Skip to content

feat: validate T1569.002 service execution - #21

Merged
egrexsec merged 1 commit into
mainfrom
feat/pt-2026-012-service-execution
Jul 29, 2026
Merged

egrexsec merged 1 commit into
mainfrom
feat/pt-2026-012-service-execution

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

  • live-validates Atomic Red Team T1569.002 test UUID 2382dee2-a75f-49aa-9378-f52df6ed3fb1 on the approved Windows victim
  • adds a behavioral services.exe child-process Sigma rule, generated Splunk/Elastic queries, two positive fixtures, and three negative fixtures
  • records positive, variant, control, cleanup, snapshot, and postflight evidence
  • updates campaign metrics to 12 validated techniques (12/74, 16.2%)

Validation

  • both positive paths detected in Splunk
  • all three controls remained quiet
  • zero services/artifacts remained after cleanup
  • victim sensors and domain secure channel healthy; DC dcdiag /q quiet
  • 9/9 unit tests passed
  • 64/64 Sigma fixtures passed
  • 36 backend artifacts generated
  • schema, Markdown, JSON/YAML, historical records, and diff checks passed

Safety

  • victim-local only
  • no domain-controller execution
  • no credential access, lateral movement, destructive payload, or uncontrolled network activity
  • rollback snapshot: pre-pt-2026-012-t1569-002-20260729

Draft pending independent exact-head review and CI.

@egrexsec
egrexsec marked this pull request as ready for review July 29, 2026 17:18

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 788c9e6e58

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

- system-service-events
detections:
expected_rules:
- DET-2026-012

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Define the referenced DET-2026-012 record

The scenario declares DET-2026-012 as its expected rule, but a repository-wide search finds this as the identifier's only occurrence; the added service-execution.md summary defines neither that identifier nor its relationship to Sigma rule d7bfcdf8-7f68-4bcb-8a21-11f2c00f9a12. Consequently, consumers following expected_rules cannot resolve the scenario to its detection record, unlike the existing DET-2026-001 through DET-2026-011 artifacts. Define the identifier in the validation summary or add the corresponding detection record and mapping.

Useful? React with 👍 / 👎.

Comment on lines +64 to +65
self.assertEqual(len(positive), 2)
self.assertEqual(len(negative), 3)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Allow additional fixtures in the contract test

Adding any valid T1569.002 fixture will make this test fail solely because the directory count changed, even when the fixture harness successfully evaluates the new case. The campaign standard calls for at least two positive and three negative fixtures, so exact equality prevents normal coverage expansion; assert minimum counts or the presence of the five required fixture names instead.

Useful? React with 👍 / 👎.

@egrexsec
egrexsec merged commit ab27b2f into main Jul 29, 2026
2 checks passed
@egrexsec
egrexsec deleted the feat/pt-2026-012-service-execution branch July 29, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant