Add audited response apply rehearsal

This commit is contained in:
Luna 2026-07-09 05:56:25 -07:00
parent 51d52b5229
commit 0b010df514
No known key found for this signature in database
11 changed files with 198 additions and 28 deletions

View file

@ -355,6 +355,11 @@ not create artifacts. Plans also include pacman package-restore guidance
plus read-only recovery checks for package verification, rootcheck, persistence
re-checks, and off-host watchdog visibility.
`enodia-sentinel respond apply <plan-ref> --dry-run` reloads a saved plan,
prints the reviewed actions, and appends an audit record without executing
commands. Apply execution remains unsupported until the state-changing workflow
is separately designed and tested.
Alert snapshots include a best-effort enrichment block that annotates flagged
processes and paths with package ownership, executable hashes, parent chains,
remote IP classification, file metadata, recent watched writes, and local