Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
140 changes: 72 additions & 68 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,81 +1,86 @@
# DetLab

DetLab is an open-source detection-as-code platform for validating detections, generating analytics, exporting detections across platforms, and managing reusable behavioral detection content.
DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, and distributing behavioral detections across multiple security backends.

## Core Capabilities
## Platform Capabilities

- Detection validation
- ATT&CK mapping
- ATT&CK analytics
- ATT&CK mapping and analytics
- Detection maturity scoring
- Behavioral sequence detections
- Sigma import/export
- Splunk SPL export
- Microsoft Sentinel KQL export
- Elastic EQL export
- HTML dashboard generation
- Multi-platform export pipelines
- HTML analytics dashboards
- Detection pack management
- Pack registry workflows
- Governance reporting
- CI/CD integration

## Detection Packs
## Detection Pack Registry

DetLab now supports reusable detection packs.
DetLab now supports registry-oriented detection pack workflows.

### Example Structure
## Pack Lifecycle

```text
packs/
windows-core/
pack.yml
detections/

insider-threat/
pack.yml
detections/
Build -> Publish -> Install -> Validate -> Analyze
```

### Example Manifest
## Supported Workflows

```yaml
name: windows-core
version: 1.0.0
maintainer: Mell0wx
platforms:
- splunk
- sentinel
- elastic

attack_tactics:
- execution
- persistence
### Build Detection Pack

```bash
detlab pack build packs/windows-core

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Wire the documented pack CLI before advertising it

These new workflows are documented as detlab pack ..., but I checked the actual console entry point (pyproject.toml points detlab at detlab.main:app) and detlab/main.py still only registers the existing top-level commands; there is no pack Typer sub-app or command. As a result, users following this README will get an unknown-command error instead of being able to build, publish, or install packs.

Useful? React with 👍 / 👎.

```

## Pack Features
Creates:
- distributable archives
- checksum metadata
- semantic version metadata

- Pack manifest validation
- Version tracking
- Supported backend tracking
- ATT&CK coverage summaries
- Pack maturity scoring
- Dependency tracking
- Reusable detection libraries
### Publish Detection Pack

## Example Pack Workflows
```bash
detlab pack publish packs/windows-core
```

Creates:
- registry archives
- registry metadata manifests
- reusable distributable bundles

### Validate Pack
### Install Detection Pack

```bash
detlab pack validate packs/windows-core
detlab pack install windows-core
```

### Generate Pack Report
Supports:
- local registry cache
- reusable deployments
- portable content workflows

```bash
detlab pack report packs/windows-core --format markdown
## Registry Metadata Example

```json
{
"name": "windows-core",
"version": "1.0.0",
"checksum": "sha256-value",
"archive": "windows-core-1.0.0.tar.gz"
}
```

## Detection Pack Structure

```text
packs/
windows-core/
pack.yml
detections/
```

## Behavioral Sequence Example
## Behavioral Detection Example

```yaml
sequence:
Expand All @@ -86,39 +91,38 @@ sequence:
selection:
Image: powershell.exe

- name: Suspicious Network Connection
- name: Network Connection
selection:
DestinationPort: 4444
```

## Platform Export Matrix
## Supported Export Targets

| Backend | Supported |
| Backend | Support |
|---|---|
| Sigma | Yes |
| Splunk SPL | Yes |
| Microsoft Sentinel KQL | Yes |
| Elastic EQL | Yes |

## Governance + Analytics
## Governance Features

DetLab supports:

- ATT&CK tactic coverage analysis
- Detection quality scoring
- ATT&CK coverage analytics
- Weak detection identification
- Maturity distributions
- HTML executive dashboards
- Behavioral analytics foundations

## Roadmap

- Pack publishing
- Community registry
- Interactive dashboards
- Correlation rule generation
- Behavioral detection packs
- Threat-informed analytics
- Detection maturity scoring
- Pack-level reporting
- Behavioral analytics
- Executive dashboards

## Long-Term Vision

DetLab is evolving toward:

- community detection ecosystems
- reusable behavioral detection libraries
- enterprise detection governance
- portable detection engineering pipelines
- threat-informed analytics platforms

## License

Expand Down
83 changes: 83 additions & 0 deletions detlab/registry.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
from pathlib import Path
import hashlib
import json
import shutil
import tarfile

from detlab.packs import load_pack_manifest

LOCAL_REGISTRY = Path(".detlab/registry")



def calculate_checksum(path: Path) -> str:
sha256 = hashlib.sha256()

with path.open("rb") as f:
while chunk := f.read(8192):
sha256.update(chunk)

return sha256.hexdigest()



def build_pack(pack_dir: Path, output_dir: Path = Path("dist")) -> Path:
manifest = load_pack_manifest(pack_dir)

output_dir.mkdir(parents=True, exist_ok=True)

archive_name = f"{manifest['name']}-{manifest['version']}.tar.gz"
archive_path = output_dir / archive_name

with tarfile.open(archive_path, "w:gz") as tar:
tar.add(pack_dir, arcname=pack_dir.name)

checksum = calculate_checksum(archive_path)

metadata = {
"name": manifest["name"],
"version": manifest["version"],
"checksum": checksum,
"platforms": manifest.get("platforms", []),
}

metadata_path = output_dir / f"{manifest['name']}-{manifest['version']}.json"
metadata_path.write_text(json.dumps(metadata, indent=2), encoding="utf-8")

return archive_path



def install_pack(archive_path: Path, install_dir: Path = LOCAL_REGISTRY) -> Path:
install_dir.mkdir(parents=True, exist_ok=True)

with tarfile.open(archive_path, "r:gz") as tar:
tar.extractall(path=install_dir)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reject unsafe tar members before extraction

When install_pack is used on a pack archive from a registry or another user, tar.extractall on the supported Python 3.11/3.12 targets will honor member names such as ../../... and can overwrite files outside .detlab/registry. Please validate that every member resolves under install_dir (and handle links/devices appropriately) or use a safe extraction filter before unpacking downloaded packs.

Useful? React with 👍 / 👎.


return install_dir



def publish_pack(pack_dir: Path, registry_dir: Path = Path("registry")) -> dict:
registry_dir.mkdir(parents=True, exist_ok=True)

archive = build_pack(pack_dir, registry_dir)

checksum = calculate_checksum(archive)

manifest = load_pack_manifest(pack_dir)

published_metadata = {
"name": manifest["name"],
"version": manifest["version"],
"checksum": checksum,
"archive": archive.name,
}

metadata_file = registry_dir / f"{manifest['name']}.json"
metadata_file.write_text(
json.dumps(published_metadata, indent=2),
encoding="utf-8",
)

return published_metadata
14 changes: 14 additions & 0 deletions tests/test_registry.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
from pathlib import Path

from detlab.registry import calculate_checksum



def test_calculate_checksum(tmp_path: Path):
test_file = tmp_path / "test.txt"
test_file.write_text("detlab", encoding="utf-8")

checksum = calculate_checksum(test_file)

assert isinstance(checksum, str)
assert len(checksum) == 64
Loading