Skip to content

fix(sophos): correct XG and Central normalization and rule populations - #2638

Draft
rvald26 wants to merge 1 commit into
utmstack:v11from
rvald26:codex/v11-sophos-public-review-20260917
Draft

rvald26 wants to merge 1 commit into
utmstack:v11from
rvald26:codex/v11-sophos-public-review-20260917

Conversation

@rvald26

@rvald26 rvald26 commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

New Sophos replacement draft following the review of #2617. Includes XG Firewall and Central filters, their correlation rules, fabricated regression fixtures, and a source audit. The historical PR is unchanged.

XG fixes independent field extraction when subtype is absent, endpoint and numeric validation, rejection precedence, authentication/IDP/IP-spoofing matching, and history queries that previously counted unrelated traffic.

Central no longer treats successful malware cleanup as a fresh detection or a blocked peripheral as a compromised device. It adds guarded standard endpoint, severity, timestamp, hash and single-file remediation fields, while preserving vendor fields. Behavioral/PUA/tamper events reach the appropriate rules, and a new device-health rule covers unavailable endpoint protection. Endpoint context is distinguished from attacker identity. Histories require relevant events in the same account and endpoint scope.

Existing impact ratings and history thresholds are preserved. The rapid ZTNA failure rule no longer claims distinct-user password spraying. Unsupported exploitation/technique claims are removed from generic notifications. XG identifier 17913 alone no longer establishes an administrator authentication failure; 17925 remains a literal notification with its meaning unverified.

Validation uses SDK v1.1.31 and its official filter/rule/schema wiki: 159 fabricated raw fixtures, positive/negative checks for all 29 rule predicates, strict Event decoding, Alert-side checks, and nine SDK history-query tests against local mocks. Combined replacement-branch validation passes with no failures or file conflicts.

The extraction harness is an offline model, not the closed EventProcessor. Geolocation and production alert creation are not exercised. Shared grouping support is proposed separately in #2627. Review candidate-history warm-up, renamed-rule reconciliation, outcome/severity consumers, and the audit's unverified legacy variants before any rollout.

Draft for review only, targeting UTMStack v11. No merge, auto-merge or deployment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant