Skip to content

feat: add shared detection content specification v1 - #18

Merged
egrexsec merged 1 commit into
mainfrom
feat/detection-content-spec-v1
Jul 27, 2026
Merged

egrexsec merged 1 commit into
mainfrom
feat/detection-content-spec-v1

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

  • add the shared DetLab Detection Content Specification v1 JSON Schema
  • normalize canonical Sigma rules into the portable contract
  • record canonical source hashes and generated-artifact provenance
  • validate every authored Sigma rule through the contract in CI
  • document that Sigma remains canonical and generated queries remain derived

Validation

  • python playbook validate
  • python -m unittest discover -s tests -p 'test_*.py' -v
  • python playbook --json sigma lint
  • python automation/validators/check_markdown.py
  • git diff --check

Boundaries

  • no live lab or SIEM validation was performed
  • this PR does not replace authored Sigma or claim generated targets are live validated
  • contract schema is byte-identical to the copy proposed in egrexsec/DetLab-DAC

@egrexsec
egrexsec marked this pull request as ready for review July 27, 2026 16:36
@egrexsec
egrexsec merged commit fcf52b6 into main Jul 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant