Files
Aegis/backend/tests/test_procedure_extraction_service.py
kitos 11080bd627
Aegis CI / lint-and-test (push) Has been cancelled
Snyk Security Scan / Python vulnerabilities (backend) (push) Has been cancelled
Snyk Security Scan / npm vulnerabilities (frontend) (push) Has been cancelled
Snyk Security Scan / Docker image vulnerabilities (backend) (push) Has been cancelled
fix(tests): recognize sysmon, wevtutil, auditpol as detection commands
Blue's detect_procedure extraction had zero Blue-team-oriented tool
names in its known-binaries list — sysmon.exe, one of the most common
Windows detection tools, silently produced no suggestion at all.
Verified against the exact production input that surfaced this.
2026-07-14 17:24:14 +02:00

110 lines
3.9 KiB
Python

"""Tests for the regex-based command/query extraction heuristic used to
build procedure-improvement suggestions from free-text procedure fields."""
import pytest
from app.services.procedure_extraction_service import extract_commands
@pytest.mark.parametrize("value", [None, "", " ", "\n\n"])
def test_returns_none_for_empty_input(value):
assert extract_commands(value) is None
def test_returns_none_for_pure_narrative():
text = (
"I logged into the domain controller and tried a well-known credential "
"dumping tool. It worked well and I documented everything in the summary."
)
assert extract_commands(text) is None
def test_fenced_code_block_takes_priority_over_surrounding_narrative():
text = (
"Ran the following from an elevated prompt:\n"
"```\n"
"Invoke-Mimikatz -DumpCreds\n"
"```\n"
"It successfully extracted plaintext passwords from LSASS memory."
)
assert extract_commands(text) == "Invoke-Mimikatz -DumpCreds"
def test_tilde_fence_supported():
text = "~~~\nGet-Process lsass\n~~~"
assert extract_commands(text) == "Get-Process lsass"
def test_multiple_fenced_blocks_are_joined():
text = "```\nwhoami /priv\n```\nthen\n```\nGet-Process lsass\n```"
assert extract_commands(text) == "whoami /priv\n\nGet-Process lsass"
def test_extracts_command_lines_from_mixed_narrative_no_fence():
text = (
"First I checked what privileges I had.\n"
"whoami /priv\n"
"Then I dumped credentials from LSASS.\n"
"Invoke-Mimikatz -DumpCreds\n"
"This successfully retrieved plaintext passwords, as shown below.\n"
"Handles NPM(K) PM(K) WS(K) CPU(s) Id SI ProcessName\n"
" 542 27 23012 41564 0.45 1234 1 explorer\n"
)
result = extract_commands(text)
assert result == "whoami /priv\nInvoke-Mimikatz -DumpCreds"
def test_strips_shell_prompt_markers():
text = (
"Ran this against the target host:\n"
"$ curl -X POST http://target/api/exfil -d @creds.txt\n"
"Got a 200 OK back.\n"
)
assert extract_commands(text) == "curl -X POST http://target/api/exfil -d @creds.txt"
def test_strips_powershell_prompt_marker():
text = "PS C:\\Users\\op> Get-Process lsass"
assert extract_commands(text) == "Get-Process lsass"
def test_extracts_kql_detection_query_mixed_with_narrative():
text = (
"I built a Sentinel query to catch this technique going forward.\n"
"DeviceProcessEvents\n"
"| where FileName == \"mimikatz.exe\"\n"
"That caught it within a minute of execution in testing.\n"
)
result = extract_commands(text)
assert 'where FileName == "mimikatz.exe"' in result
assert "That caught it" not in result
def test_extracts_splunk_query():
text = (
"Search used for detection:\n"
"index=main sourcetype=WinEventLog:Security EventCode=4688\n"
"This surfaced the process creation event immediately.\n"
)
result = extract_commands(text)
assert "index=main sourcetype=WinEventLog:Security EventCode=4688" in result
assert "immediately" not in result
def test_known_binary_at_start_of_line_is_recognized():
text = "Notes: used the following.\nsudo tcpdump -i eth0 -w capture.pcap\nCaptured 500 packets."
result = extract_commands(text)
assert result == "sudo tcpdump -i eth0 -w capture.pcap"
def test_recognizes_sysmon_as_a_detection_command():
text = "launch sysmon to detect\nsysmon.exe\nthen search this query\n\\? mimikatz \\n"
result = extract_commands(text)
assert result == "sysmon.exe"
def test_recognizes_wevtutil_and_auditpol():
text = "Pulled the security log.\nwevtutil qe Security /c:5\nThen checked audit policy.\nauditpol /get /category:*"
result = extract_commands(text)
assert result == "wevtutil qe Security /c:5\nauditpol /get /category:*"