PersonalSOC
個人資安營運中心
PersonalSOC 會彙整本裝置的日誌與防護狀況,產生便於發現異常的報告。它是一個小型資安營運中心(SOC),面向沒有專職資安人員的個人,讓您帶著依據瞭解自己裝置的狀況,並決定下一步行動。
它隨 RoamSwitch 安裝程式一同提供,但是獨立於 RoamSwitch 的應用程式(有自己的圖示)。即使沒有安裝 RoamSwitch 也能使用。
一鍵檢查狀況
只需按下「檢查狀況」,就會以唯讀方式檢查本裝置的日誌(依作業系統:SSH 驗證、auditd、Web、DNS、macOS 統一日誌)、MCP 設定以及 RoamSwitch 的偵測歷史。不會提升權限,無法讀取的日誌會回報為「無法讀取」。
儀表板
透過圖表,一眼掌握綜合風險(估計)、依嚴重度的數量、依類別的發生次數、發生趨勢以及 MITRE ATT&CK 技術。
報告
將來源、依類別的檢出事項與 IOC(無害化表示)彙整為 Markdown 報告。時間以本裝置的本地時間、易讀的形式顯示。
由 LLM 自主調查(選用,預設關閉)
啟用後,檢查完成後 LLM 會自主調查,並以稽核員的身分撰寫報告。PersonalSOC 只向 LLM 提供經允許的唯讀工具,不會交給它 shell 或檔案。
定期執行(選用)
Mac 使用 launchd、Linux 使用 systemd 的使用者權限登錄,僅在出現上次沒有的偵測結果時才通知(通知只包含數量)。不使用 root。
支援 10 種語言
日語、英語、德語、西班牙語、法語、義大利語、韓語、葡萄牙語、簡體中文與繁體中文。自動跟隨作業系統的語言。
RoamSwitch MCP 連動
若已安裝 RoamSwitch,PersonalSOC 會從 RoamSwitch 的 MCP 伺服器(唯讀)取得尚未解決的偵測與設定診斷中未通過的項目,與日誌中的偵測結果一併彙整成同一份報告。相同的偵測會合併為一筆,並附上次數與最新時間。在 LLM 調查中,也只能呼叫 RoamSwitch 的唯讀工具,run_* 之類的執行類工具會被拒絕。未安裝 RoamSwitch 時會略過此來源,也可以在設定中關閉。
畫面範例



所示畫面中的資料(IP 位址等)均為虛構。
報告輸出範例
這是報告範例(已啟用 LLM 連動的情況)。可以複製為 Markdown 直接分享。
PersonalSOC 状況報告書
- 環境: Linux
- 確認時刻: 2026-09-29T09:19:22Z
現在の状況サマリー
総合リスク(目安): 低(22/100) █████░░░░░░░░░░░░░░░
| 深刻度「高」 | 深刻度「中」 | 深刻度「低」 | 検知の種類 | 確認できなかった収集元 |
|---|---|---|---|---|
| 2 | 3 | 1 | 6 | 0 |
リスクは深刻度と確度による目安(発生件数では増えない)。仮説は要裏取り。検出なしは安全の証明ではない。
分類ごとの状況
| 類別 | 発生件数 | 件数の比較 | 検知の種類 | 最高の深刻度 | 最新 |
|---|---|---|---|---|---|
| SSH 総当たり後の認証成功 | 25 | ████████████ | 1 | 🔴 高 | 2026年9月29日(火) 08:50:00 (UTC+9) |
| MCP 設定の問題 | 4 | ██░░░░░░░░░░ | 4 | 🔴 高 | 2026年9月29日(火) 07:14:00 (UTC+9) |
| Web 攻撃パターン | 4 | ██░░░░░░░░░░ | 1 | 🟠 中 | 2026年9月29日(火) 03:04:00 (UTC+9) |
発生の推移(時間ごと)
| 時期 | 件数 | 推移 | 内訳(高/中/低) |
|---|---|---|---|
| 09/28 18:00 | 1 | ████░░░░░░░░░░░░ | 0/0/1 |
| 09/28 19:00 | 4 | ████████████████ | 3/1/0 |
| 09/28 20:00 | 1 | ████░░░░░░░░░░░░ | 0/1/0 |
| 09/28 21:00 | 4 | ████████████████ | 3/1/0 |
| 09/28 22:00 | 2 | ████████░░░░░░░░ | 0/2/0 |
| 09/28 23:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 00:00 | 3 | ████████████░░░░ | 1/2/0 |
| 09/29 01:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 02:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 03:00 | 4 | ████████████████ | 3/1/0 |
| 09/29 04:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 05:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 06:00 | 3 | ████████████░░░░ | 3/0/0 |
| 09/29 07:00 | 2 | ████████░░░░░░░░ | 1/0/1 |
| 09/29 08:00 | 3 | ████████████░░░░ | 3/0/0 |
直近の出来事(新しい順)
| 時刻 | 類別 | 深刻度 | 描述 |
|---|---|---|---|
| 2026年9月29日(火) 08:50:00 (UTC+9) | SSH 総当たり後の認証成功 | 🔴 高 | 203.0.113.45 から失敗 24 回の後に成功が 1 回。正規利用者の入力ミスの可能性もあるため、当該アカウント… |
| 2026年9月29日(火) 07:14:00 (UTC+9) | MCP 設定の問題 | 🟡 低 | -y により初回導入の確認が省かれている。 |
| 2026年9月29日(火) 05:57:00 (UTC+9) | MCP 設定の問題 | 🔴 高 | コマンドがシェルの -c 経由。引数の組み立て次第で任意コマンドが実行される。直接実行に変えること。 |
| 2026年9月29日(火) 03:04:00 (UTC+9) | Web 攻撃パターン | 🟠 中 | 198.51.100.7 から 4 件。種別: パストラバーサル/LFI、SQLインジェクション、機密ファイル探索。成功… |
| 2026年9月29日(火) 00:11:00 (UTC+9) | MCP 設定の問題 | 🟠 中 | npx が版を固定せずに取得して実行する。上流が乗っ取られると次回起動で悪性コードが動く |
| 2026年9月28日(月) 21:18:00 (UTC+9) | MCP 設定の問題 | 🟠 中 | 環境変数 API_TOKEN に値が直接書かれている |
MITRE ATT&CK
| 技術 | 発生件数 | 件数の比較 | 検知の種類 |
|---|---|---|---|
| T1078 | 1 | ████████████ | 1 |
| T1190 | 1 | ████████████ | 1 |
監査レポート
セキュリティ監査レポート
概要
- 侵害が確定したとは言えませんが、優先して確認すべき点が2つあります。
- SSHの総当たりの後に、同じ送信元(203.0.113.45)からログインが成功しています。 失敗が24回続いた後の成功で、パスワードが破られた可能性があります(確度: 有力)。
- Webサーバーに、パス走査とSQLインジェクションを試す要求があります。応答は404で、成功の証拠はありません(確度: 仮説)。
推奨する対応
adminアカウントのパスワードを変更し、ログイン履歴を確認する。- SSHのパスワード認証をやめ、公開鍵認証にする。
- MCPの設定にある秘密の直書きを、環境変数の参照に置き換える。
収集元
| 確認したもの | 状態 | 検出 | 備考 |
|---|---|---|---|
| 認証ログ(sshd) | 読めた | 1 | |
| auditd | 該当なし | 0 | この環境に該当するログがない |
| Web アクセスログ(nginx / apache) | 読めた | 1 | |
| DNS クエリログ(dnsmasq / named) | 該当なし | 0 | この環境に該当するログがない |
| MCP の設定(Claude Code・Claude Desktop・opencode・Cursor) | 読めた | 4 | |
| RoamSwitch(MCP、読み取り専用) | 読めた | 0 |
検出事項
SSH 総当たり後の認証成功(検知 1 種類・発生 25 件)
| 深刻度 | 確度 | ATT&CK | 描述 | 件数 | 最新 |
|---|---|---|---|---|---|
| 🔴 高 | 有力 | T1078 | 203.0.113.45 から失敗 24 回の後に成功が 1 回。正規利用者の入力ミスの可能性もあるため、当該アカウントの直後の操作を確認すること。(根拠の行: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20 ...) | 1 | 2026年9月29日(火) 08:50:00 (UTC+9) |
MCP 設定の問題(検知 4 種類・発生 4 件)
| 深刻度 | 確度 | ATT&CK | 描述 | 件数 | 最新 |
|---|---|---|---|---|---|
| 🔴 高 | 有力 | - | コマンドがシェルの -c 経由。引数の組み立て次第で任意コマンドが実行される。直接実行に変えること。 | 1 | 2026年9月29日(火) 05:57:00 (UTC+9) |
| 🟠 中 | 確定 | - | npx が版を固定せずに取得して実行する。上流が乗っ取られると次回起動で悪性コードが動く(ラグプル)。版またはハッシュを固定すること。 | 1 | 2026年9月29日(火) 00:11:00 (UTC+9) |
| 🟠 中 | 有力 | - | 環境変数 API_TOKEN に値が直接書かれている(値は表示しない)。環境変数参照かキーチェーンに移すこと。 | 1 | 2026年9月28日(月) 21:18:00 (UTC+9) |
| 🟡 低 | 確定 | - | -y により初回導入の確認が省かれている。 | 1 | 2026年9月29日(火) 07:14:00 (UTC+9) |
Web 攻撃パターン(検知 1 種類・発生 4 件)
| 深刻度 | 確度 | ATT&CK | 描述 | 件数 | 最新 |
|---|---|---|---|---|---|
| 🟠 中 | 有力 | T1190 | 198.51.100.7 から 4 件。種別: パストラバーサル/LFI、SQLインジェクション、機密ファイル探索。成功応答は観測されていない。(根拠の行: 1, 2, 4, 5) | 1 | 2026年9月29日(火) 03:04:00 (UTC+9) |
IOC(無害化表記)
- IP:
198[.]51[.]100[.]7 - IP:
203[.]0[.]113[.]45 - ドメイン:
malware[.]example
調査の経過
LLM が調べた理由と、PersonalSOC が実行したツール。
- 検出事項の一覧を確認する
list_findings
- SSHの成功ログインの根拠を確認する
get_evidence(1)
PersonalSOC Status Report
- Environment: Linux
- Checked at: 2026-09-29T09:19:22Z
Current status summary
Overall risk (estimate): Low(22/100) █████░░░░░░░░░░░░░░░
| Severity: High | Severity: Medium | Severity: Low | Detection types | Sources not checked |
|---|---|---|---|---|
| 2 | 3 | 1 | 6 | 0 |
Risk is an estimate based on severity and confidence (it does not grow with occurrence count). Hypotheses need verification. No detections is not proof of safety.
Status by category
| Category | Occurrences | Comparison | Detection types | Highest severity | Latest |
|---|---|---|---|---|---|
| SSH login succeeded after brute force | 25 | ████████████ | 1 | 🔴 High | Tue, 2026-09-29 08:50:00 (UTC) |
| MCP configuration issues | 4 | ██░░░░░░░░░░ | 4 | 🔴 High | Tue, 2026-09-29 07:14:00 (UTC) |
| Web attack patterns | 4 | ██░░░░░░░░░░ | 1 | 🟠 Medium | Tue, 2026-09-29 03:04:00 (UTC) |
Trend (per hour)
| Period | Count | Trend | Breakdown (H/M/L) |
|---|---|---|---|
| 09/28 18:00 | 1 | ████░░░░░░░░░░░░ | 0/0/1 |
| 09/28 19:00 | 4 | ████████████████ | 3/1/0 |
| 09/28 20:00 | 1 | ████░░░░░░░░░░░░ | 0/1/0 |
| 09/28 21:00 | 4 | ████████████████ | 3/1/0 |
| 09/28 22:00 | 2 | ████████░░░░░░░░ | 0/2/0 |
| 09/28 23:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 00:00 | 3 | ████████████░░░░ | 1/2/0 |
| 09/29 01:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 02:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 03:00 | 4 | ████████████████ | 3/1/0 |
| 09/29 04:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 05:00 | 2 | ████████░░░░░░░░ | 2/0/0 |
| 09/29 06:00 | 3 | ████████████░░░░ | 3/0/0 |
| 09/29 07:00 | 2 | ████████░░░░░░░░ | 1/0/1 |
| 09/29 08:00 | 3 | ████████████░░░░ | 3/0/0 |
Recent events (newest first)
| Time | Category | Severity | Details |
|---|---|---|---|
| Tue, 2026-09-29 08:50:00 (UTC) | SSH login succeeded after brute force | 🔴 High | 1 success |
| Tue, 2026-09-29 07:14:00 (UTC) | MCP configuration issues | 🟡 Low | -y skips the confirmation for the first installation. |
| Tue, 2026-09-29 05:57:00 (UTC) | MCP configuration issues | 🔴 High | The command runs through a shell's -c. Depending on how argu… |
| Tue, 2026-09-29 03:04:00 (UTC) | Web attack patterns | 🟠 Medium | 4 request |
| Tue, 2026-09-29 00:11:00 (UTC) | MCP configuration issues | 🟠 Medium | npx fetches and runs the package without pinning a version. … |
| Mon, 2026-09-28 21:18:00 (UTC) | MCP configuration issues | 🟠 Medium | The environment variable API_TOKEN has its value written dir… |
MITRE ATT&CK
| Technique | Occurrences | Comparison | Detection types |
|---|---|---|---|
| T1078 | 1 | ████████████ | 1 |
| T1190 | 1 | ████████████ | 1 |
Audit report
Security audit report
Summary
- A compromise is not confirmed, but two points need attention first.
- A login succeeded from the same source (203.0.113.45) right after an SSH brute-force run. Success after 24 failures suggests the password may have been guessed (confidence: likely).
- The web server received path-traversal and SQL injection attempts. All returned 404, so there is no evidence of success (confidence: hypothesis).
Recommended actions
- Change the
adminpassword and review its login history.- Turn off SSH password authentication and use public keys.
- Replace the hardcoded secret in the MCP configuration with an environment variable reference.
Sources
| Checked item | Status | Found | Note |
|---|---|---|---|
| Authentication log (sshd) | Read | 1 | |
| auditd | Not present | 0 | No matching log in this environment |
| Web access log (nginx / apache) | Read | 1 | |
| DNS query log (dnsmasq / named) | Not present | 0 | No matching log in this environment |
| MCP settings (Claude Code, Claude Desktop, opencode, Cursor) | Read | 4 | |
| RoamSwitch (MCP, read-only) | Read | 0 |
Findings
SSH login succeeded after brute force (1 type(s), 25 occurrence(s))
| Severity | Confidence | ATT&CK | Details | Count | Latest |
|---|---|---|---|---|---|
| 🔴 High | Likely | T1078 | 1 success(es) after 24 failures from 203.0.113.45. It may be a legitimate user's typo, so check what the account did right afterwards.(evidence lines: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20 ...) | 1 | Tue, 2026-09-29 08:50:00 (UTC) |
MCP configuration issues (4 type(s), 4 occurrence(s))
| Severity | Confidence | ATT&CK | Details | Count | Latest |
|---|---|---|---|---|---|
| 🔴 High | Likely | - | The command runs through a shell's -c. Depending on how arguments are assembled, arbitrary commands can run. Change it to run the program directly. | 1 | Tue, 2026-09-29 05:57:00 (UTC) |
| 🟠 Medium | Confirmed | - | npx fetches and runs the package without pinning a version. If the upstream is hijacked, malicious code runs at the next launch (rug pull). Pin the version or a hash. | 1 | Tue, 2026-09-29 00:11:00 (UTC) |
| 🟠 Medium | Likely | - | The environment variable API_TOKEN has its value written directly (the value is not shown). Move it to an environment reference or the keychain. | 1 | Mon, 2026-09-28 21:18:00 (UTC) |
| 🟡 Low | Confirmed | - | -y skips the confirmation for the first installation. | 1 | Tue, 2026-09-29 07:14:00 (UTC) |
Web attack patterns (1 type(s), 4 occurrence(s))
| Severity | Confidence | ATT&CK | Details | Count | Latest |
|---|---|---|---|---|---|
| 🟠 Medium | Likely | T1190 | 4 request(s) from 198.51.100.7. Types: Path traversal / LFI, SQL injection, Probing for sensitive files. No successful response was observed.(evidence lines: 1, 2, 4, 5) | 1 | Tue, 2026-09-29 03:04:00 (UTC) |
IOCs (defanged)
- IP:
198[.]51[.]100[.]7 - IP:
203[.]0[.]113[.]45 - Domain:
malware[.]example
Investigation trail
The reasons the LLM gave and the tools PersonalSOC ran.
- Review the list of findings
list_findings
- Check the evidence for the successful SSH login
get_evidence(1)
所示的 IP 位址與日誌均為虛構。報告可以用顯示語言(10 種語言)輸出。
啟動方法
Mac:開啟「應用程式」資料夾中的「PersonalSOC」(與 RoamSwitch 不同的圖示)。
Linux:從應用程式清單開啟「PersonalSOC」(獨立圖示)。在終端機中執行 personalsoc-app。
命令列:personalsoc scan --report(報告)、personalsoc scan --llm <名稱>(LLM 自主調查)。
隱私與適用範圍
PersonalSOC 的日誌分析全部在本裝置內完成。它不會開放監聽連接埠,介面也不會載入外部網站。
LLM 連動預設關閉。啟用後,會啟動您選擇的 LLM 命令(opencode、claude、codex、agy 等),並傳遞偵測內容與作為依據的日誌行(金鑰、權杖等機密已被遮蓋)。依該命令的設定,內容可能會被傳送到外部服務。傳送目的地與處理方式取決於您所選的 LLM 及其提供者的條款。
RoamSwitch 的「Zero-Telemetry」(不向外部傳送通訊內容與日誌)是針對 RoamSwitch 本體的說明。啟用 PersonalSOC 的 LLM 連動後產生的通訊不在其範圍內。若保持 LLM 連動關閉,PersonalSOC 不會將日誌內容傳送到裝置之外。
授權
PersonalSOC 採用 Apache License 2.0 授權,不適用 RoamSwitch 的使用授權合約(EULA)。授權文件、NOTICE 以及隨附的第三方軟體清單,在 Mac 上位於應用程式內部(PersonalSOC.app/Contents/Resources),在 Linux 上位於 /usr/share/licenses/personalsoc/。
執行環境與更新
macOS 12 或更新版本。Linux 需要 WebKitGTK 4.1(libwebkit2gtk-4.1),deb / rpm 會自動安裝;在 Arch(AUR)上請將 webkit2gtk-4.1 作為選用相依套件安裝。在 Mac 上,可以在設定的「更新」中直接於應用程式內更新。只有按下按鈕時才會連線,下載的檔案會先驗證簽章再安裝。在 Linux 上,它包含在 RoamSwitch 套件的更新中。