单条遥测:`
metadata.uid`,不是 endpoint EID。
详情与跨域传递规则见 [实体与标识符](references/entities-and-ids.md)。
查询流程
每次先确认当前资源和参数:
qmedr describe endpoint --format json
qmedr describe incident --format json
qmedr describe signal --format json
只读取任务需要的资源描述。典型稳定只读底座:
qmedr endpoint get <EID> --format json
qmedr incident get <INCIDENT_UUID> --format json
qmedr signal get <SIGNAL_UUID> --format json
筛选、分页、count 与 group-by 先读 [列表与统计](references/list-and-count.md),并以 describe 返回的当前 flag 为准。overview 不是离线能力;必须先 qmedr describe overview --format json。
调查工作流
endpoint +investigate、incident +investigate、signal +investigate 当前都是占位命令,调用会返回 exit 2。不要把它们当作自动调查能力。
可用替代编排:
识别输入 ID 类型
→ get 主实体
→ 从响应提取 EID、RuleID、关联 UUID 与时间范围
→ describe 后用 list/count 查询关联 endpoint/signal/incident
→ hunt 可用时,先执行 qmedr skills read qmedr-hunt,再按 EID + UTC 时间窗补充遥测
→ 区分事实、关联和推断,输出证据链
具体步骤见 [调查编排](references/investigation.md)。
写操作
assign、judge、edit 等写 verb 只在服务端 metadata 提供且本地为 operate 时出现。不得因文档示例假定存在,必须按 shared 的 dry-run → 展示 plan → 用户确认 → --apply 流程。任务确需写入时读取 [写操作](references/write-actions.md)。
References
- ID 解析或跨域关联:[entities-and-ids.md](references/entities-and-ids.md)
- list/count、时间和分页:[list-and-count.md](references/list-and-count.md)
- 告警/实体调查:[investigation.md](references/investigation.md)
- 用户明确要求处置写入:[write-actions.md](references/write-actions.md)