Skip to content

feat: harden automated IR and validation safety boundaries - #16

Closed
egrexsec wants to merge 3 commits into
mainfrom
feat/automated-ir-powershell-foundation
Closed

egrexsec wants to merge 3 commits into
mainfrom
feat/automated-ir-powershell-foundation

Conversation

@egrexsec

@egrexsec egrexsec commented Jul 19, 2026 •

Copy link
Copy Markdown
Owner

1|## Summary
2|
3|Hardens the automated IR foundation into a public-safe, fixture-verifiable workflow and removes environment-specific live execution from the repository.
4|
5|### Implemented
6|
7|- deterministic, duplicate-aware alert intake with dry-run and audit support
8|- typed IOC enrichment with bounded timeout, fail-open results, and advisory-only CTI
9|- explicit planned, fixture-collected, and live collection boundaries
10|- fixture-backed evidence hashing, timeline, analysis, reporting, and cleanup tests
11|- honest hunt planning: no fabricated SIEM result count when no adapter executes
12|- bounded/authenticated IR receiver and Splunk-to-n8n relay defaults
13|- strict private preflight + approval-token + external-adapter contract for live validation
14|- generalized PowerShell-profile persistence Sigma logic and regenerated SPL/EQL
15|- strict validation schemas, public-safety scanner, and expanded CI gates
16|- README/current-state wording that separates present offline capability from dated historical live summaries
17|
18|### Security and repository hygiene
19|
20|- removed embedded environment-specific live validators
21|- removed committed runtime cases, manifests, and live-intake output
22|- sanitized historical validation records to summary-only metadata with source hashes
23|- sanitized public asset, workflow, endpoint, network, VM, and account identifiers
24|- keeps raw evidence and runtime case data outside Git
25|- destructive containment remains disabled
26|
27|## Validation performed
28|
29|text 30|python3 playbook validate 31|python3 -m unittest discover -s tests -p 'test_*.py' -v 32|python3 automation/validators/public_safety.py 33|python3 automation/validators/check_markdown.py 34|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json sigma lint 35|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json sigma convert --target all 36|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json test fixtures 37|python3 playbook --json validate previous-scenarios 38|python3 playbook --json metrics 39|python3 -m compileall -q automation tests 40|git diff --check 41|
42|
43|Observed results:
44|
45|- 17 unit/security tests passed
46|- 11 Sigma rules linted without issues
47|- 33 backend artifacts generated
48|- 59 fixtures passed; 0 failures
49|- 11 sanitized historical validation summaries validated
50|- public-safety scan passed
51|- Markdown and schema checks passed
52|
53|## Validation boundaries
54|
55|### Fixture/repository validated
56|
57|- schemas and content structure
58|- Sigma lint/conversion
59|- positive/negative fixtures
60|- deterministic IR lifecycle
61|- receiver/relay authentication and payload bounds
62|- preflight and approval-token safety checks
63|- sanitized historical-summary parsing
64|
65|### Not freshly live validated in this change
66|
67|- Splunk saved searches, alerts, or webhook delivery
68|- endpoint/SIEM telemetry health
69|- Velociraptor or other DFIR collection
70|- OpenCTI/Shodan connectivity
71|- snapshot/rollback readiness
72|- Elastic backend behavior
73|- live containment
74|
75|Live execution now fails closed unless a fresh private preflight, mode-0600 approval token, expected digest, and executable external adapter all pass validation.
76|

@egrexsec

Copy link
Copy Markdown
Owner Author

Live Splunk → n8n → IR validation complete

Commit: 896d87a

Validated end to end on 2026-07-20:

  • PT-2026-001 replay generated PowerShell Operational event 4104 on VICTIM-MAYURI.
  • Splunk saved search DET-2026-001-live-webhook returned result_count=1, executed alert_actions="webhook", and recorded fired=1.
  • Source-restricted Mayuri relay accepted the POST from SOC 10.10.10.20 and returned HTTP 200.
  • Live n8n normalized and forwarded the alert to the Tailscale-bound VPS receiver.
  • The deterministic controller created IR-2026-006 with rule DET-2026-001, ATT&CK T1059.001, severity high, and the original Splunk SID / 4104 script block preserved.
  • Subsequent matching scheduler runs recorded suppressed=1, confirming duplicate suppression.

Evidence: evidence/live-intake-validation-2026-07-20.md and investigations/cases/IR-2026-006/.

Security controls preserved: Authentik remains on the n8n editor, the relay binds only to vmbr10 and permits only the SOC source, the receiver binds only to Tailscale and requires a token, and containment remains approval-gated.

@egrexsec egrexsec changed the title feat: add automated IR PowerShell workflow foundation feat: harden automated IR and validation safety boundaries Jul 21, 2026
@egrexsec

Copy link
Copy Markdown
Owner Author

Closing this draft in favor of #20. The 143-file cross-cutting diff is not safely reviewable as one unit. The source branch is preserved as reference; implementation should return as concern-specific, rebased, independently validated PRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant