Milestones
List view
Patch release after 1.9.0 GA
No due date•0/9 issues closedTurn detections into investigation packages with surrounding event context. ## Release outcome #243 coordinates a bounded rolling recorder (#244), stable detector-origin correlation (#245), coalesced package persistence (#246), explicit configuration and retention (#247), and alert-to-package links (#248). Native validation is tracked by #249 and #250. An operator should be able to follow an alert to the configured before/after event window, with missing origins, telemetry loss, interruption, and persistence failure reported honestly. Detection and active response must not wait for package writes. ## Dependencies and implementation boundary Reuse #415/#416 timing and loss, #417/#418 identity, #424 provenance, and #437 scan identity. Do not introduce parallel identity or event models. Preserve the epic's exclusions, including no file/memory evidence acquisition or remote-upload feature. Recording a context window is not a claim to collect a complete forensic image. ## Release proof and platform claims - Trigger detections through Sigma, IOC, file YARA, and memory YARA; follow alert links to valid packages with the configured surrounding window. - Verify overlapping triggers coalesce, origins survive asynchronous completion or are explicitly unavailable, and PID reuse cannot reattribute evidence. - Exercise storage bounds, eviction, interrupted persistence, deliberate event loss, and recording replay. Measure runtime, memory, and storage overhead. - #249 Windows end-to-end and performance validation is mandatory for the initial release. - #250 Linux/macOS validation remains planned. If incomplete, the new flight-recorder capability must be documented as validated on Windows only, with each other platform's status explicit. Do not advertise cross-platform flight-recorder readiness based on compilation alone. Existing agent platform support is a separate claim. If every-platform investigation support is promised, #250 becomes a release gate. Otherwise it may follow after the Windows-first release as the epic permits. No extra collectors or delivery sinks are needed. Provisional sequencing with no calendar commitment.
No due date•2/16 issues closedDetect newly written malicious files, match Linux connections to domain indicators, and explain which rules can work. ## Release outcomes and required scope - #437 -> #324: identity-validated YARA targets enable scanning newly written files, with explicit changed-artifact outcomes and bounded work. - #439 + #436: DNS responses populate Linux hostname context and observable extraction makes it matchable on subsequent connections. Both are required for this outcome. - #436 + #231: match resolved path observables without rewriting the original command line. - #438 + #184 + #190: complete Sigma field views, actionable compatibility diagnostics, and conformance coverage. Diagnostics must respect alternatives/negation and distinguish unavailable from degraded data. ## Dependencies and release boundary Build on #423/#424 from v1.8. #420 must be complete before the dependent field-view and diagnostic work. Finish IOC, YARA, and Sigma migration onto the canonical architecture with preserved output and recording contracts. Secondary, non-gating scope: #442 auditd feasibility measurement, #385 CIDR indexing, #316 Application channel collection, and #323 classic PowerShell collection. Do not delay the three headline outcomes for these additions. Trim #316/#323 first, then #385; defer #442 if needed. #321 stays unscheduled until the spike recommends an implementation; do not promise auditd coverage from a field-view refactor alone. ## Release proof - Write a file matching a controlled YARA rule and receive a correctly attributed alert; replace the artifact during scanning and verify the identity guard's explicit outcome. - Resolve a domain present in the IOC set, then connect to its resolved address and demonstrate a connection-time IOC alert with available process context. The DNS-only alert is not enough. - Demonstrate the relative-path regression pair with byte-preserved command-line output. - Show actionable rule diagnostics for supported, unavailable, and degraded cases, including conditions with alternatives/negation. Publish corpus/conformance and overhead results. Full detector integration completes here. Investigation packages follow in v1.10. Provisional scope, not a dated promise.
No due date•29/29 issues closed