Mission
Jessie answers analyst questions by planning and executing bounded read-only threat hunts, maps IoCs to TTPs, enriches Kelpie cases, and helps analysts understand the evidence.
One out of the box skill and knowledge I want Jessie to have is be an expert at searching Unifi API for events and logs and IoCs or just general information about what it's seen on my network.
Data sources
- Tawny endpoint telemetry and hunts.
- Sentinel/Log Analytics.
- Defender for Endpoint and Defender for Cloud.
- Approved firewall and CSPM REST connectors.
- Organisation-defined generic REST connectors.
- Kelpie cases, observables, tasks and history.
- Approved threat-intelligence sources and ATT&CK knowledge.
Responsibilities
- Turn natural-language questions into a visible query plan with time range, sources and limits.
- Resolve and normalize IP, domain, URL, hash, identity, endpoint and cloud-resource observables.
- Map evidence to MITRE ATT&CK techniques with confidence and supporting references.
- Run ad-hoc hunts, correlate results and clearly separate observed fact from inference.
- Propose Kelpie observable/finding/timeline enrichment; writes require capability and approval policy.
- Explain reasoning for new analysts, suggest next questions and teach safe hunting patterns.
- Learn only through evidence-linked notes and human-approved skill versions.
Safety
- Connector framework issue is a dependency; no unrestricted web or shell.
- Secrets never enter prompts. External results are untrusted evidence.
- Enforce query range, record, cost, runtime and concurrency limits.
- State-changing response remains separate and human-approved.
Acceptance criteria
- Jessie ships on clean install and is assignable from Tasks or @mention.
- Analyst can ask a question, inspect/approve the plan when policy requires, watch progress, cancel, and receive a typed HuntResult.
- Result contains queries, sources, evidence references, IoC/TTP mappings, confidence, gaps and recommended next steps.
- Approved enrichment appears once in the linked Kelpie case and Muster room.
- Duplicate/replayed hunts are idempotent.
- Training mode explains without exposing restricted evidence or overstating certainty.
Verification
- Multi-source correlation fixtures.
- Malicious connector-output prompt injection test.
- Tenant/capability/approval bypass tests.
- Real homelab hunt across Tawny and one Microsoft or generic connector.
- Kelpie enrichment E2E with audit-chain verification.
Mission
Jessie answers analyst questions by planning and executing bounded read-only threat hunts, maps IoCs to TTPs, enriches Kelpie cases, and helps analysts understand the evidence.
One out of the box skill and knowledge I want Jessie to have is be an expert at searching Unifi API for events and logs and IoCs or just general information about what it's seen on my network.
Data sources
Responsibilities
Safety
Acceptance criteria
Verification