Feature/risk object local - #48
Merged
Merged
Conversation
- add rule preview action and result modal in Detection rule detail - build a dedicated Kibana preview payload separate from publish payload - query internal Kibana preview alert indices for matched alert count and samples - display matched event count and first 10 preview alert samples - add ES|QL regeneration from Sigma - persist detection schedule, ES|QL source, and entity risk configuration - support generated risk/notable actions for Kibana publishing
…e/risk-object-local # Conflicts: # frontend/src/modules/detections/DetectionRuleDetail.tsx # frontend/src/modules/detections/Detections.tsx
| @@ -1,12 +1,37 @@ | |||
| import React from "react"; | |||
| import { Button, Card, Input, Popconfirm, Select, Space, Tag, Typography } from "antd"; | |||
| import { Button, Card, Checkbox, Input, Popconfirm, Select, Space, Tag, Tooltip, Typography } from "antd"; | |||
| > | ||
| {(() => { | ||
| const TYPE_MAP: Record<string, string> = Object.fromEntries(ECS_PRESETS.map((p) => [p.field, p.type])); | ||
| const GROUP_LABELS: Record<string, string> = { |
| import React, { useCallback, useEffect, useMemo, useState } from "react"; | ||
| import { useRouter } from "next/navigation"; | ||
| import { App, Button, Input, Modal, Space, Tabs } from "antd"; | ||
| import { App, Badge, Button, Card, Checkbox, Collapse, Input, Modal, Space, Statistic, Switch, Table, Tag, Tabs, Tooltip, Typography } from "antd"; |
| parsed = urlparse(host) | ||
| if parsed.hostname and parsed.port == 5601: | ||
| host = f"{parsed.scheme}://{parsed.hostname}:9200" | ||
| except Exception: |
| ) | ||
| if asset and hasattr(asset, 'criticality') and asset.criticality: | ||
| return ASSET_CRITICALITY_WEIGHT.get(asset.criticality.lower(), 1.0) | ||
| except Exception: |
alexchen16
requested changes
Aug 30, 2026
alexchen16
left a comment
Contributor
There was a problem hiding this comment.
Please help to check. Thanks.
| 优先级 | 问题 | 主要影响 | 阻塞合并 |
|---|---|---|---|
| P0 | riskEnabled=false 实际不能关闭规则级 RBA | 关闭后仍可能继续累计风险分 | 是 |
| P0/P1 | Risk score 更新存在并发竞争,幂等机制不足 | 重复加分或 profile 分数丢更新 | 是 |
| P1 | 修改配置 / resolve 只要求view_integration 权限 | 只读用户可修改配置、resolve notable event | 是 |
select_for_update/F()), least-privilege write permissions
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Risk-Based Alerting (RBA) — feature summary
Entity-centric risk scoring for the ECHO SOC platform. Extracts "risk objects" (IP/user/host/etc.) from ingested alerts, accumulates per-entity risk scores, and surfaces them across UI/dashboard/correlation.
Backend (backend/risk/ — new Django app)
multi-value.
Frontend
Objects" column + detail-modal tags (wrap-safe).
Config flow
Global default fields → per-rule override; source-field aliases map non-ECS names to ECS paths.