Milestone 1: design proposal, normalized event model and alert sinks - #1
Merged
Merged
Conversation
Establishes the foundations the rest of Argus is written against. docs/design.md is the contract: the normalized Event schema and its JSON wire form, the field paths rules will address, the collector interface with the privilege each planned collector needs and its degraded fallback, the YAML rule format (operators, boolean composition, correlation), and the seven-milestone plan. Implementation: - Event model with a variant Target, so a file event cannot carry a remote port. Category is derived from the action rather than passed in, so the two can never disagree. Unknown pid/uid stay explicitly unknown instead of defaulting to zero, which would read as root. - Hand-written JSON serialization. The wire format is a published contract, output is deterministic (sorted maps, fixed key order) so runs are diffable, and parsing is defensive: unknown actions and doctored categories are rejected rather than trusted. - JSONL trace loading/saving, the input format for the replay tests that milestone 2 will use to exercise rules without any live host activity. - Alert model carrying rule identity, severity, MITRE ATT&CK mapping and the events that are its evidence. - Sink interface plus console, JSONL (stdout/file) and memory implementations. A SinkGroup fans out and tolerates partial failure: a full disk on the file sink must not cost you the console alert. - CLI with version, demo and check-trace. The demo alert is synthetic — no host activity is observed to produce it. 98 unit tests, and CI runs lint, tests, build and a CLI smoke test. No collectors yet, so Argus observes nothing at this milestone and needs no privilege. The educational, read-only, non-production scope is stated in the README, the design doc, the module docs and the CLI itself.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Milestone 1 — foundations
This PR does two things: it proposes the contract in
docs/design.md, and it implements the first milestone against it.The proposal —
docs/design.mdEventschema and its JSON wire form, plus the dotted field paths rules will address (actor.exe,target.remotePort,raw.*).start/stop/privileges/available, and a table of the privilege each planned collector needs, why it needs it, and the degraded fallback available without it.all/any/notcomposition, and the windowed correlation shape for milestone 6.The implementation
src/argus/types.nim).Targetis a variant, so a file event carrying a remote port is unrepresentable rather than merely unset. The category is derived from the action rather than passed in, so the two cannot disagree. Unknown pid/uid stay explicitly unknown instead of defaulting to0, which would read as root.src/argus/serialization.nim). Hand-written, because the wire format is a contract other tools consume. Output is deterministic — sorted maps, fixed key order — so two runs are byte-identical and diffable. Parsing is defensive: unknown actions are rejected, and a doctoredcategoryis re-derived rather than trusted. Includes JSONL trace load/save, the input format for milestone 2's replay tests.src/argus/alert.nim). Rule identity, severity, ATT&CK mapping with a derived canonical URL, and the events that are its evidence.src/argus/sink.nim,src/argus/sinks/). Console (severity-colored, color auto-disabled when not a terminal), JSONL to stdout or file, and memory for tests.SinkGroupfans out and tolerates partial failure — a full disk on the file sink must not cost you the console alert.argus version,argus demo,argus check-trace FILE.Verification
98 unit tests across four modules, all green;
nimble lintclean; binary builds. CI runs lint, tests, build and a CLI smoke test on every push and PR.tests/data/sample_trace.jsonlis a synthetic ten-event trace — a web server behaving normally, then an nginx worker spawning a shell that writes a cron entry and connects outbound, plus benignaptactivity for rules to not fire on. Nothing in it was collected from a real host.Scope of this milestone
No collectors. Argus observes nothing yet and therefore needs no privilege at all. The pipeline downstream of collection is what is built and tested here.
Next
Milestone 2 — the rule engine: YAML loading, field matching, and trace-replay tests.