docs(phase-15): complete phase execution
This commit is contained in:
parent
c33b6615c9
commit
664dfcb763
3 changed files with 18 additions and 17 deletions
|
|
@ -9,12 +9,12 @@ destructive remediation gated behind explicit human approval.
|
||||||
|
|
||||||
### Detection
|
### Detection
|
||||||
|
|
||||||
- [ ] **DETECT-01**: System scans recent Autotask/Pulse tickets and flags candidates
|
- [x] **DETECT-01**: System scans recent Autotask/Pulse tickets and flags candidates
|
||||||
matching known phishing/spam-report patterns (title/body: "Phishing Report",
|
matching known phishing/spam-report patterns (title/body: "Phishing Report",
|
||||||
"Spam Alert", "Phishing Alert - Email Security Report", "KnowBe4 Phish Alert
|
"Spam Alert", "Phishing Alert - Email Security Report", "KnowBe4 Phish Alert
|
||||||
Report", "Source: KnowBe4 Phish Alert Button", "userSubmissionsReportMessage",
|
Report", "Source: KnowBe4 Phish Alert Button", "userSubmissionsReportMessage",
|
||||||
"reported message destinations", "Microsoft directly")
|
"reported message destinations", "Microsoft directly")
|
||||||
- [ ] **DETECT-02**: Re-scanning does not reprocess a ticket already ingested unless
|
- [x] **DETECT-02**: Re-scanning does not reprocess a ticket already ingested unless
|
||||||
its source ticket data has changed since last processed (idempotent)
|
its source ticket data has changed since last processed (idempotent)
|
||||||
- [ ] **DETECT-03**: An operator can trigger analysis of one specific ticket by ID
|
- [ ] **DETECT-03**: An operator can trigger analysis of one specific ticket by ID
|
||||||
on demand (`POST /api/phishing/tickets/{ticket_id}/analyze`) instead of waiting
|
on demand (`POST /api/phishing/tickets/{ticket_id}/analyze`) instead of waiting
|
||||||
|
|
@ -22,7 +22,7 @@ destructive remediation gated behind explicit human approval.
|
||||||
|
|
||||||
### Evidence Extraction
|
### Evidence Extraction
|
||||||
|
|
||||||
- [ ] **EVID-01**: For each candidate ticket, the system extracts ticket ID/number,
|
- [x] **EVID-01**: For each candidate ticket, the system extracts ticket ID/number,
|
||||||
company, requester/reporter, title, description, notes, relevant time entries,
|
company, requester/reporter, title, description, notes, relevant time entries,
|
||||||
and attachment metadata
|
and attachment metadata
|
||||||
- [ ] **EVID-02**: When multiple `.eml` attachments exist, the system prefers
|
- [ ] **EVID-02**: When multiple `.eml` attachments exist, the system prefers
|
||||||
|
|
@ -149,10 +149,10 @@ Populated during roadmap creation.
|
||||||
|
|
||||||
| Requirement | Phase | Status |
|
| Requirement | Phase | Status |
|
||||||
|-------------|-------|--------|
|
|-------------|-------|--------|
|
||||||
| DETECT-01 | Phase 15 | Pending |
|
| DETECT-01 | Phase 15 | Complete |
|
||||||
| DETECT-02 | Phase 15 | Pending |
|
| DETECT-02 | Phase 15 | Complete |
|
||||||
| DETECT-03 | Phase 18 | Pending |
|
| DETECT-03 | Phase 18 | Pending |
|
||||||
| EVID-01 | Phase 15 | Pending |
|
| EVID-01 | Phase 15 | Complete |
|
||||||
| EVID-02 | Phase 16 | Pending |
|
| EVID-02 | Phase 16 | Pending |
|
||||||
| EVID-03 | Phase 16 | Pending |
|
| EVID-03 | Phase 16 | Pending |
|
||||||
| EVID-04 | Phase 16 | Pending |
|
| EVID-04 | Phase 16 | Pending |
|
||||||
|
|
|
||||||
|
|
@ -477,7 +477,7 @@ Phases execute in numeric order. v1.0 (Phases 1-9.1) shipped 2026-07-10. v2.0 (P
|
||||||
| 12. Orders/Invoices & Company Matching | v2.0 | 5/5 | Complete | 2026-07-11 |
|
| 12. Orders/Invoices & Company Matching | v2.0 | 5/5 | Complete | 2026-07-11 |
|
||||||
| 13. Scheduler & Admin Toggle | v2.0 | 3/3 | Complete | 2026-07-11 |
|
| 13. Scheduler & Admin Toggle | v2.0 | 3/3 | Complete | 2026-07-11 |
|
||||||
| 14. /pax8 UI Surface | v2.0 | 6/6 | Complete | 2026-07-12 |
|
| 14. /pax8 UI Surface | v2.0 | 6/6 | Complete | 2026-07-12 |
|
||||||
| 15. Data Model, Detection & Ticket Evidence | v3.0 | 3/3 | Complete | 2026-07-15 |
|
| 15. Data Model, Detection & Ticket Evidence | v3.0 | 3/3 | Complete | 2026-07-15 |
|
||||||
| 16. EML/MIME Evidence Parser | v3.0 | 0/TBD | Not started | - |
|
| 16. EML/MIME Evidence Parser | v3.0 | 0/TBD | Not started | - |
|
||||||
| 17. Mimecast Blast Radius Lookup | v3.0 | 0/TBD | Not started | - |
|
| 17. Mimecast Blast Radius Lookup | v3.0 | 0/TBD | Not started | - |
|
||||||
| 18. Campaign Grouping & Phishing Analysis API | v3.0 | 0/TBD | Not started | - |
|
| 18. Campaign Grouping & Phishing Analysis API | v3.0 | 0/TBD | Not started | - |
|
||||||
|
|
|
||||||
|
|
@ -2,15 +2,15 @@
|
||||||
gsd_state_version: 1.0
|
gsd_state_version: 1.0
|
||||||
milestone: v3.0
|
milestone: v3.0
|
||||||
milestone_name: Phishing Triage Automation
|
milestone_name: Phishing Triage Automation
|
||||||
status: executing
|
status: ready_to_plan
|
||||||
stopped_at: Phase 15 context gathered
|
stopped_at: Phase 15 complete (3/3) — ready to discuss Phase 16
|
||||||
last_updated: "2026-07-15T11:33:35.155Z"
|
last_updated: 2026-07-15T12:21:58.275Z
|
||||||
last_activity: 2026-07-15 -- Phase 15 execution started
|
last_activity: 2026-07-15 -- Phase 15 execution started
|
||||||
progress:
|
progress:
|
||||||
total_phases: 7
|
total_phases: 7
|
||||||
completed_phases: 0
|
completed_phases: 0
|
||||||
total_plans: 3
|
total_plans: 3
|
||||||
completed_plans: 0
|
completed_plans: 3
|
||||||
percent: 0
|
percent: 0
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -21,14 +21,14 @@ progress:
|
||||||
See: .planning/PROJECT.md (updated 2026-07-14)
|
See: .planning/PROJECT.md (updated 2026-07-14)
|
||||||
|
|
||||||
**Core value:** A manager/security operator can see every phishing/spam report ticket automatically triaged, deduplicated into campaigns, and classified — with any destructive remediation gated behind explicit human approval.
|
**Core value:** A manager/security operator can see every phishing/spam report ticket automatically triaged, deduplicated into campaigns, and classified — with any destructive remediation gated behind explicit human approval.
|
||||||
**Current focus:** Phase 15 — Data Model, Detection & Ticket Evidence
|
**Current focus:** Phase 16 — eml/mime evidence parser
|
||||||
|
|
||||||
## Current Position
|
## Current Position
|
||||||
|
|
||||||
Phase: 15 (Data Model, Detection & Ticket Evidence) — EXECUTING
|
Phase: 16
|
||||||
Plan: 1 of 3
|
Plan: Not started
|
||||||
Status: Executing Phase 15
|
Status: Ready to plan
|
||||||
Last activity: 2026-07-15 -- Phase 15 execution started
|
Last activity: 2026-07-15
|
||||||
|
|
||||||
Progress: [░░░░░░░░░░] 0%
|
Progress: [░░░░░░░░░░] 0%
|
||||||
|
|
||||||
|
|
@ -36,7 +36,7 @@ Progress: [░░░░░░░░░░] 0%
|
||||||
|
|
||||||
**Velocity:**
|
**Velocity:**
|
||||||
|
|
||||||
- Total plans completed: 50 (v1.0: 42, v2.0: 20 across phases 10-14 — see per-phase table)
|
- Total plans completed: 53 (v1.0: 42, v2.0: 20 across phases 10-14 — see per-phase table)
|
||||||
- Average duration: —
|
- Average duration: —
|
||||||
- Total execution time: 0.0 hours (v3.0)
|
- Total execution time: 0.0 hours (v3.0)
|
||||||
|
|
||||||
|
|
@ -47,6 +47,7 @@ Progress: [░░░░░░░░░░] 0%
|
||||||
| 01-09.1 (v1.0) | 34 | - | - |
|
| 01-09.1 (v1.0) | 34 | - | - |
|
||||||
| 10-14 (v2.0) | 20 | - | - |
|
| 10-14 (v2.0) | 20 | - | - |
|
||||||
| 15-21 (v3.0) | TBD | - | - |
|
| 15-21 (v3.0) | TBD | - | - |
|
||||||
|
| 15 | 3 | - | - |
|
||||||
|
|
||||||
**Recent Trend:**
|
**Recent Trend:**
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue