Add stable v1 schema IDs and docs
This commit is contained in:
parent
bfef23fc4a
commit
7a176ea238
13 changed files with 409 additions and 8 deletions
|
|
@ -41,6 +41,8 @@ Project docs:
|
|||
response, fleet, and assurance layers.
|
||||
- [Operations guide](docs/OPERATIONS.md) — install checks, health checks, alert
|
||||
workflow, baseline hygiene, and evidence export.
|
||||
- [JSON schemas](docs/SCHEMAS.md) — stable v1 contracts for alerts, incidents,
|
||||
status, response plans, and response audit records.
|
||||
- [IR runbooks](docs/RUNBOOKS.md) — confirm/preserve/contain/recover playbooks
|
||||
per alert: reverse shells, persistence, trojaned binaries, rootkits, tampering.
|
||||
- [Rule reference](docs/RULES.md) — generated event-rule documentation: SID,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue