Skip to content

Add fixture-backed Sigma backend validation gates#2234

Open
Errordog2 wants to merge 1 commit into
UnitOneAI:mainfrom
Errordog2:codex/detection-fixture-backed-sigma-gates
Open

Add fixture-backed Sigma backend validation gates#2234
Errordog2 wants to merge 1 commit into
UnitOneAI:mainfrom
Errordog2:codex/detection-fixture-backed-sigma-gates

Conversation

@Errordog2

Copy link
Copy Markdown

/claim #2221

Summary

  • Adds a fixture-backed backend validation gate before detection coverage can be marked Tested or Operational.
  • Requires TP and benign fixtures, saved backend conversion output, expected/actual alert counts, backend parity review, and regression replay evidence.
  • Updates coverage definitions, detection-as-code CI/CD stages, output template, common pitfalls, and changelog for detection-engineering v1.0.1.

Why

Issue #2221 notes that synthetic validation was treated as sufficient even when Sigma rules lacked replayable fixture evidence and backend-specific conversion checks. This change makes the promotion criteria explicit and prevents Sigma-authored-only or Atomic-only coverage from being mislabeled as Tested.

Validation

  • git diff --check
  • Frontmatter required-field check across skills and roles
  • index.yaml file existence check
  • Prompt-injection phrase scan across skills and roles
  • Targeted rg check for version and new validation sections

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant