Conversation
Owner
Author
Live Splunk → n8n → IR validation completeCommit: Validated end to end on 2026-07-20:
Evidence: Security controls preserved: Authentik remains on the n8n editor, the relay binds only to |
Owner
Author
|
Closing this draft in favor of #20. The 143-file cross-cutting diff is not safely reviewable as one unit. The source branch is preserved as reference; implementation should return as concern-specific, rebased, independently validated PRs. |
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
1|## Summary
2|
3|Hardens the automated IR foundation into a public-safe, fixture-verifiable workflow and removes environment-specific live execution from the repository.
4|
5|### Implemented
6|
7|- deterministic, duplicate-aware alert intake with dry-run and audit support
8|- typed IOC enrichment with bounded timeout, fail-open results, and advisory-only CTI
9|- explicit
planned,fixture-collected, and live collection boundaries10|- fixture-backed evidence hashing, timeline, analysis, reporting, and cleanup tests
11|- honest hunt planning: no fabricated SIEM result count when no adapter executes
12|- bounded/authenticated IR receiver and Splunk-to-n8n relay defaults
13|- strict private preflight + approval-token + external-adapter contract for live validation
14|- generalized PowerShell-profile persistence Sigma logic and regenerated SPL/EQL
15|- strict validation schemas, public-safety scanner, and expanded CI gates
16|- README/current-state wording that separates present offline capability from dated historical live summaries
17|
18|### Security and repository hygiene
19|
20|- removed embedded environment-specific live validators
21|- removed committed runtime cases, manifests, and live-intake output
22|- sanitized historical validation records to summary-only metadata with source hashes
23|- sanitized public asset, workflow, endpoint, network, VM, and account identifiers
24|- keeps raw evidence and runtime case data outside Git
25|- destructive containment remains disabled
26|
27|## Validation performed
28|
29|
text 30|python3 playbook validate 31|python3 -m unittest discover -s tests -p 'test_*.py' -v 32|python3 automation/validators/public_safety.py 33|python3 automation/validators/check_markdown.py 34|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json sigma lint 35|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json sigma convert --target all 36|SIGMA_BIN=/tmp/detlab-pysigma-assess/bin/sigma python3 playbook --json test fixtures 37|python3 playbook --json validate previous-scenarios 38|python3 playbook --json metrics 39|python3 -m compileall -q automation tests 40|git diff --check 41|42|
43|Observed results:
44|
45|- 17 unit/security tests passed
46|- 11 Sigma rules linted without issues
47|- 33 backend artifacts generated
48|- 59 fixtures passed; 0 failures
49|- 11 sanitized historical validation summaries validated
50|- public-safety scan passed
51|- Markdown and schema checks passed
52|
53|## Validation boundaries
54|
55|### Fixture/repository validated
56|
57|- schemas and content structure
58|- Sigma lint/conversion
59|- positive/negative fixtures
60|- deterministic IR lifecycle
61|- receiver/relay authentication and payload bounds
62|- preflight and approval-token safety checks
63|- sanitized historical-summary parsing
64|
65|### Not freshly live validated in this change
66|
67|- Splunk saved searches, alerts, or webhook delivery
68|- endpoint/SIEM telemetry health
69|- Velociraptor or other DFIR collection
70|- OpenCTI/Shodan connectivity
71|- snapshot/rollback readiness
72|- Elastic backend behavior
73|- live containment
74|
75|Live execution now fails closed unless a fresh private preflight, mode-
0600approval token, expected digest, and executable external adapter all pass validation.76|