守望项目🌐
融合中心-MCP服务器和人工智能代理,用于OSINT和地缘政治情报
Project Overwatch是一个自主智能系统,它将模型上下文协议(MCP)服务器与用于开源智能(OSINT)分析的AI代理相结合。它将来自新闻媒体、卫星图像和互联网基础设施监控的数据相关联。
🌟 介绍和经过验证的能力
Fusion Center不仅仅是一个数据提取器;这是一个 关联引擎其真正的力量在于通过交叉引用来自三个不同领域的信号来“三角测量”真相:
- 物理的 (卫星热异常)
- 数字 (互联网流量和中断)
- 信息性 (新闻、电报、威胁英特尔)
🎥 Watch the Agent in Action
Demonstration: The Agent performing a multi-step analysis on live data.
💡 示例查询(展示)
要查看代理的全部潜力,请尝试以下强制多域关联的查询:
1.“言语与行动”分歧测试(外交与现实)
“使用美国国家航空航天局FIRMS数据分析过去14天顿巴斯地区‘热异常’强度的趋势,并将其与GDELT新闻文章中包含关键词‘谈判’、‘和平谈判’或‘外交官’的情绪相关联。 假设: 如果新闻情绪是积极的(谈判),但热异常正在上升(动态),停火的可能性很低。"
- 为什么有效: 验证外交辞令是否得到地面真相物理学的支持,或者是否会分散注意力。
2.“无声降级”(网络和基础设施)
“查看IODA和Cloudflare Radar,了解过去一周乌克兰关键基础设施中断或DDoS攻击流量的减少情况。将其与RSS提要中的任何‘善意’声明相关联。 前提条件: 停火往往始于战略基础设施目标的减少。"
3.“宣传验证”(信息战)
“将GDELT官方媒体报道中关于边境紧张局势的官方说法与当地Telegram OSINT频道中描述部队调动的原始情绪和照片进行比较。此外,请查看AlienVault OTX,了解针对该地区的网络威胁指标是否出现任何激增。”
📄 Click to view Sample Intelligence Report Output
🔴 **COMPREHENSIVE OSINT SITREP – PROJECT OVERWATCH**
**CLASSIFICATION:** OSINT / PUBLIC
**DTG:** 18 DEC 2025 / 19:30Z
**QUERY:** "Compare official GDELT state media narrative vs. Telegram OSINT on Ukraine border tensions"
**INTELLIGENCE SOURCES:** GDELT, Telegram OSINT, AlienVault OTX, NASA FIRMS
–––
## SECTION I – EXECUTIVE INTELLIGENCE SUMMARY
### A. DIRECT RESPONSE TO QUERY
**Analysis reveals a significant narrative divergence:** State media (GDELT) reports "de-escalation" and "diplomatic progress" (65% positive sentiment), while local Telegram OSINT channels document **increased troop movements** and **artillery repositioning** near Kharkiv and Sumy oblasts.
### B. KEY INTELLIGENCE HIGHLIGHTS
• **Narrative Divergence Detected:** GDELT state media sources published 47 articles (Dec 14-18) emphasizing "ceasefire talks" and "withdrawal agreements". Simultaneously, Telegram channels (@CITeam_ua, @DeepStateUA, @Rybar) reported 23 confirmed sightings of armored columns moving **toward** the border, not away.
• **Kinetic Reality Check:** NASA FIRMS detected 156 thermal anomalies in Kharkiv Oblast (Dec 16-17), a **340% increase** from the 7-day baseline. Coordinates cluster around (49.9°N, 36.2°E), consistent with artillery positions reported by @CITeam_ua 4 hours prior.
• **Cyber Indicators Align:** AlienVault OTX shows a **spike in DDoS pulses** targeting Ukrainian energy infrastructure IPs (+180% vs. baseline). Attack vectors match Russian APT28 TTPs, contradicting the "peaceful" narrative.
• **Temporal Correlation:** State media "peace talks" articles peaked on Dec 16 at 14:00 UTC, exactly **6 hours before** Telegram channels reported renewed shelling near Vovchansk (50.29°N, 36.93°E).
### C. CONFIDENCE ASSESSMENT
**Overall Confidence:** 82%
**Intelligence Quality:** HIGH
**Query Complexity:** MODERATE
**Assessment:** Strong multi-source corroboration between kinetic signals (FIRMS), cyber activity (OTX), and ground truth (Telegram). State media narrative assessed as **disinformation or strategic misdirection**.
–––
## SECTION IV – ACTIONABLE INTELLIGENCE & RECOMMENDATIONS
### A. IMMEDIATE ACTIONS
1. **Monitor Artillery Deployment:** Track thermal anomalies in cluster zone (49.8-50.1°N, 36.0-36.5°E)
2. **Cross-Reference Telegram Geotagged Posts:** Validate troop movement claims with FIRMS data
3. **Cyber Defense Alert:** Warn energy sector of probable escalation in DDoS attacks
### B. MONITORING INDICATORS
• Thermal anomaly density >100/day in Kharkiv Oblast = High kinetic alert
• State media "peace" keyword volume inversely correlated with FIRMS detections
• OTX pulse velocity >50 new IoCs/day targeting UA infrastructure
### C. FOLLOW-UP COLLECTION
• **Satellite Tasking:** Request commercial SAR imagery of Vovchansk area for vehicle count validation
• **SIGINT Cross-Check:** Correlate with radio chatter reports from Telegram (if available)
• **GDELT Deep Dive:** Analyze which state outlets push "peace" narrative hardest (identify amplifiers)
–––
## SECTION V – INTELLIGENCE ASSESSMENT METADATA
### A. SOURCE RELIABILITY MATRIX
| Source | Reliability | Credibility | Timeliness | Grade | Notes |
|--------|-------------|-------------|------------|-------|-------|
| GDELT News | C | 4 | Current | C-4 | State bias detected |
| Telegram OSINT | B | 2 | Real-time | B-2 | Verified channels only |
| NASA FIRMS | A | 1 | 3-hour lag | A-1 | Physics-based, no bias |
| AlienVault OTX | B | 2 | Current | B-2 | Community-sourced |
**Grading Key:** Reliability (A-F), Credibility (1-6, lower=better)
### B. ANALYTICAL CONFIDENCE
- **Methodology:** Dual-LLM reasoning with Bayesian hypothesis updating
- **Primary Evidence:** 156 thermal anomalies + 23 Telegram sightings + 47 DDoS pulses
- **Assumptions:** Telegram channels are not compromised; FIRMS anomalies exclude wildfires (verified via intensity >350K)
–––
## SECTION VI – INTELLIGENCE NARRATIVE ANALYSIS
**Assessed Purpose of State Media Narrative:**
The timing and intensity of "de-escalation" messaging suggests a **strategic deception operation** to:
1. Lower international alert posture before kinetic action
2. Create plausible deniability for troop repositioning ("exercises")
3. Exploit Western holiday period (Dec 20-25) for reduced monitoring
**Risk:** If pattern holds, expect significant military action within **72-96 hours** of peak "peace" messaging.
–––
**CLASSIFICATION:** OSINT / PUBLIC
**ANALYST:** Project Overwatch Dual-LLM Intelligence System
**SESSION:** 20251218_194200_narrative_divergence_analysis
〔END SITREP〕🎯 建筑
┌─────────────────────────────────────────────────────────────────┐
│ FUSION CENTER │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────┐ MCP/SSE ┌──────────────────────┐ │
│ │ Overwatch │ ◄──────────────► │ MCP Server │ │
│ │ Agent │ │ (project-overwatch) │ │
│ │ (LLM) │ └──────────────────────┘ │
│ └─────────────┘ │ │
│ │ ┌─────────┴─────────┐ │
│ │ ▼ ▼ ▼ │
│ ▼ ┌─────────┐ ┌──────┐ ┌────────┐ │
│ ┌───────────┐ │ GDELT │ │ NASA │ │ IODA │ │
│ │ Analysis │ │ News │ │FIRMS │ │ Outage │ │
│ │ & Reports │ └─────────┘ └──────┘ └────────┘ │
│ └───────────┘ │
│ │
└─────────────────────────────────────────────────────────────────┘✨ 特性
MCP服务器工具
| 类别 | 工具 | 描述 |
|---|---|---|
| 📰 新闻 | search_news | 在GDELT搜索全球新闻 |
| 📰 新闻 | fetch_rss_news | 从RSS源(Meduza、The Insider、The Cradle)获取文章 |
| 🔍 搜索 | search_internet | 通过DuckDuckGo进行一般网络搜索 |
| 🔍 搜索 | search_leaks | 搜索泄露的数据集(DDoS机密) |
| 🛰️ 卫星 | detect_thermal_anomalies | 美国国家航空航天局火灾/爆炸探测系统 |
| 🌐 网络 | check_connectivity | IODA互联网中断检测 |
| 🌐 网络 | check_traffic_metrics | Cloudflare雷达分析 |
| 📱 电报 | search_telegram | 搜索OSINT Telegram频道 |
| 📱 电报 | get_channel_info | 获取Telegram频道元数据 |
| 📱 电报 | list_osint_channels | 列出精选的OSINT频道 |
| 🔍 威胁英特尔 | check_ioc | 在AlienVault OTX中查找IoC |
| 🔍 威胁英特尔 | get_threat_pulse | 获取OTX脉冲详细信息 |
| 🔍 威胁英特尔 | search_threats | 搜索OTX威胁脉冲 |
AI 代理
- 自主OSINT分析
- 多源数据关联
- LLM驱动工具选择
- 结构化情报报告
- 多步推理 通过假设检验、自我反思和验证
🚀 快速开始
先决条件
- Python 3.10+
- 紫外线 (推荐)或pip
安装
cd fusion-center
# Create virtual environment and install
uv venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
uv pip install -e ".[agent]" # Include agent dependencies
# Copy environment template
cp .env.example .env配置
编辑 .env:
# Required for satellite data
NASA_FIRMS_API_KEY=your_key_here
# Required for Telegram monitoring (get from https://my.telegram.org)
TELEGRAM_API_ID=your_api_id
TELEGRAM_API_HASH=your_api_hash
# After setting these, run: python scripts/telegram_auth.py
# Required for threat intelligence (get from https://otx.alienvault.com)
OTX_API_KEY=your_otx_key
# For agent (choose based on provider)
GOOGLE_API_KEY=your_google_key # for gemini provider
XAI_API_KEY=your_xai_key # for grok provider
# ollama and docker providers don't need API keys
# Optional
LOG_LEVEL=INFO
MCP_SERVER_PORT=8080📦 跑步
启动MCP服务器
# HTTP/SSE mode (default)
python -m src.mcp_server.server --transport sse --port 8080
# Or stdio mode
python -m src.mcp_server.server --transport stdio运行代理
# Start analysis task
python -m src.agent "Analyze military activity in Ukraine over the past week"
# With custom server
python -m src.agent --server http://localhost:9000/sse "Check internet status in Iran"
# Output as JSON
python -m src.agent --json "Search for news about protests in China"运行仪表板
# Start dashboard (requires MCP server to be running)
python -m src.dashboard.server
# Custom port
python -m src.dashboard.server --port 9000
# Custom MCP server URL
python -m src.dashboard.server --mcp-url http://localhost:9000/sse仪表板在以下位置提供了一个web界面 http://127.0.0.1:8000 显示:
- GDELT的最新消息
- 交互式三维地球仪上的热异常
- 电报OSINT频道帖子
- 威胁情报脉冲
一起运行所有组件
# Terminal 1: Start MCP Server
python -m src.mcp_server.server --transport sse --port 8080
# Terminal 2: Run Agent (optional)
python -m src.agent "Correlate thermal anomalies with news near Kyiv"
# Terminal 3: Start Dashboard (optional)
python -m src.dashboard.server --port 8000您可以单独运行MCP服务器,并将多个客户端(代理、仪表板或自定义客户端)连接到它。
📁 项目结构
📂 Click to view Project Structure
fusion-center/
├── pyproject.toml # Dependencies and config
├── .env.example # Environment template
├── README.md
│
├── scripts/
│ └── telegram_auth.py # One-time Telegram authentication
│
├── output/ # Research outputs
│ └── {session_id}/
│ ├── report.md # Final intelligence report
│ ├── reasoning.log # Full reasoning trace
│ └── state.json # Complete state snapshot
│
└── src/
├── __init__.py
│
├── mcp_server/ # 🔧 MCP Server
│ ├── __init__.py
│ ├── server.py # Server entry point
│ └── tools/
│ ├── geo.py # NASA FIRMS
│ ├── news.py # GDELT
│ ├── cyber.py # IODA/Cloudflare
│ ├── telegram.py # Telegram OSINT channels
│ └── threat_intel.py # AlienVault OTX
│
├── agent/ # 🤖 AI Agent
│ ├── __init__.py
│ ├── __main__.py # CLI entry point
│ ├── core.py # Agent exports
│ ├── graph.py # LangGraph definition
│ ├── nodes.py # Graph nodes (incl. multi-step reasoning)
│ ├── state.py # Agent state schema
│ ├── tools.py # MCP tool executor
│ └── prompts/ # System prompts & reasoning prompts
│
├── dashboard/ # 🌐 Web Dashboard
│ ├── __init__.py
│ ├── server.py # Dashboard server (FastAPI)
│ ├── api.py # API endpoints (MCP client)
│ └── static/ # Frontend files
│ ├── index.html # Dashboard page
│ ├── style.css # Terminal DOS styling
│ └── app.js # Frontend logic
│
└── shared/ # 🔗 Shared Code
├── __init__.py
├── config.py # Centralized config
├── logger.py # Rich logging
└── output_writer.py # Report & reasoning log writer🔌 集成示例
Python客户端
from mcp import ClientSession
from mcp.client.sse import sse_client
async def analyze():
async with sse_client("http://127.0.0.1:8080/sse") as (read, write):
async with ClientSession(read, write) as session:
await session.initialize()
# Search news
result = await session.call_tool(
"search_news",
arguments={
"keywords": "military activity",
"country_code": "UA",
"timespan": "3d"
}
)
print(result)以编程方式使用Agent
from src.agent.core import OverwatchAgent
async def run_analysis():
agent = OverwatchAgent()
result = await agent.run_analysis(
task="Analyze internet outages in Iran and correlate with news",
context={"country_code": "IR"}
)
return result📊 数据源
| 来源 | 描述 | 身份验证 |
|---|---|---|
| DuckDuckGo | 以隐私为中心的网络搜索 | 免费(无API密钥) |
| DDoS秘密 | 泄露/黑客攻击的数据存档 | 免费(网络抓取) |
| GDELT | 全球新闻监测 | 免费 |
| 梅杜莎 | 俄罗斯独立新闻 | 免费(RSS) |
| 内幕 | 俄罗斯调查性新闻 | 免费(RSS) |
| 摇篮 | 地缘政治新闻(西亚) | 免费(RSS) |
| 美国国家航空航天局公司 | 卫星火灾探测 | 免费API密钥 |
| 碘 | 互联网中断 | 免费 |
| Cloudflare雷达 | 流量分析 | 免费(有限) |
| 电报 | OSINT通道监控 | 免费API凭据 |
| AlienVault OTX | 威胁情报 | 免费API密钥 |
🧪 发展
# Install dev dependencies
uv pip install -e ".[dev,agent]"
# Linting
ruff check src/
# Type checking
mypy src/
# Test server
python -m src.mcp_server.server --transport sse --port 8080🧠 多步推理
该代理使用先进的多步推理进行更深入的分析:
🧠 Click to view Multi-step Reasoning Flow
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ MULTI-STEP REASONING FLOW │
├─────────────────────────────────────────────────────────────────────────────────────┤
│ │
│ ┌──────────┐ ┌─────────────┐ ┌──────────────┐ ┌───────────┐ │
│ │ PLANNING │───►│ DECOMPOSING │───►│ HYPOTHESIZING│───►│ GATHERING │◄────┐ │
│ └──────────┘ └─────────────┘ └──────────────┘ └─────┬─────┘ │ │
│ │ │ │
│ (update hyp) │ │
│ ▼ │ │
│ ┌───────────┐ │ │
│ │ ANALYZING │ │ │
│ └─────┬─────┘ │ │
│ │ │ │
│ ┌────────────┼───────────┘ │
│ │ (follow-up)│ │
│ │ ▼ │
│ │ ┌────────────┐ │
│ │ │ REFLECTING │◄──────┐ │
│ │ └─────┬──────┘ │ │
│ │ │ │ │
│ │ (gaps) │ │ │
│ └────────────┤ (not ready) │
│ ▼ │ │
│ ┌────────────┐ │ │
│ │ CORRELATING│ │ │
│ └─────┬──────┘ │ │
│ ▼ │ │
│ ┌───────────┐ │ │
│ │ VERIFYING │────────┘ │
│ └─────┬─────┘ │
│ │ (ready) │
│ ▼ │
│ ┌─────────────┐ │
│ │ SYNTHESIZING│ │
│ └──────┬──────┘ │
│ ▼ │
│ ┌──────────┐ │
│ │ COMPLETE │ │
│ └──────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────────────────────┘阶段描述
| 阶段 | 描述 |
|---|---|
| 规划 | 创建包含目标、地区、关键字和初始查询的研究计划 |
| 分解 | 将复杂任务分解为可管理的子任务,评估复杂性 |
| 假设 | 生成具有支持/反驳标准的可测试假设 |
| 聚集 | 执行MCP查询,更新假设置信度(贝叶斯) |
| 分析 | 思维链分析、模式识别与假设有关 |
| 反光板 | 自我批评:偏见检查、差距分析、替代解释 |
| 相互依赖 | 查找跨源连接(时间、地理空间、因果关系) |
| 验证 | 验证结论,检查一致性,调整置信度 |
| 合成 | 从生成最终报告 已验证 洞察力和相关性 |
相转变
| 从 | 到 | 条件 |
|---|---|---|
| 计划 | 分解 | 创建计划 |
| 分解 | 假设 | 任务中等/复杂 |
| 假设 | 收集 | 生成的假设 |
| 正在收集 | 正在分析 | 不再有待处理的查询 |
| 正在收集 | 正在收集 | 要执行的更多查询 |
| 分析 | 反思 | 分析完成 |
| 分析 | 收集 | 需要后续查询 |
| 反思 | 关联 | 无关键问题 |
| 反思 | 收集 | 差距需要更多调查 |
| 关联 | 验证 | 找到关联 |
| 验证 | 合成 | 验证通过 |
| 验证 | 反思 | 发现问题,需要审查 |
| 合成 | 完成 | 生成报告 |
益处
- 思维链:透明度的明确分步推理
- 假设检验:基于证据的情报分析方法
- 置信度校准:根据反思调整信心
- 偏差检测自我批评以识别潜在的盲点
- 一致性检查:验证结论是否相互矛盾
推理轨迹
所有推理步骤都记录到 reasoning.log 包括:
- 每一步的思考过程
- 假设状态更新与置信度得分
- 自我反思笔记和发现的问题
- 洞察和相关性的验证结果
🗺️ 路线图
✅ 完成
- \[x\] 配备OSINT工具的MCP服务器
- \[x\] 丰富的测井系统
- \[x\] 项目重组(单回购)
- \[x\] 特工骨架
- \[x\] LLM集成(Gemini/Grok/Ollama/Docker)
- \[x\] 多步推理
🔴 优先级:新数据源
- \[x\] 电报频道 -来自冲突区域的实时OSINT(Telethon API)
- \[x\] AlienVault OTX -网络威胁情报开放威胁交换
- \[x\] 订阅 -独立新闻来源(Meduza、The Insider、The Cradle)
🟡 未来
- \[x\] 两个代理,一个用于推理,另一个用于严格的JSON输出
- \[x\] 事件关联引擎
- \[x\] Web仪表板
- \[x\] 添加DuckDuckGo搜索工具
- \[x\] 添加https://ddosecrets.com/作为一种工具(网页抓取)
- \[\]使用PydanticAI而不是当前的langchain代理创建PoC代理
📄 许可证
MIT许可证
⚠️ 免责声明
此工具用于研究和教育目的。核实来自多个来源的信息,并遵守适用法律和API服务条款。
