Works for all three deployment modes. Mode-specific steps come after.
- SANS SIFT Workstation (Ubuntu 22.04 LTS based)
- Python 3.12 or later
- Git
- Protocol SIFT installed
Verify:
python3 --version # >= 3.12
git --version
which protocol-sift # should exist after Protocol SIFT installgit clone https://github.com/aptwatcher/APTWatcher.git
cd APTWatcherAPTWatcher uses a single Python package (aptwatcher) that holds the
shared brain (src/core/), the MCP server entry point (src/mcp_server/),
and the agent-extension entry point (src/agent_extension/). One install
gives you all three.
python3 -m venv .venv
source .venv/bin/activate
pip install -e .After install, you should have on your PATH:
aptwatcher-preflight— run the SIFT environment probeaptwatcher-mcp-server— launch the MCP server (Mode B)aptwatcher— CLI entry for the agent-extension scripts (Mode A)
APTWatcher reads config.yaml at repo root (or $APTWATCHER_CONFIG).
A minimal starter:
tiers:
tier_0: true # core forensic triage (always on)
tier_1: false # external threat intel
tier_2: false # IR workflow (GLPI)
tier_3: false # defensive containment
tier_4: false # offensive containment (requires second flag)
profile: windows-host-triage # see docs/use-cases/
audit:
log_dir: ./logs
rotation: daily
# Only read if the matching tier is enabled
intel:
apt_watch:
base_url: https://api.aptwatch.org
api_key_env: APTWATCH_API_KEY
ms_threat_analytics:
mcp_stdio_cmd: /usr/local/bin/ms-threat-analytics-mcpCredentials are never read from this file — only the environment variable names are. Export the actual secret in your shell:
export APTWATCH_API_KEY='…'Run the preflight probe:
aptwatcher-preflight --profile windows-host-triageYou should see a report listing each required tool with its version. Missing tools → install them before proceeding. See Use cases for what each profile requires.
Pick your mode:
Or run the quick start: Try it out.
!!! note "In development" APTWatcher is pre-alpha. Commands and config above reflect the target design; implementation is in progress. See the GitHub issue tracker for current status.