Add audited response apply rehearsal
This commit is contained in:
parent
51d52b5229
commit
0b010df514
11 changed files with 198 additions and 28 deletions
|
|
@ -355,6 +355,11 @@ not create artifacts. Plans also include pacman package-restore guidance
|
|||
plus read-only recovery checks for package verification, rootcheck, persistence
|
||||
re-checks, and off-host watchdog visibility.
|
||||
|
||||
`enodia-sentinel respond apply <plan-ref> --dry-run` reloads a saved plan,
|
||||
prints the reviewed actions, and appends an audit record without executing
|
||||
commands. Apply execution remains unsupported until the state-changing workflow
|
||||
is separately designed and tested.
|
||||
|
||||
Alert snapshots include a best-effort enrichment block that annotates flagged
|
||||
processes and paths with package ownership, executable hashes, parent chains,
|
||||
remote IP classification, file metadata, recent watched writes, and local
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue