enodia-sentinal/docs
Luna 6a06eba255
docs(behavior): add behavioral spec for sweep + baseline lifecycle
Start a per-subsystem behavioral specification under docs/behavior/ that
documents the current Python agent's observable behavior at reimplementation
fidelity. It is the parity contract for the Go 2.0 rewrite (Active Migration
Track), complementing the product-oriented docs/SPECIFICATION.md.

Section 1 covers system-state capture, the daemon sweep loop, alert dedup, the
detector registry gating, and the baseline lifecycle — including three
behaviors the port must match exactly: baselines are rebuilt (not loaded) at
daemon start, arming is time-based via baseline_grace, and first_seen's
initialized flag persists across restarts while listener/SUID baselines
re-learn every start.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D36ffwoga57opftxzJVHPW
2026-07-19 10:08:32 -07:00
..
behavior docs(behavior): add behavioral spec for sweep + baseline lifecycle 2026-07-19 10:08:32 -07:00
superpowers Add enrichment and SID coverage gates 2026-07-08 17:05:17 -07:00
COMMAND_REFERENCE.md Add host correlation and assurance coverage 2026-07-10 04:04:27 -07:00
FLEET_DESIGN.md Add host correlation and assurance coverage 2026-07-10 04:04:27 -07:00
INDEX.md Add Suricata assimilation design 2026-07-10 04:16:31 -07:00
OPERATIONS.md Expand TUI guidance and host detection coverage 2026-07-09 19:16:27 -07:00
PACKAGING.md Add terminal TUI and shell completion 2026-07-08 20:47:58 -07:00
ROADMAP.md feat(go): port socket detectors 2026-07-10 17:29:07 -07:00
RULES.md Add host event rules for bind and capability activity 2026-07-10 04:11:33 -07:00
RUNBOOKS.md Add host correlation and assurance coverage 2026-07-10 04:04:27 -07:00
SCHEMAS.md feat(go): add Phase 1 parity sidecar 2026-07-10 05:02:50 -07:00
SPECIFICATION.md Add typed host event egress rule 2026-07-09 06:04:30 -07:00
SURICATA_ASSIMILATION.md feat(go): port memory-map detector tranche 2026-07-11 01:19:56 -07:00
THREAT_MODEL.md Frame Sentinel as IDS IPS and EDR 2026-06-13 05:59:03 -07:00
VERSION.json Document packaging and release artifacts 2026-06-17 00:22:43 -07:00