Skip to main content

Crate mnemo_baseline

Crate mnemo_baseline 

Source
Expand description

v0.4.1 (P0-3) — agent behavioural-baseline exporter.

RSAC 2026 (2026-04-26) called out the agentic-SOC telemetry gap: agents emit logs but no normalised behavioural baseline an SOC can alert on. This crate ships the missing surface — a per-agent rolling profile (recall rate, write rate, namespace fanout, tool mix, HMAC continuity) emitted in two canonical schemas:

  1. OpenTelemetry semconv 1.31agent.* attributes on a span the operator’s existing OTel collector already ingests.
  2. OCSF 1.4 Application Activity — JSON the SOC’s SIEM pipeline already understands.

A z-score + EWMA detector flags drift; the exporter is deliberately signal, not enforcement — it does not refuse ops. The README’s threat-model section spells that out so a reader doesn’t mistake the surface for a policy gate.

Anti-leak invariant: emitted payloads never contain memory contents. Only metric aggregates. The unit tests sweep the payload with a regex to assert this.

Re-exports§

pub use anomaly::BaselineDelta;
pub use anomaly::BaselineMetric;
pub use anomaly::Severity;
pub use exporter::BaselineExporter;
pub use exporter::JsonExporter;
pub use profile::AgentBaseline;
pub use profile::ToolId;

Modules§

anomaly
z-score + EWMA drift detector (v0.4.1 P0-3).
exporter
OpenTelemetry + OCSF emitters (v0.4.1 P0-3).
profile
Rolling per-agent profile (v0.4.1 P0-3).