Introduction

The core capability of DeepSeek Harness (DSH) is reflected in its event stream, but this raw data must be normalized before it can be integrated with a Security Operations Center (SOC). The role of the dsh-ocsf-forwarder plugin is to normalize DSH session activity data into OCSF 1.9.0 format and deliver it to a target receiver. It acts as a read-side SIEM forwarder, runs within the DSH agent process, and is responsible for parsing, classifying, and delivering the data.

Core Capabilities

The plugin primarily handles DSH session lifecycle and tool invocation behavior:

  1. Event Subscription and Correlation: Subscribes to session/event, session/created, and session/disposed events, and scans existing sessions on mount. It can correlate tool/call with tool/result, and approval/asked with approval/decided, thereby calculating approval decision latency as a signal for “approval fatigue”.
  2. Activity Classification and Naming: Classifies tool calls into Process Activity (1007), File System Activity (1001), HTTP Activity (4002), Authorize Session (3003), and API Activity (6003). For MCP calls, it resolves and names the underlying MCP server.
  3. External Delegation and Log Upload: When a tool delegates tasks to an external Harness, it emits high-severity records. It also records session log upload behavior, including destination service and event count.
  4. Teams and Shared Tasks: Reads team events (such as member join and message wake-up) and the write scope of shared tasks.
  5. Integrity Chain and Replay: Links each record to the OCSF record_integrity profile and supports verifying chain integrity with dsh-ocsf-verify. Supports replay recovery or constructor seeds for forked sessions.
  6. Privacy Protection: Removes raw values from data sent to the SOC, retaining only key-value summaries, value classification, and length to avoid leaking sensitive information.

Installation and Enablement

Before installation, ensure the configuration file includes a runnable agent (for example @deepseek-ai/dsh-headless); otherwise the plugin will be unable to observe any events.

  1. Install core dependencies and the plugin:
dsh plugin --profile <name> add @deepseek-ai/dsh-headless@0.1.1-rc.2
dsh plugin --profile <name> add dsh-ocsf-forwarder
  1. Verify that the configuration has been mounted successfully:
dsh --profile <name> --dump-config

Notes:
* The @deepseek-ai/dsh-headless version must be explicitly pinned (for example 0.1.1-rc.2), because the latest tag still points to 0.0.1-rc.1.
* The required DSH version range is 0.1.0-rc.6 to 0.1.2.

Configuration and Delivery

The plugin uses a YAML configuration file to define output path, receiver, and privacy policy.

  1. Configure local Spool and sender (using Splunk as an example):
- id: dsh-ocsf-forwarder
  config:
    spoolPath: /var/log/dsh/ocsf.jsonl      # 绝对路径,权限建议 0640
    splunk:
      endpoint: https://splunk.example:8088
      token: { source: env, variable: SPLUNK_HEC_TOKEN }
    privacy:
      hmacKey: { source: env, variable: DSH_OCSF_KEY }
  1. Configure an OTLP/HTTP collector:
    The configuration example is similar to Splunk; replace the splunk section with the corresponding OTLP/HTTP configuration items.

Integrity and Verification

Every record includes an OCSF 1.9.0 record_integrity attestation, containing the SHA-256 fingerprints of the current record and the previous record. If intermediate records are tampered with or deleted, chain verification will fail.

  1. Check Spool file integrity:
dsh-ocsf-verify /var/log/dsh/ocsf.jsonl
  • Return 0 means the file is intact.
  • Return 1 means the chain is broken.
  • Return 2 means the file is unreadable.
  1. Verify using an anchor file in the SIEM:
dsh-ocsf-verify --anchor shipped.jsonl /var/log/dsh/ocsf.jsonl

On Linux systems, you can use chattr +a to harden the Spool file so it rejects truncation and rewriting, thereby preventing data damage.

Applicable Scenarios and Considerations

  • Applicable Scenarios: Organizations that need to structurally import DSH session activity into a SOC and are focused on approval fatigue analysis, external delegation detection, and session log auditing.
  • Runtime Boundary: The plugin runs with the UID of the agent process and is not a containment boundary. If the agent has permission to run bash, it can theoretically delete or rewrite the Spool file and recompute the hash chain.
  • Capability Boundary: The plugin never writes session logs and does not register waterfall listeners, so it cannot modify tool calls, approval decisions, or model requests. It also does not provide any detection content, alerts, or key detectors.

Summary

dsh-ocsf-forwarder provides a mechanism for normalizing DeepSeek Harness event streams and securely delivering them to a SOC. With OCSF 1.9.0 normalization and integrity chain verification, it ensures audit data traceability and tamper resistance.