Skip to content

Improve alert enrichment provenance gates#2186

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/alert-enrichment-freshness-fixtures-2032
Open

Improve alert enrichment provenance gates#2186
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/alert-enrichment-freshness-fixtures-2032

Conversation

@DENGXUELIN

Copy link
Copy Markdown

/claim #2032

Summary

  • Adds enrichment freshness and provenance gates to alert-triage.
  • Requires asset/user freshness, threat-intel provenance, GeoIP/ASN/provider corroboration, historical disposition drift checks, post-containment timestamp handling, analyst override provenance, and correlated-alert enrichment age.
  • Adds skill-local JSON fixtures for stale/copied enrichment causing an FP/P4 decision and for current or Not Evaluable enrichment handled safely.

Validation

  • git diff --cached --check
  • git diff --check origin/main...HEAD
  • Parsed both JSON fixtures with ConvertFrom-Json
  • Verified Markdown fence balance
  • Verified TRIAGE-ENRICH-01 through TRIAGE-ENRICH-08 markers
  • Added-line sensitive-pattern scan
  • git merge-tree --write-tree origin/main HEAD matched HEAD^{tree}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant