Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
86 changes: 42 additions & 44 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# DetLab

DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, and distributing behavioral detections across multiple security backends.
DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, distributing, and verifying behavioral detections across multiple security backends.

## Platform Capabilities

Expand All @@ -12,72 +12,69 @@ DetLab is an advanced detection engineering platform for validating, translating
- HTML analytics dashboards
- Detection pack management
- Pack registry workflows
- Pack trust verification
- Governance reporting
- CI/CD integration

## Detection Pack Registry
## Detection Pack Trust Verification

DetLab now supports registry-oriented detection pack workflows.
DetLab now supports integrity-oriented pack verification workflows.

## Pack Lifecycle
## Verification Workflow

```text
Build -> Publish -> Install -> Validate -> Analyze
Build -> Publish -> Verify -> Install -> Analyze
```

## Supported Workflows
## Supported Verification Workflows

### Build Detection Pack
### Verify Detection Pack

```bash
detlab pack build packs/windows-core
detlab pack verify registry/windows-core-1.0.0.tar.gz \
--metadata registry/windows-core.json
Comment on lines +34 to +35

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Wire the documented pack verify command

This new documented workflow is not reachable from the CLI: pyproject.toml points detlab at detlab.main:app, and detlab/main.py only registers the existing top-level commands with no pack Typer sub-app or verify command, while the new trust functions are never imported there. Users following this example will get an unknown-command error instead of pack verification, so the CLI needs to expose this workflow or the docs should not advertise it.

Useful? React with 👍 / 👎.

```

Creates:
- distributable archives
- checksum metadata
- semantic version metadata
Supports:
- SHA256 verification
- Registry metadata validation
- Pack integrity validation
- Trust-oriented governance workflows

### Publish Detection Pack
## Example Trust Metadata

```bash
detlab pack publish packs/windows-core
```json
{
"name": "windows-core",
"version": "1.0.0",
"checksum": "sha256-value",
"trust": {
"verified": true,
"algorithm": "sha256"
}
}
```

Creates:
- registry archives
- registry metadata manifests
- reusable distributable bundles
## Detection Pack Registry

### Install Detection Pack
DetLab supports registry-oriented detection pack workflows.

### Build Detection Pack

```bash
detlab pack install windows-core
detlab pack build packs/windows-core
```

Supports:
- local registry cache
- reusable deployments
- portable content workflows

## Registry Metadata Example
### Publish Detection Pack

```json
{
"name": "windows-core",
"version": "1.0.0",
"checksum": "sha256-value",
"archive": "windows-core-1.0.0.tar.gz"
}
```bash
detlab pack publish packs/windows-core
```

## Detection Pack Structure
### Install Detection Pack

```text
packs/
windows-core/
pack.yml
detections/
```bash
detlab pack install windows-core
```

## Behavioral Detection Example
Expand Down Expand Up @@ -113,16 +110,17 @@ sequence:
- Pack-level reporting
- Behavioral analytics
- Executive dashboards
- Pack integrity verification

## Long-Term Vision

DetLab is evolving toward:

- community detection ecosystems
- reusable behavioral detection libraries
- enterprise detection governance
- portable detection engineering pipelines
- threat-informed analytics platforms
- secure detection distribution ecosystems
- reusable behavioral detection libraries
- trusted security content pipelines
- portable detection engineering platforms

## License

Expand Down
44 changes: 44 additions & 0 deletions detlab/trust.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
from pathlib import Path
import json

from detlab.registry import calculate_checksum



def load_metadata(metadata_path: Path) -> dict:
return json.loads(metadata_path.read_text(encoding="utf-8"))



def verify_checksum(archive_path: Path, expected_checksum: str) -> bool:
calculated = calculate_checksum(archive_path)
return calculated == expected_checksum



def verify_pack(archive_path: Path, metadata_path: Path) -> dict:
metadata = load_metadata(metadata_path)

expected_checksum = metadata.get("checksum")
verified = verify_checksum(archive_path, expected_checksum)

return {
"name": metadata.get("name"),
"version": metadata.get("version"),
"verified": verified,
"checksum": expected_checksum,
"archive": archive_path.name,
}



def generate_trust_metadata(name: str, version: str, checksum: str) -> dict:
return {
"name": name,
"version": version,
"checksum": checksum,
"trust": {
"verified": True,
"algorithm": "sha256",
},
}
44 changes: 44 additions & 0 deletions tests/test_trust.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
import json
from pathlib import Path

from detlab.trust import generate_trust_metadata, verify_checksum, verify_pack
from detlab.registry import calculate_checksum


def test_verify_checksum(tmp_path: Path):
archive = tmp_path / "pack.tar.gz"
archive.write_text("detlab-pack", encoding="utf-8")

checksum = calculate_checksum(archive)

assert verify_checksum(archive, checksum) is True


def test_verify_pack(tmp_path: Path):
archive = tmp_path / "windows-core-1.0.0.tar.gz"
archive.write_text("detlab-pack", encoding="utf-8")

checksum = calculate_checksum(archive)

metadata = {
"name": "windows-core",
"version": "1.0.0",
"checksum": checksum,
"archive": archive.name,
}

metadata_path = tmp_path / "windows-core.json"
metadata_path.write_text(json.dumps(metadata), encoding="utf-8")

result = verify_pack(archive, metadata_path)

assert result["verified"] is True
assert result["name"] == "windows-core"


def test_generate_trust_metadata():
metadata = generate_trust_metadata("windows-core", "1.0.0", "abc123")

assert metadata["name"] == "windows-core"
assert metadata["trust"]["algorithm"] == "sha256"
assert metadata["trust"]["verified"] is True
Loading