You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #16 combines 143 files and +4,451/-3,132 lines across automation, schemas, detections, forensics, threat hunting, evidence, documentation, tests, and ten workflow files. Green CI is not enough to safely review or merge that scope, and its branch predates the merged shared-content contract and PowerShell lifecycle pack.
The source branch feat/automated-ir-powershell-foundation must remain available as reference until the slices below are landed or deliberately retired.
Required slices
Contracts and offline lifecycle core — schemas, deterministic case state transitions, bounded input, duplicate handling, dry-run/audit behavior, and focused unit tests. No generated content or live-environment material.
Receiver and relay security boundary — authenticated/bounded intake, Splunk relay contract, explicit fail-closed configuration, and adversarial tests. No environment-specific endpoints or credentials.
Collection and enrichment adapters — typed IOC enrichment, bounded timeout/fail-open CTI semantics, external adapter contract, and fixture-only collection evidence. Keep advisory CTI separate from execution decisions.
Detection-content changes — one rule/fixture/query family per PR, rebased onto the current shared contract and lifecycle-pack conventions.
Public-safe documentation and historical summaries — sanitization changes, validation boundaries, and public-safety checks, separated from behavior changes.
Private live-validation plan — fresh preflight, approval token, rollback readiness, execution, cleanup, and sanitized dated evidence. Do not merge live claims without a completed execution record.
Gates for every child PR
Rebase on current main.
TDD for behavior changes.
Focused diff with one ownership concern.
Public-safety and secret scans.
Independent review before merge.
Clearly separate fixture/repository proof from fresh live proof.
Not authorized by this issue
Destructive containment.
Committing runtime cases, raw telemetry, private endpoints, credentials, or connection details.
Treating historical validation summaries as fresh execution proof.
Why this replaces PR #16
PR #16 combines 143 files and +4,451/-3,132 lines across automation, schemas, detections, forensics, threat hunting, evidence, documentation, tests, and ten workflow files. Green CI is not enough to safely review or merge that scope, and its branch predates the merged shared-content contract and PowerShell lifecycle pack.
The source branch
feat/automated-ir-powershell-foundationmust remain available as reference until the slices below are landed or deliberately retired.Required slices
Gates for every child PR
main.Not authorized by this issue