{
  "_meta": {
    "view": "case_detail",
    "storage": "assembled by the detail API; not a physical table",
    "source_tables": [
      "sdm_case",
      "sdm_alert",
      "sdm_evidence",
      "sdm_analysis",
      "sdm_analysis_citation"
    ],
    "note": "members 是告警列表投影。点进某条再查 alert.detail.json。evidence 只含本案自有证据，不含成员告警 TRIGGER。案件叙事只在这里出现一次。"
  },
  "case": {
    "tenant_id": "tenant01",
    "case_id": "case_59782e57543384097b85dcfc",
    "created_time": 1734506882800,
    "case_name": "SQL注入 · 192.0.2.146",
    "description": "同一受害 IP、同一攻击源、15 分钟内的多条 SQL 注入源告警。弱关联因 rule_id 不同且主对象为 ip 不能并案，由关联引擎 correlation_id 编组。",
    "workflow_status": "NEW",
    "case_kind": "INVESTIGATION",
    "verdict": "UNKNOWN",
    "priority_score": 88,
    "score_source": "COMPUTED",
    "severity": "HIGH",
    "primary_entity_id": "ip:192.0.2.146",
    "primary_entity_type": "ip",
    "primary_entity_value": "192.0.2.146",
    "alert_count": 4,
    "correlation_id": "corr_42aaea032af935ce",
    "first_seen": 1734506882000,
    "last_seen": 1734508616000,
    "updated_time": 1734509043200,
    "latest_analysis_id": "an_case_daf835235a61fe15",
    "latest_analysis_conclusion": "SUSPICIOUS",
    "latest_analysis_summary": "同一源 192.0.2.238 在约一分钟内对 192.0.2.146 打出 4 类 SQL 注入（SQL注入攻击_SLEEP休眠函数注入、SQL注入攻击、SQL注入攻击_注释字符绕过、MSSQL Waitfor语句SQL注入攻击），合计命中 57 次，来源均标企图。关联资产 衡阳农商行快贷系统。无成功落地或数据外带证据。应按同一调查处置，核验 WAF 与应用日志。正式 verdict 仍为 UNKNOWN。",
    "latest_analysis_time": 1734509043200
  },
  "members": [
    {
      "slug": "sql_injection_sleep_function",
      "alert_id": "alert_b8394e3bb27f24b31765a384",
      "alert_display_id": "ALT-20241218-A26FBA8B",
      "alert_name": "SQL注入攻击_SLEEP休眠函数注入",
      "alert_type": "SOURCE_ALERT",
      "category_code": "EXPLOIT",
      "severity": "HIGH",
      "verdict": "UNKNOWN",
      "workflow_status": "NEW",
      "event_count": 14,
      "rule_id": "11724",
      "rule_name": "调整-网络探针检测到SQL注入事件",
      "primary_entity_id": "ip:192.0.2.146",
      "primary_entity_type": "ip",
      "primary_entity_value": "192.0.2.146",
      "primary_entity_role": "victim",
      "first_seen": 1734506882000,
      "last_seen": 1734508595000,
      "latest_analysis_conclusion": "SUSPICIOUS",
      "latest_analysis_confidence": 74
    },
    {
      "slug": "sql_injection_attempt",
      "alert_id": "alert_27d1706a8d1dbf0cfa17b465",
      "alert_display_id": "ALT-20241218-D74528BE",
      "alert_name": "SQL注入攻击",
      "alert_type": "SOURCE_ALERT",
      "category_code": "EXPLOIT",
      "severity": "HIGH",
      "verdict": "UNKNOWN",
      "workflow_status": "NEW",
      "event_count": 18,
      "rule_id": "1335",
      "rule_name": "调整-网络探针检测到SQL注入事件",
      "primary_entity_id": "ip:192.0.2.146",
      "primary_entity_type": "ip",
      "primary_entity_value": "192.0.2.146",
      "primary_entity_role": "victim",
      "first_seen": 1734506888000,
      "last_seen": 1734508612000,
      "latest_analysis_conclusion": "SUSPICIOUS",
      "latest_analysis_confidence": 74
    },
    {
      "slug": "sql_injection_comment_bypass",
      "alert_id": "alert_281a9f5389ac9b2cfcb7288e",
      "alert_display_id": "ALT-20241218-41387673",
      "alert_name": "SQL注入攻击_注释字符绕过",
      "alert_type": "SOURCE_ALERT",
      "category_code": "EXPLOIT",
      "severity": "HIGH",
      "verdict": "UNKNOWN",
      "workflow_status": "NEW",
      "event_count": 8,
      "rule_id": "304481",
      "rule_name": "SQL注入攻击_注释字符绕过",
      "primary_entity_id": "ip:192.0.2.146",
      "primary_entity_type": "ip",
      "primary_entity_value": "192.0.2.146",
      "primary_entity_role": "victim",
      "first_seen": 1734506889000,
      "last_seen": 1734508608000,
      "latest_analysis_conclusion": "SUSPICIOUS",
      "latest_analysis_confidence": 74
    },
    {
      "slug": "mssql_waitfor_delay_sql_injection",
      "alert_id": "alert_d7d70bb58dbddda778c058b6",
      "alert_display_id": "ALT-20241218-DD3D8D6B",
      "alert_name": "MSSQL Waitfor语句SQL注入攻击",
      "alert_type": "SOURCE_ALERT",
      "category_code": "EXPLOIT",
      "severity": "HIGH",
      "verdict": "UNKNOWN",
      "workflow_status": "NEW",
      "event_count": 17,
      "rule_id": "310189",
      "rule_name": "MSSQL Waitfor语句SQL注入攻击",
      "primary_entity_id": "ip:192.0.2.146",
      "primary_entity_type": "ip",
      "primary_entity_value": "192.0.2.146",
      "primary_entity_role": "victim",
      "first_seen": 1734506894000,
      "last_seen": 1734508616000,
      "latest_analysis_conclusion": "SUSPICIOUS",
      "latest_analysis_confidence": 74
    }
  ],
  "evidence": [
    {
      "tenant_id": "tenant01",
      "evidence_id": "ev_dff344f81cda87a74b906e3b",
      "subject_type": "CASE",
      "case_id": "case_59782e57543384097b85dcfc",
      "evidence_time": 1734509043200,
      "evidence_type": "INTEL",
      "external_ref": "intel:ip:192.0.2.238",
      "evidence_role": "ENRICHMENT",
      "evidence_summary": "调查补充：源 IP 192.0.2.238 的威胁情报命中（样例）。不是检出 TRIGGER，不重复挂到成员告警。",
      "sequence_no": 1,
      "weight": 0.5
    }
  ],
  "analyses": [
    {
      "analysis": {
        "tenant_id": "tenant01",
        "analysis_id": "an_case_daf835235a61fe15",
        "created_time": 1734509043200,
        "case_id": "case_59782e57543384097b85dcfc",
        "subject_type": "CASE",
        "analysis_type": "AI",
        "trigger_mode": "CASE",
        "conclusion": "SUSPICIOUS",
        "analysis_confidence": 80,
        "reasoning_summary": "同一源 192.0.2.238 在约一分钟内对 192.0.2.146 打出 4 类 SQL 注入（SQL注入攻击_SLEEP休眠函数注入、SQL注入攻击、SQL注入攻击_注释字符绕过、MSSQL Waitfor语句SQL注入攻击），合计命中 57 次，来源均标企图。关联资产 衡阳农商行快贷系统。无成功落地或数据外带证据。应按同一调查处置，核验 WAF 与应用日志。正式 verdict 仍为 UNKNOWN。",
        "evidence_gaps": [
          "http_request_body",
          "prevention_action",
          "db_audit"
        ],
        "recommended_actions": [
          "TREAT_AS_ONE_INVESTIGATION",
          "REVIEW_WAF_AND_APP_LOG",
          "CONFIRM_ASSET_OWNER"
        ],
        "accepted_status": "PENDING",
        "model_name": "triage-agent",
        "model_version": "2026.8.1",
        "prompt_version": "case-narrative-v1",
        "token_in": 1101,
        "token_out": 192,
        "duration_ms": 2560,
        "created_by": "ai"
      },
      "cites": [
        {
          "tenant_id": "tenant01",
          "analysis_id": "an_case_daf835235a61fe15",
          "evidence_id": "ev_52588753281a6d943a49d672",
          "evidence_subject_type": "ALERT",
          "alert_id": "alert_b8394e3bb27f24b31765a384",
          "evidence_type": "EVENT",
          "evidence_role": "TRIGGER",
          "event_id": "evt-47d5b0d8036453990c43912cf64f5ecca539c800739b908fc634a78bd6be2628",
          "evidence_summary": "SQL注入攻击_SLEEP休眠函数注入：192.0.2.238 → 192.0.2.146:80，命中 14 次。",
          "cited_time": 1734509043200
        },
        {
          "tenant_id": "tenant01",
          "analysis_id": "an_case_daf835235a61fe15",
          "evidence_id": "ev_f346c7cebc8bff74f710f1a3",
          "evidence_subject_type": "ALERT",
          "alert_id": "alert_27d1706a8d1dbf0cfa17b465",
          "evidence_type": "EVENT",
          "evidence_role": "TRIGGER",
          "event_id": "evt-7041f9ed6e8bc01b2267846a565f8ec81b8155782cb7816a39fd613428e818d3",
          "evidence_summary": "SQL注入攻击：192.0.2.238 → 192.0.2.146:80，命中 18 次。",
          "cited_time": 1734509043200
        },
        {
          "tenant_id": "tenant01",
          "analysis_id": "an_case_daf835235a61fe15",
          "evidence_id": "ev_a12f7d8703d93d11f481c8c3",
          "evidence_subject_type": "ALERT",
          "alert_id": "alert_281a9f5389ac9b2cfcb7288e",
          "evidence_type": "EVENT",
          "evidence_role": "TRIGGER",
          "event_id": "evt-08f3dc269d6e4e86f64eed1f7c4ccb33b8dc32b27688142b382e50a3e4792c93",
          "evidence_summary": "SQL注入攻击_注释字符绕过：192.0.2.238 → 192.0.2.146:80，命中 8 次。",
          "cited_time": 1734509043200
        },
        {
          "tenant_id": "tenant01",
          "analysis_id": "an_case_daf835235a61fe15",
          "evidence_id": "ev_1b56036f1934d57623896489",
          "evidence_subject_type": "ALERT",
          "alert_id": "alert_d7d70bb58dbddda778c058b6",
          "evidence_type": "EVENT",
          "evidence_role": "TRIGGER",
          "event_id": "evt-68ab54deb295b1b964dfcd7f3bdd04e48bacae8935176e07b394447ac70b408e",
          "evidence_summary": "MSSQL Waitfor语句SQL注入攻击：192.0.2.238 → 192.0.2.146:80，命中 17 次。",
          "cited_time": 1734509043200
        },
        {
          "tenant_id": "tenant01",
          "analysis_id": "an_case_daf835235a61fe15",
          "evidence_id": "ev_dff344f81cda87a74b906e3b",
          "evidence_subject_type": "CASE",
          "case_id": "case_59782e57543384097b85dcfc",
          "evidence_type": "INTEL",
          "evidence_role": "ENRICHMENT",
          "external_ref": "intel:ip:192.0.2.238",
          "evidence_summary": "调查补充：源 IP 192.0.2.238 的威胁情报命中（样例）。不是检出 TRIGGER，不重复挂到成员告警。",
          "cited_time": 1734509043200
        }
      ]
    }
  ],
  "workflow": []
}
