11080bd627
Aegis CI / lint-and-test (push) Has been cancelled
Snyk Security Scan / Python vulnerabilities (backend) (push) Has been cancelled
Snyk Security Scan / npm vulnerabilities (frontend) (push) Has been cancelled
Snyk Security Scan / Docker image vulnerabilities (backend) (push) Has been cancelled
Blue's detect_procedure extraction had zero Blue-team-oriented tool names in its known-binaries list — sysmon.exe, one of the most common Windows detection tools, silently produced no suggestion at all. Verified against the exact production input that surfaced this.
110 lines
3.9 KiB
Python
110 lines
3.9 KiB
Python
"""Tests for the regex-based command/query extraction heuristic used to
|
|
build procedure-improvement suggestions from free-text procedure fields."""
|
|
|
|
import pytest
|
|
|
|
from app.services.procedure_extraction_service import extract_commands
|
|
|
|
|
|
@pytest.mark.parametrize("value", [None, "", " ", "\n\n"])
|
|
def test_returns_none_for_empty_input(value):
|
|
assert extract_commands(value) is None
|
|
|
|
|
|
def test_returns_none_for_pure_narrative():
|
|
text = (
|
|
"I logged into the domain controller and tried a well-known credential "
|
|
"dumping tool. It worked well and I documented everything in the summary."
|
|
)
|
|
assert extract_commands(text) is None
|
|
|
|
|
|
def test_fenced_code_block_takes_priority_over_surrounding_narrative():
|
|
text = (
|
|
"Ran the following from an elevated prompt:\n"
|
|
"```\n"
|
|
"Invoke-Mimikatz -DumpCreds\n"
|
|
"```\n"
|
|
"It successfully extracted plaintext passwords from LSASS memory."
|
|
)
|
|
assert extract_commands(text) == "Invoke-Mimikatz -DumpCreds"
|
|
|
|
|
|
def test_tilde_fence_supported():
|
|
text = "~~~\nGet-Process lsass\n~~~"
|
|
assert extract_commands(text) == "Get-Process lsass"
|
|
|
|
|
|
def test_multiple_fenced_blocks_are_joined():
|
|
text = "```\nwhoami /priv\n```\nthen\n```\nGet-Process lsass\n```"
|
|
assert extract_commands(text) == "whoami /priv\n\nGet-Process lsass"
|
|
|
|
|
|
def test_extracts_command_lines_from_mixed_narrative_no_fence():
|
|
text = (
|
|
"First I checked what privileges I had.\n"
|
|
"whoami /priv\n"
|
|
"Then I dumped credentials from LSASS.\n"
|
|
"Invoke-Mimikatz -DumpCreds\n"
|
|
"This successfully retrieved plaintext passwords, as shown below.\n"
|
|
"Handles NPM(K) PM(K) WS(K) CPU(s) Id SI ProcessName\n"
|
|
" 542 27 23012 41564 0.45 1234 1 explorer\n"
|
|
)
|
|
result = extract_commands(text)
|
|
assert result == "whoami /priv\nInvoke-Mimikatz -DumpCreds"
|
|
|
|
|
|
def test_strips_shell_prompt_markers():
|
|
text = (
|
|
"Ran this against the target host:\n"
|
|
"$ curl -X POST http://target/api/exfil -d @creds.txt\n"
|
|
"Got a 200 OK back.\n"
|
|
)
|
|
assert extract_commands(text) == "curl -X POST http://target/api/exfil -d @creds.txt"
|
|
|
|
|
|
def test_strips_powershell_prompt_marker():
|
|
text = "PS C:\\Users\\op> Get-Process lsass"
|
|
assert extract_commands(text) == "Get-Process lsass"
|
|
|
|
|
|
def test_extracts_kql_detection_query_mixed_with_narrative():
|
|
text = (
|
|
"I built a Sentinel query to catch this technique going forward.\n"
|
|
"DeviceProcessEvents\n"
|
|
"| where FileName == \"mimikatz.exe\"\n"
|
|
"That caught it within a minute of execution in testing.\n"
|
|
)
|
|
result = extract_commands(text)
|
|
assert 'where FileName == "mimikatz.exe"' in result
|
|
assert "That caught it" not in result
|
|
|
|
|
|
def test_extracts_splunk_query():
|
|
text = (
|
|
"Search used for detection:\n"
|
|
"index=main sourcetype=WinEventLog:Security EventCode=4688\n"
|
|
"This surfaced the process creation event immediately.\n"
|
|
)
|
|
result = extract_commands(text)
|
|
assert "index=main sourcetype=WinEventLog:Security EventCode=4688" in result
|
|
assert "immediately" not in result
|
|
|
|
|
|
def test_known_binary_at_start_of_line_is_recognized():
|
|
text = "Notes: used the following.\nsudo tcpdump -i eth0 -w capture.pcap\nCaptured 500 packets."
|
|
result = extract_commands(text)
|
|
assert result == "sudo tcpdump -i eth0 -w capture.pcap"
|
|
|
|
|
|
def test_recognizes_sysmon_as_a_detection_command():
|
|
text = "launch sysmon to detect\nsysmon.exe\nthen search this query\n\\? mimikatz \\n"
|
|
result = extract_commands(text)
|
|
assert result == "sysmon.exe"
|
|
|
|
|
|
def test_recognizes_wevtutil_and_auditpol():
|
|
text = "Pulled the security log.\nwevtutil qe Security /c:5\nThen checked audit policy.\nauditpol /get /category:*"
|
|
result = extract_commands(text)
|
|
assert result == "wevtutil qe Security /c:5\nauditpol /get /category:*"
|