feat: validate T1569.002 service execution - #21
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 788c9e6e58
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - system-service-events | ||
| detections: | ||
| expected_rules: | ||
| - DET-2026-012 |
There was a problem hiding this comment.
Define the referenced DET-2026-012 record
The scenario declares DET-2026-012 as its expected rule, but a repository-wide search finds this as the identifier's only occurrence; the added service-execution.md summary defines neither that identifier nor its relationship to Sigma rule d7bfcdf8-7f68-4bcb-8a21-11f2c00f9a12. Consequently, consumers following expected_rules cannot resolve the scenario to its detection record, unlike the existing DET-2026-001 through DET-2026-011 artifacts. Define the identifier in the validation summary or add the corresponding detection record and mapping.
Useful? React with 👍 / 👎.
| self.assertEqual(len(positive), 2) | ||
| self.assertEqual(len(negative), 3) |
There was a problem hiding this comment.
Allow additional fixtures in the contract test
Adding any valid T1569.002 fixture will make this test fail solely because the directory count changed, even when the fixture harness successfully evaluates the new case. The campaign standard calls for at least two positive and three negative fixtures, so exact equality prevents normal coverage expansion; assert minimum counts or the presence of the five required fixture names instead.
Useful? React with 👍 / 👎.
Summary
2382dee2-a75f-49aa-9378-f52df6ed3fb1on the approved Windows victimservices.exechild-process Sigma rule, generated Splunk/Elastic queries, two positive fixtures, and three negative fixturesValidation
dcdiag /qquietSafety
pre-pt-2026-012-t1569-002-20260729Draft pending independent exact-head review and CI.