Skip to content

Publish Validated PowerShell Detection Lifecycle v1 - #19

Merged
egrexsec merged 1 commit into
mainfrom
feat/validated-powershell-lifecycle-v1
Jul 29, 2026
Merged

egrexsec merged 1 commit into
mainfrom
feat/validated-powershell-lifecycle-v1

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

  • publish a deterministic PT-2026-001 lifecycle manifest
  • hash the canonical Sigma source, all positive/negative fixtures, and generated Splunk/Elastic artifacts
  • link canonical content to DetLab and sanitized Mayuri evidence without copying raw telemetry
  • fail CI when the committed pack becomes stale

Validation

  • 4 Python tests passed
  • 9/9 T1059.001 fixtures passed
  • lifecycle manifest staleness check passed
  • markdown links passed
  • Sigma lint completed with no errors (one pre-existing warning in an unrelated rule)

Evidence boundary

This organizes the existing 2026-07-18 live validation. It does not claim a new execution or newly measured latency.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 09b19d8021

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


- name: Validated PowerShell lifecycle pack
run: |
python3 automation/build_powershell_lifecycle_pack.py --check

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Check staleness before regenerating artifacts

In the inspected detection-validation workflow, an artifact-only change can pass this check because the earlier Sigma conversion step rewrites every generated SPL/EQL file before --check hashes them. With no subsequent git diff --exit-code, CI compares the regenerated canonical files to the old manifest and succeeds, while the changed file remains in the commit and becomes stale after merge. Run the lifecycle check before conversion or verify that conversion leaves the worktree unchanged.

Useful? React with 👍 / 👎.

@egrexsec
egrexsec merged commit e64a35f into main Jul 29, 2026
2 checks passed
@egrexsec
egrexsec deleted the feat/validated-powershell-lifecycle-v1 branch July 29, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant