Add incident grouping (roadmap v0.8: incident list/show/export)
Collapse related alerts into one incident, process-lineage first with a time-window fallback. Each alert batch's flagged PIDs are walked up the /proc PPid chain into a lineage set (excluding pid 0/1 so everything doesn't correlate through init); batches whose lineage sets intersect — sharing a process or a common ancestor like the web server or SSH session — join the same incident. PID-less batches (FIM drift, package tamper, hidden modules) fall back to the most recently active open incident within incident_window. snapshot.capture now computes lineage and records each snapshot into a JSON incident index (incidents.json), writing incident_id into both the report JSON (report level, so the per-alert schema is untouched) and the text header. New commands: incident list incidents newest-first, with signatures incident show <id> summary + time-ordered snapshot timeline incident export <id> JSON bundle: record + inlined snapshots The lineage/assign cores are pure functions; record() serializes the index under a lock (capture runs from sweep + eBPF threads) and is best-effort so an index problem never loses a snapshot. 17 new tests (lineage, assign, record, and an end-to-end capture→group→CLI path). Config: incident_tracking / incident_window / incident_lineage_depth. Docs + sample config updated; closes the last v0.8 roadmap item. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
4015ec872b
commit
a56d72edd6
9 changed files with 545 additions and 13 deletions
|
|
@ -92,6 +92,15 @@ rootcheck_enabled = true
|
|||
rootcheck_interval = 300 # seconds between cross-view sweeps
|
||||
rootcheck_pid_cap = 65536 # upper PID to brute-force via kill(0)
|
||||
|
||||
# --- incident grouping ---------------------------------------------------
|
||||
# Collapse related alerts into one incident: process-lineage first (shared PID
|
||||
# or ancestor — the web server / SSH session the alerts descend from), then a
|
||||
# time fallback for PID-less alerts (FIM drift, package tamper). Each snapshot
|
||||
# gets an incident_id; browse with `enodia-sentinel incident list/show/export`.
|
||||
incident_tracking = true
|
||||
incident_window = 1800 # seconds an incident stays open for new alerts
|
||||
incident_lineage_depth = 8 # ancestors walked when correlating
|
||||
|
||||
# --- host posture --------------------------------------------------------
|
||||
# Config-hygiene audit run on demand (`enodia-sentinel posture check`), not in
|
||||
# the daemon loop: root SSH login, password auth, passwordless sudo, world-
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue