Skip to content

fix(techvault): materialize detection content and SOC ports - #275

Merged
Brad-Edwards merged 2 commits into
devfrom
fix/techvault-workshop-happy-path
Aug 4, 2026
Merged

fix(techvault): materialize detection content and SOC ports#275
Brad-Edwards merged 2 commits into
devfrom
fix/techvault-workshop-happy-path

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Collaborator

Summary

  • package the Wazuh rule and decoder corpora that TechVault declares as loaded
  • materialize those assets at the manager paths referenced by its generated configuration
  • preserve the executable Wazuh-to-Shuffle integration as a pack directory artifact
  • restore loopback-only host publications for MISP, TheHive, Cortex, and Shuffle
  • align the lockfile with the existing 3.9.0 package version
  • add regression tests for loaded content placements, executable integration content, and SOC port exposure

Problem

A clean env-pack realization started the full TechVault topology, but the Wazuh manager could not find any declared custom rule files and participant-facing SOC services had no host bindings. The web attack reached TechVault but produced zero custom alerts, and TheHive was reachable only through a changing Docker bridge address.

Validation

  • full unittest suite: 814 tests passed
  • repository and pack content validation passed
  • all release gates passed
  • source and test compile checks passed
  • uv lock consistency check passed

@Brad-Edwards
Brad-Edwards merged commit 9e9509e into dev Aug 4, 2026
12 checks passed
@Brad-Edwards
Brad-Edwards deleted the fix/techvault-workshop-happy-path branch August 4, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant