Token导航 LogoToken导航TokenDH.com
Fusion Center logo
运维云端stdio官方级别未说明来源级核验

Fusion Center

MCP Server

Project Overwatch是一个结合MCP服务器和AI代理的开源情报分析系统,用于从新闻媒体、卫星图像和互联网基础设施监控中关联数据。

工具数

0

提示词数

0

GitHub Stars

3

资源数

0
Python云端部署Docker

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

作者 / 组织

Draichi

提供方

Draichi

最后核验

2026/5/17 20:22

运行时

Python

快速接入

先看主来源和安装命令,再打开仓库或文档;下面只保留这个条目的关键接入事实。

命令预览

python -m src.mcp_server.server --transport sse --port 8080

详细介绍

守望项目🌐

融合中心-MCP服务器和人工智能代理,用于OSINT和地缘政治情报

Project Overwatch是一个自主智能系统,它将模型上下文协议(MCP)服务器与用于开源智能(OSINT)分析的AI代理相结合。它将来自新闻媒体、卫星图像和互联网基础设施监控的数据相关联。

🌟 介绍和经过验证的能力

Fusion Center不仅仅是一个数据提取器;这是一个 关联引擎其真正的力量在于通过交叉引用来自三个不同领域的信号来“三角测量”真相:

  1. 物理的 (卫星热异常)
  2. 数字 (互联网流量和中断)
  3. 信息性 (新闻、电报、威胁英特尔)

🎥 Watch the Agent in Action

Demonstration: The Agent performing a multi-step analysis on live data.

💡 示例查询(展示)

要查看代理的全部潜力,请尝试以下强制多域关联的查询:

1.“言语与行动”分歧测试(外交与现实)

“使用美国国家航空航天局FIRMS数据分析过去14天顿巴斯地区‘热异常’强度的趋势,并将其与GDELT新闻文章中包含关键词‘谈判’、‘和平谈判’或‘外交官’的情绪相关联。 假设: 如果新闻情绪是积极的(谈判),但热异常正在上升(动态),停火的可能性很低。"
  • 为什么有效: 验证外交辞令是否得到地面真相物理学的支持,或者是否会分散注意力。

2.“无声降级”(网络和基础设施)

“查看IODA和Cloudflare Radar,了解过去一周乌克兰关键基础设施中断或DDoS攻击流量的减少情况。将其与RSS提要中的任何‘善意’声明相关联。 前提条件: 停火往往始于战略基础设施目标的减少。"

3.“宣传验证”(信息战)

“将GDELT官方媒体报道中关于边境紧张局势的官方说法与当地Telegram OSINT频道中描述部队调动的原始情绪和照片进行比较。此外,请查看AlienVault OTX,了解针对该地区的网络威胁指标是否出现任何激增。”

📄 Click to view Sample Intelligence Report Output

🔴 **COMPREHENSIVE OSINT SITREP – PROJECT OVERWATCH**

**CLASSIFICATION:** OSINT / PUBLIC
**DTG:** 18 DEC 2025 / 19:30Z
**QUERY:** "Compare official GDELT state media narrative vs. Telegram OSINT on Ukraine border tensions"
**INTELLIGENCE SOURCES:** GDELT, Telegram OSINT, AlienVault OTX, NASA FIRMS

–––

## SECTION I – EXECUTIVE INTELLIGENCE SUMMARY

### A. DIRECT RESPONSE TO QUERY

**Analysis reveals a significant narrative divergence:** State media (GDELT) reports "de-escalation" and "diplomatic progress" (65% positive sentiment), while local Telegram OSINT channels document **increased troop movements** and **artillery repositioning** near Kharkiv and Sumy oblasts.

### B. KEY INTELLIGENCE HIGHLIGHTS

• **Narrative Divergence Detected:** GDELT state media sources published 47 articles (Dec 14-18) emphasizing "ceasefire talks" and "withdrawal agreements". Simultaneously, Telegram channels (@CITeam_ua, @DeepStateUA, @Rybar) reported 23 confirmed sightings of armored columns moving **toward** the border, not away.

• **Kinetic Reality Check:** NASA FIRMS detected 156 thermal anomalies in Kharkiv Oblast (Dec 16-17), a **340% increase** from the 7-day baseline. Coordinates cluster around (49.9°N, 36.2°E), consistent with artillery positions reported by @CITeam_ua 4 hours prior.

• **Cyber Indicators Align:** AlienVault OTX shows a **spike in DDoS pulses** targeting Ukrainian energy infrastructure IPs (+180% vs. baseline). Attack vectors match Russian APT28 TTPs, contradicting the "peaceful" narrative.

• **Temporal Correlation:** State media "peace talks" articles peaked on Dec 16 at 14:00 UTC, exactly **6 hours before** Telegram channels reported renewed shelling near Vovchansk (50.29°N, 36.93°E).

### C. CONFIDENCE ASSESSMENT

**Overall Confidence:** 82%
**Intelligence Quality:** HIGH  
**Query Complexity:** MODERATE

**Assessment:** Strong multi-source corroboration between kinetic signals (FIRMS), cyber activity (OTX), and ground truth (Telegram). State media narrative assessed as **disinformation or strategic misdirection**.

–––

## SECTION IV – ACTIONABLE INTELLIGENCE & RECOMMENDATIONS

### A. IMMEDIATE ACTIONS

1. **Monitor Artillery Deployment:** Track thermal anomalies in cluster zone (49.8-50.1°N, 36.0-36.5°E)
2. **Cross-Reference Telegram Geotagged Posts:** Validate troop movement claims with FIRMS data
3. **Cyber Defense Alert:** Warn energy sector of probable escalation in DDoS attacks

### B. MONITORING INDICATORS

• Thermal anomaly density >100/day in Kharkiv Oblast = High kinetic alert
• State media "peace" keyword volume inversely correlated with FIRMS detections
• OTX pulse velocity >50 new IoCs/day targeting UA infrastructure

### C. FOLLOW-UP COLLECTION

• **Satellite Tasking:** Request commercial SAR imagery of Vovchansk area for vehicle count validation
• **SIGINT Cross-Check:** Correlate with radio chatter reports from Telegram (if available)
• **GDELT Deep Dive:** Analyze which state outlets push "peace" narrative hardest (identify amplifiers)

–––

## SECTION V – INTELLIGENCE ASSESSMENT METADATA

### A. SOURCE RELIABILITY MATRIX

| Source | Reliability | Credibility | Timeliness | Grade | Notes |
|--------|-------------|-------------|------------|-------|-------|
| GDELT News | C | 4 | Current | C-4 | State bias detected |
| Telegram OSINT | B | 2 | Real-time | B-2 | Verified channels only |
| NASA FIRMS | A | 1 | 3-hour lag | A-1 | Physics-based, no bias |
| AlienVault OTX | B | 2 | Current | B-2 | Community-sourced |

**Grading Key:** Reliability (A-F), Credibility (1-6, lower=better)

### B. ANALYTICAL CONFIDENCE

- **Methodology:** Dual-LLM reasoning with Bayesian hypothesis updating
- **Primary Evidence:** 156 thermal anomalies + 23 Telegram sightings + 47 DDoS pulses
- **Assumptions:** Telegram channels are not compromised; FIRMS anomalies exclude wildfires (verified via intensity >350K)

–––

## SECTION VI – INTELLIGENCE NARRATIVE ANALYSIS

**Assessed Purpose of State Media Narrative:**
The timing and intensity of "de-escalation" messaging suggests a **strategic deception operation** to:
1. Lower international alert posture before kinetic action
2. Create plausible deniability for troop repositioning ("exercises")
3. Exploit Western holiday period (Dec 20-25) for reduced monitoring

**Risk:** If pattern holds, expect significant military action within **72-96 hours** of peak "peace" messaging.

–––

**CLASSIFICATION:** OSINT / PUBLIC  
**ANALYST:** Project Overwatch Dual-LLM Intelligence System  
**SESSION:** 20251218_194200_narrative_divergence_analysis

〔END SITREP〕

🎯 建筑

┌─────────────────────────────────────────────────────────────────┐
│                        FUSION CENTER                            │
├─────────────────────────────────────────────────────────────────┤
│                                                                 │
│   ┌─────────────┐     MCP/SSE      ┌──────────────────────┐    │
│   │  Overwatch  │ ◄──────────────► │    MCP Server        │    │
│   │    Agent    │                  │  (project-overwatch) │    │
│   │   (LLM)     │                  └──────────────────────┘    │
│   └─────────────┘                            │                  │
│         │                          ┌─────────┴─────────┐       │
│         │                          ▼         ▼         ▼       │
│         ▼                    ┌─────────┐ ┌──────┐ ┌────────┐   │
│   ┌───────────┐              │  GDELT  │ │ NASA │ │  IODA  │   │
│   │ Analysis  │              │  News   │ │FIRMS │ │ Outage │   │
│   │ & Reports │              └─────────┘ └──────┘ └────────┘   │
│   └───────────┘                                                 │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

✨ 特性

MCP服务器工具

类别工具描述
📰 新闻search_news在GDELT搜索全球新闻
📰 新闻fetch_rss_news从RSS源(Meduza、The Insider、The Cradle)获取文章
🔍 搜索search_internet通过DuckDuckGo进行一般网络搜索
🔍 搜索search_leaks搜索泄露的数据集(DDoS机密)
🛰️ 卫星detect_thermal_anomalies美国国家航空航天局火灾/爆炸探测系统
🌐 网络check_connectivityIODA互联网中断检测
🌐 网络check_traffic_metricsCloudflare雷达分析
📱 电报search_telegram搜索OSINT Telegram频道
📱 电报get_channel_info获取Telegram频道元数据
📱 电报list_osint_channels列出精选的OSINT频道
🔍 威胁英特尔check_ioc在AlienVault OTX中查找IoC
🔍 威胁英特尔get_threat_pulse获取OTX脉冲详细信息
🔍 威胁英特尔search_threats搜索OTX威胁脉冲

AI 代理

  • 自主OSINT分析
  • 多源数据关联
  • LLM驱动工具选择
  • 结构化情报报告
  • 多步推理 通过假设检验、自我反思和验证

🚀 快速开始

先决条件

安装

cd fusion-center

# Create virtual environment and install
uv venv
source .venv/bin/activate  # Windows: .venv\Scripts\activate
uv pip install -e ".[agent]"  # Include agent dependencies

# Copy environment template
cp .env.example .env

配置

编辑 .env:

# Required for satellite data
NASA_FIRMS_API_KEY=your_key_here

# Required for Telegram monitoring (get from https://my.telegram.org)
TELEGRAM_API_ID=your_api_id
TELEGRAM_API_HASH=your_api_hash
# After setting these, run: python scripts/telegram_auth.py

# Required for threat intelligence (get from https://otx.alienvault.com)
OTX_API_KEY=your_otx_key

# For agent (choose based on provider)
GOOGLE_API_KEY=your_google_key      # for gemini provider
XAI_API_KEY=your_xai_key            # for grok provider
# ollama and docker providers don't need API keys

# Optional
LOG_LEVEL=INFO
MCP_SERVER_PORT=8080

📦 跑步

启动MCP服务器

# HTTP/SSE mode (default)
python -m src.mcp_server.server --transport sse --port 8080

# Or stdio mode
python -m src.mcp_server.server --transport stdio

运行代理

# Start analysis task
python -m src.agent "Analyze military activity in Ukraine over the past week"

# With custom server
python -m src.agent --server http://localhost:9000/sse "Check internet status in Iran"

# Output as JSON
python -m src.agent --json "Search for news about protests in China"

运行仪表板

# Start dashboard (requires MCP server to be running)
python -m src.dashboard.server

# Custom port
python -m src.dashboard.server --port 9000

# Custom MCP server URL
python -m src.dashboard.server --mcp-url http://localhost:9000/sse

仪表板在以下位置提供了一个web界面 http://127.0.0.1:8000 显示:

  • GDELT的最新消息
  • 交互式三维地球仪上的热异常
  • 电报OSINT频道帖子
  • 威胁情报脉冲

一起运行所有组件

# Terminal 1: Start MCP Server
python -m src.mcp_server.server --transport sse --port 8080

# Terminal 2: Run Agent (optional)
python -m src.agent "Correlate thermal anomalies with news near Kyiv"

# Terminal 3: Start Dashboard (optional)
python -m src.dashboard.server --port 8000

您可以单独运行MCP服务器,并将多个客户端(代理、仪表板或自定义客户端)连接到它。

📁 项目结构

📂 Click to view Project Structure

fusion-center/
├── pyproject.toml              # Dependencies and config
├── .env.example                # Environment template
├── README.md
│
├── scripts/
│   └── telegram_auth.py        # One-time Telegram authentication
│
├── output/                     # Research outputs
│   └── {session_id}/
│       ├── report.md           # Final intelligence report
│       ├── reasoning.log       # Full reasoning trace
│       └── state.json          # Complete state snapshot
│
└── src/
    ├── __init__.py
    │
    ├── mcp_server/             # 🔧 MCP Server
    │   ├── __init__.py
    │   ├── server.py           # Server entry point
    │   └── tools/
    │       ├── geo.py          # NASA FIRMS
    │       ├── news.py         # GDELT
    │       ├── cyber.py        # IODA/Cloudflare
    │       ├── telegram.py     # Telegram OSINT channels
    │       └── threat_intel.py # AlienVault OTX
    │
    ├── agent/                  # 🤖 AI Agent
    │   ├── __init__.py
    │   ├── __main__.py         # CLI entry point
    │   ├── core.py             # Agent exports
    │   ├── graph.py            # LangGraph definition
    │   ├── nodes.py            # Graph nodes (incl. multi-step reasoning)
    │   ├── state.py            # Agent state schema
    │   ├── tools.py            # MCP tool executor
    │   └── prompts/            # System prompts & reasoning prompts
    │
    ├── dashboard/              # 🌐 Web Dashboard
    │   ├── __init__.py
    │   ├── server.py           # Dashboard server (FastAPI)
    │   ├── api.py              # API endpoints (MCP client)
    │   └── static/             # Frontend files
    │       ├── index.html      # Dashboard page
    │       ├── style.css       # Terminal DOS styling
    │       └── app.js          # Frontend logic
    │
    └── shared/                 # 🔗 Shared Code
        ├── __init__.py
        ├── config.py           # Centralized config
        ├── logger.py           # Rich logging
        └── output_writer.py    # Report & reasoning log writer

🔌 集成示例

Python客户端

from mcp import ClientSession
from mcp.client.sse import sse_client

async def analyze():
    async with sse_client("http://127.0.0.1:8080/sse") as (read, write):
        async with ClientSession(read, write) as session:
            await session.initialize()
            
            # Search news
            result = await session.call_tool(
                "search_news",
                arguments={
                    "keywords": "military activity",
                    "country_code": "UA",
                    "timespan": "3d"
                }
            )
            print(result)

以编程方式使用Agent

from src.agent.core import OverwatchAgent

async def run_analysis():
    agent = OverwatchAgent()
    result = await agent.run_analysis(
        task="Analyze internet outages in Iran and correlate with news",
        context={"country_code": "IR"}
    )
    return result

📊 数据源

来源描述身份验证
DuckDuckGo以隐私为中心的网络搜索免费(无API密钥)
DDoS秘密泄露/黑客攻击的数据存档免费(网络抓取)
GDELT全球新闻监测免费
梅杜莎俄罗斯独立新闻免费(RSS)
内幕俄罗斯调查性新闻免费(RSS)
摇篮地缘政治新闻(西亚)免费(RSS)
美国国家航空航天局公司卫星火灾探测免费API密钥
互联网中断免费
Cloudflare雷达流量分析免费(有限)
电报OSINT通道监控免费API凭据
AlienVault OTX威胁情报免费API密钥

🧪 发展

# Install dev dependencies
uv pip install -e ".[dev,agent]"

# Linting
ruff check src/

# Type checking
mypy src/

# Test server
python -m src.mcp_server.server --transport sse --port 8080

🧠 多步推理

该代理使用先进的多步推理进行更深入的分析:

🧠 Click to view Multi-step Reasoning Flow

┌─────────────────────────────────────────────────────────────────────────────────────┐
│                           MULTI-STEP REASONING FLOW                                 │
├─────────────────────────────────────────────────────────────────────────────────────┤
│                                                                                     │
│   ┌──────────┐    ┌─────────────┐    ┌──────────────┐    ┌───────────┐             │
│   │ PLANNING │───►│ DECOMPOSING │───►│ HYPOTHESIZING│───►│ GATHERING │◄────┐       │
│   └──────────┘    └─────────────┘    └──────────────┘    └─────┬─────┘     │       │
│                                                                 │           │       │
│                                                           (update hyp)     │       │
│                                                                 ▼           │       │
│                                                           ┌───────────┐     │       │
│                                                           │ ANALYZING │     │       │
│                                                           └─────┬─────┘     │       │
│                                                                 │           │       │
│                                                    ┌────────────┼───────────┘       │
│                                                    │ (follow-up)│                   │
│                                                    │            ▼                   │
│                                                    │      ┌────────────┐            │
│                                                    │      │ REFLECTING │◄──────┐    │
│                                                    │      └─────┬──────┘       │    │
│                                                    │            │              │    │
│                                                    │ (gaps)     │              │    │
│                                                    └────────────┤     (not ready)   │
│                                                                 ▼              │    │
│                                                           ┌────────────┐       │    │
│                                                           │ CORRELATING│       │    │
│                                                           └─────┬──────┘       │    │
│                                                                 ▼              │    │
│                                                           ┌───────────┐        │    │
│                                                           │ VERIFYING │────────┘    │
│                                                           └─────┬─────┘             │
│                                                                 │ (ready)           │
│                                                                 ▼                   │
│                                                           ┌─────────────┐           │
│                                                           │ SYNTHESIZING│           │
│                                                           └──────┬──────┘           │
│                                                                  ▼                  │
│                                                            ┌──────────┐             │
│                                                            │ COMPLETE │             │
│                                                            └──────────┘             │
│                                                                                     │
└─────────────────────────────────────────────────────────────────────────────────────┘

阶段描述

阶段描述
规划创建包含目标、地区、关键字和初始查询的研究计划
分解将复杂任务分解为可管理的子任务,评估复杂性
假设生成具有支持/反驳标准的可测试假设
聚集执行MCP查询,更新假设置信度(贝叶斯)
分析思维链分析、模式识别与假设有关
反光板自我批评:偏见检查、差距分析、替代解释
相互依赖查找跨源连接(时间、地理空间、因果关系)
验证验证结论,检查一致性,调整置信度
合成从生成最终报告 已验证 洞察力和相关性

相转变

条件
计划分解创建计划
分解假设任务中等/复杂
假设收集生成的假设
正在收集正在分析不再有待处理的查询
正在收集正在收集要执行的更多查询
分析反思分析完成
分析收集需要后续查询
反思关联无关键问题
反思收集差距需要更多调查
关联验证找到关联
验证合成验证通过
验证反思发现问题,需要审查
合成完成生成报告

益处

  • 思维链:透明度的明确分步推理
  • 假设检验:基于证据的情报分析方法
  • 置信度校准:根据反思调整信心
  • 偏差检测自我批评以识别潜在的盲点
  • 一致性检查:验证结论是否相互矛盾

推理轨迹

所有推理步骤都记录到 reasoning.log 包括:

  • 每一步的思考过程
  • 假设状态更新与置信度得分
  • 自我反思笔记和发现的问题
  • 洞察和相关性的验证结果

🗺️ 路线图

✅ 完成

  • \[x\] 配备OSINT工具的MCP服务器
  • \[x\] 丰富的测井系统
  • \[x\] 项目重组(单回购)
  • \[x\] 特工骨架
  • \[x\] LLM集成(Gemini/Grok/Ollama/Docker)
  • \[x\] 多步推理

🔴 优先级:新数据源

  • \[x\] 电报频道 -来自冲突区域的实时OSINT(Telethon API)
  • \[x\] AlienVault OTX -网络威胁情报开放威胁交换
  • \[x\] 订阅 -独立新闻来源(Meduza、The Insider、The Cradle)

🟡 未来

  • \[x\] 两个代理,一个用于推理,另一个用于严格的JSON输出
  • \[x\] 事件关联引擎
  • \[x\] Web仪表板
  • \[x\] 添加DuckDuckGo搜索工具
  • \[x\] 添加https://ddosecrets.com/作为一种工具(网页抓取)
  • \[\]使用PydanticAI而不是当前的langchain代理创建PoC代理

📄 许可证

MIT许可证

⚠️ 免责声明

此工具用于研究和教育目的。核实来自多个来源的信息,并遵守适用法律和API服务条款。

目录标签

目录标签

Python云端部署Docker开源情报本地部署卫星图像分析新闻媒体监控互联网基础设施

接入字段

传输方式(transport,传输协议)

stdio

鉴权方式(authType,认证方式)

session

运行时(runtime,运行环境)

Python

工具数量(toolCount,工具数)

0

资源数量(resourceCount,资源数)

0

提示词数量(promptCount,提示词数)

0

权限和风险

stdiosession部署方式未说明

接入前请确认传输方式、认证方式和部署位置,并根据实际工具能力限制访问范围。

安装前确认

不要直接授予不必要的文件、网络或账号权限;先核对安装命令和配置内容。

来源信息

继续浏览同类 MCP