Skip to content

Split automated IR foundation into reviewable, independently validated slices #20

Description

@egrexsec

Why this replaces PR #16

PR #16 combines 143 files and +4,451/-3,132 lines across automation, schemas, detections, forensics, threat hunting, evidence, documentation, tests, and ten workflow files. Green CI is not enough to safely review or merge that scope, and its branch predates the merged shared-content contract and PowerShell lifecycle pack.

The source branch feat/automated-ir-powershell-foundation must remain available as reference until the slices below are landed or deliberately retired.

Required slices

  • Contracts and offline lifecycle core — schemas, deterministic case state transitions, bounded input, duplicate handling, dry-run/audit behavior, and focused unit tests. No generated content or live-environment material.
  • Receiver and relay security boundary — authenticated/bounded intake, Splunk relay contract, explicit fail-closed configuration, and adversarial tests. No environment-specific endpoints or credentials.
  • Collection and enrichment adapters — typed IOC enrichment, bounded timeout/fail-open CTI semantics, external adapter contract, and fixture-only collection evidence. Keep advisory CTI separate from execution decisions.
  • Detection-content changes — one rule/fixture/query family per PR, rebased onto the current shared contract and lifecycle-pack conventions.
  • Public-safe documentation and historical summaries — sanitization changes, validation boundaries, and public-safety checks, separated from behavior changes.
  • Private live-validation plan — fresh preflight, approval token, rollback readiness, execution, cleanup, and sanitized dated evidence. Do not merge live claims without a completed execution record.

Gates for every child PR

  1. Rebase on current main.
  2. TDD for behavior changes.
  3. Focused diff with one ownership concern.
  4. Public-safety and secret scans.
  5. Independent review before merge.
  6. Clearly separate fixture/repository proof from fresh live proof.

Not authorized by this issue

  • Destructive containment.
  • Committing runtime cases, raw telemetry, private endpoints, credentials, or connection details.
  • Treating historical validation summaries as fresh execution proof.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions