Introduction¶
The core capability of DeepSeek Harness (DSH) is reflected in its event stream, but this raw data must be normalized before it can be integrated with a Security Operations Center (SOC). The role of the dsh-ocsf-forwarder plugin is to normalize DSH session activity data into OCSF 1.9.0 format and deliver it to a target receiver. It acts as a read-side SIEM forwarder, runs within the DSH agent process, and is responsible for parsing, classifying, and delivering the data.
Core Capabilities¶
The plugin primarily handles DSH session lifecycle and tool invocation behavior:
- Event Subscription and Correlation: Subscribes to
session/event,session/created, andsession/disposedevents, and scans existing sessions on mount. It can correlatetool/callwithtool/result, andapproval/askedwithapproval/decided, thereby calculating approval decision latency as a signal for “approval fatigue”. - Activity Classification and Naming: Classifies tool calls into Process Activity (1007), File System Activity (1001), HTTP Activity (4002), Authorize Session (3003), and API Activity (6003). For MCP calls, it resolves and names the underlying MCP server.
- External Delegation and Log Upload: When a tool delegates tasks to an external Harness, it emits high-severity records. It also records session log upload behavior, including destination service and event count.
- Teams and Shared Tasks: Reads team events (such as member join and message wake-up) and the write scope of shared tasks.
- Integrity Chain and Replay: Links each record to the OCSF
record_integrityprofile and supports verifying chain integrity withdsh-ocsf-verify. Supports replay recovery or constructor seeds for forked sessions. - Privacy Protection: Removes raw values from data sent to the SOC, retaining only key-value summaries, value classification, and length to avoid leaking sensitive information.
Installation and Enablement¶
Before installation, ensure the configuration file includes a runnable agent (for example @deepseek-ai/dsh-headless); otherwise the plugin will be unable to observe any events.
- Install core dependencies and the plugin:
dsh plugin --profile <name> add @deepseek-ai/dsh-headless@0.1.1-rc.2
dsh plugin --profile <name> add dsh-ocsf-forwarder
- Verify that the configuration has been mounted successfully:
dsh --profile <name> --dump-config
Notes:
* The @deepseek-ai/dsh-headless version must be explicitly pinned (for example 0.1.1-rc.2), because the latest tag still points to 0.0.1-rc.1.
* The required DSH version range is 0.1.0-rc.6 to 0.1.2.
Configuration and Delivery¶
The plugin uses a YAML configuration file to define output path, receiver, and privacy policy.
- Configure local Spool and sender (using Splunk as an example):
- id: dsh-ocsf-forwarder
config:
spoolPath: /var/log/dsh/ocsf.jsonl # 绝对路径,权限建议 0640
splunk:
endpoint: https://splunk.example:8088
token: { source: env, variable: SPLUNK_HEC_TOKEN }
privacy:
hmacKey: { source: env, variable: DSH_OCSF_KEY }
- Configure an OTLP/HTTP collector:
The configuration example is similar to Splunk; replace thesplunksection with the corresponding OTLP/HTTP configuration items.
Integrity and Verification¶
Every record includes an OCSF 1.9.0 record_integrity attestation, containing the SHA-256 fingerprints of the current record and the previous record. If intermediate records are tampered with or deleted, chain verification will fail.
- Check Spool file integrity:
dsh-ocsf-verify /var/log/dsh/ocsf.jsonl
- Return 0 means the file is intact.
- Return 1 means the chain is broken.
- Return 2 means the file is unreadable.
- Verify using an anchor file in the SIEM:
dsh-ocsf-verify --anchor shipped.jsonl /var/log/dsh/ocsf.jsonl
On Linux systems, you can use chattr +a to harden the Spool file so it rejects truncation and rewriting, thereby preventing data damage.
Applicable Scenarios and Considerations¶
- Applicable Scenarios: Organizations that need to structurally import DSH session activity into a SOC and are focused on approval fatigue analysis, external delegation detection, and session log auditing.
- Runtime Boundary: The plugin runs with the UID of the agent process and is not a containment boundary. If the agent has permission to run
bash, it can theoretically delete or rewrite the Spool file and recompute the hash chain. - Capability Boundary: The plugin never writes session logs and does not register waterfall listeners, so it cannot modify tool calls, approval decisions, or model requests. It also does not provide any detection content, alerts, or key detectors.
Summary¶
dsh-ocsf-forwarder provides a mechanism for normalizing DeepSeek Harness event streams and securely delivering them to a SOC. With OCSF 1.9.0 normalization and integrity chain verification, it ensures audit data traceability and tamper resistance.
- Catalog page: dsh-ocsf-forwarder
- Source code: GitHub Repository