{"tools":[{"name":"correlate","owner":"correlate","description":"Send the incident's raw SIEM events to the Correlate service and get back observations, relationships, and scored attack chains. Run this FIRST — everything else builds on its output.","risk":"read-only","timeoutMs":15000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"map_attack","owner":"investigate","description":"Map the correlated observations onto MITRE ATT&CK techniques and produce an ordered kill chain by tactic. Use to explain adversary progression.","risk":"read-only","timeoutMs":2000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"lookup_technique","owner":"investigate","description":"Look up one technique in the pinned official Enterprise ATT&CK 19.1 STIX subset.","risk":"read-only","timeoutMs":1000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"search_techniques","owner":"investigate","description":"Search the pinned official Enterprise ATT&CK 19.1 STIX subset by ID, name, or tactic.","risk":"read-only","timeoutMs":1000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"build_timeline","owner":"investigate","description":"Return the correlated observations in chronological order, optionally scoped to an entity id. Use to reconstruct the sequence of events.","risk":"read-only","timeoutMs":2000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"verify_claim","owner":"evidence","description":"Send a factual claim about the incident to the Evidence service for verification, attaching correlated observations/relationships as evidence. Returns a verdict (SUPPORTED / UNSUPPORTED / …) with per-rule checks and a signed digest. Use to validate the key conclusion.","risk":"read-only","timeoutMs":12000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"}],"dependencies":[{"name":"correlate","state":"READY","mode":"remote","target":"https://correlate.platphormnews.com","url":"https://correlate.platphormnews.com/api/health","method":"GET","httpStatus":200,"responseSchema":"Envelope{ok,data:CorrelateHealth{status,service,version,contractVersion,ruleSet,storage},error,meta} or legacy CorrelateHealth","auth":"none","durationMs":84,"observedAt":"2026-09-01T02:55:04.166Z","error":null},{"name":"evidence","state":"READY","mode":"remote","target":"https://evidence.platphormnews.com","url":"https://evidence.platphormnews.com/api/health","method":"GET","httpStatus":200,"responseSchema":"Envelope{ok,data:EvidenceHealth{service,status,engine,checks},error,meta}","auth":"none","durationMs":96,"observedAt":"2026-09-01T02:55:04.191Z","error":null},{"name":"attack","state":"READY","mode":"local-engine","target":"pinned ATT&CK mapping engine","url":null,"method":null,"httpStatus":null,"responseSchema":"pinned ATT&CK 19.1 bundle","auth":"none","durationMs":0,"observedAt":"2026-09-01T02:55:04.191Z","error":null}]}