Directories
¶
| Path | Synopsis |
|---|---|
|
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
|
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor. |
|
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
|
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D). |
|
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
|
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405). |
|
Package correlationuc orchestrates durable, two-phase event-time correlation.
|
Package correlationuc orchestrates durable, two-phase event-time correlation. |
|
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
|
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean". |
|
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
|
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows. |
|
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
|
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state. |
|
Package detect is the agent-side detection engine (issue #422, phase 3).
|
Package detect is the agent-side detection engine (issue #422, phase 3). |
|
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
|
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches. |
|
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
|
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423). |
|
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
|
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669). |
|
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
|
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity. |
|
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
|
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure. |
|
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
|
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405). |
|
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
|
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820). |
|
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
|
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log. |
|
Package incidentuc is the usecase seam over the event-sourced incident store.
|
Package incidentuc is the usecase seam over the event-sourced incident store. |
|
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
|
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys. |
|
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
|
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults. |
|
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
|
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622). |
|
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
|
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export. |
|
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
|
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents. |
|
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
|
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D). |
|
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
|
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal. |
|
Package responseobservation runs the endpoint-side, independent response-observation workflow.
|
Package responseobservation runs the endpoint-side, independent response-observation workflow. |
|
Package responseobserver governs secondary agents that may observe response post-conditions.
|
Package responseobserver governs secondary agents that may observe response post-conditions. |
|
Package responseverificationingest authenticates and persists purpose-signed response observations.
|
Package responseverificationingest authenticates and persists purpose-signed response observations. |
|
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
|
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired. |
|
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
|
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers. |
|
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
|
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event. |
|
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
|
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061). |
|
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
|
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001). |
|
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
|
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently. |
Click to show internal directories.
Click to hide internal directories.