Skip to content

feat: ✨ Add reproducible investigations and reliable detection replay - #149

Merged
PrzemyslawKlys merged 7 commits into
masterfrom
feature/investigation-reliability
Oct 6, 2026
Merged

PrzemyslawKlys merged 7 commits into
masterfrom
feature/investigation-reliability

Conversation

@PrzemyslawKlys

@PrzemyslawKlys PrzemyslawKlys commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Investigations can retain evidence and replay detection decisions with explicit coverage and clock uncertainty. A start event without its expected completion produces a confirmed absence only when the relevant source and time window are complete; otherwise the result remains uncertain.

Changes

  • Add investigation manifests containing source and artifact hashes, parser and engine identity, query/rule-plan identity, collection receipts, time ranges, and generated outputs. Add PowerShell commands to export, open, and replay sessions.
  • Add coverage-aware absence rules and bounded restart checkpoints with invalidation for changed plans, retention, incompatible state, and late input.
  • Expose watcher queue, execution, acknowledgement, lag, and overload health, and separate stopping collection from draining accepted actions.
  • Compare detection packs against one bounded historical sample, reporting added/removed findings, volume changes, new source requirements, and incomplete coverage.
  • Preserve raw event, received, and processed clocks and display independently supported uncertainty bounds in timeline reports.
  • Fix Sigma string escaping and predicate failures, watcher startup/lifetime issues, EVTX completeness diagnostics, and checkpoint storage behavior. Optimize indexed checkpoint lookup, absence completion matching, and streamed evidence output.

Usage and operational limits are documented in INVESTIGATIONS.md. Replay uses retained canonical observations; callers provide collection receipts and retention generation changes. External alert delivery and checkpoint publication are not an atomic transaction. No new production dependencies are introduced.

Validation

  • All four supported build targets pass with zero warnings/errors.
  • 1,597 tests pass on each of .NET 8 and .NET 10; 32 PowerShell tests pass in each of PowerShell 7 and Windows PowerShell 5.1 using rebuilt source binaries.
  • 62 Linux portability tests pass, including subprocess early-disposal coverage. Independent local review findings are fixed and confirmed; generated reports were inspected at desktop and compact widths.
  • The reproducible 10,000 expired-start/10,000 late-completion benchmark improves from 914.1 ms to 10.2 ms median on the same host with fixed affinity. Benchmark inputs, summaries, and limits are retained under Benchmarks/EventCheckpoints.
  • Local broad runs excluded ExportedArchiveCanReceiveProviderResourcesSeparately because Windows error 267 also reproduced through a separate wevtutil invocation. The complete Windows CI suite subsequently passed, including that test. All 14 checks pass on the final head, including full PowerShell 5.1/7 suites, packed artifacts, Linux portability, and native archives for Windows, Linux, and macOS on x64 and ARM64.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T20:17:53.305771Z 3163991 New commits
🔒 Security Review ✅ Completed 2026-10-05T20:03:50.724651Z abbfd18 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: abbfd181ea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Sources/EventViewerX/Detection/EventDetectionReplaySession.cs
Comment thread Sources/EventViewerX/Detection/EventDetectionImpactPreview.cs Outdated
@PrzemyslawKlys
PrzemyslawKlys merged commit 9330ccf into master Oct 6, 2026
14 checks passed
@PrzemyslawKlys
PrzemyslawKlys deleted the feature/investigation-reliability branch October 6, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant