Tarea 4.1 — OSINT Enrichment:
- Add OsintItem model with source_type, severity, CVSS metadata, review flag
- Add Alembic migration b022 with osint_items table and optimized indexes
- Add osint_enrichment_service with NVD API integration, deduplication, rate limiting
- Add OSINT router: GET /osint/items, /osint/summary, /osint/technique/{id}
- Add POST /osint/items/{id}/review to mark items as reviewed
- Add POST /osint/enrich/{technique_id} for manual single-technique enrichment
- Techniques with new CVEs are automatically flagged review_required=True
- Register weekly enrichment job in APScheduler
- Add NVD_API_KEY config setting for optional increased rate limits
Tarea 4.2 — Stale Coverage Detection:
- Add stale_detection_service that flags techniques with no validated test
in the last N days, or never-validated but with a coverage status
- Configurable threshold via STALE_THRESHOLD_DAYS setting (default 365)
- Register daily stale detection job in APScheduler
- Only flags techniques not already marked review_required
37 lines
1.8 KiB
Python
37 lines
1.8 KiB
Python
# Import all models here so Alembic can detect them
|
|
from app.models.user import User
|
|
from app.models.technique import Technique
|
|
from app.models.test import Test
|
|
from app.models.test_template import TestTemplate
|
|
from app.models.evidence import Evidence
|
|
from app.models.intel import IntelItem
|
|
from app.models.audit import AuditLog
|
|
from app.models.notification import Notification
|
|
from app.models.data_source import DataSource
|
|
from app.models.detection_rule import DetectionRule
|
|
from app.models.threat_actor import ThreatActor, ThreatActorTechnique
|
|
from app.models.defensive_technique import DefensiveTechnique, DefensiveTechniqueMapping
|
|
from app.models.test_template_detection_rule import TestTemplateDetectionRule
|
|
from app.models.test_detection_result import TestDetectionResult
|
|
from app.models.campaign import Campaign, CampaignTest
|
|
from app.models.compliance import ComplianceFramework, ComplianceControl, ComplianceControlMapping
|
|
from app.models.coverage_snapshot import CoverageSnapshot, SnapshotTechniqueState
|
|
from app.models.jira_link import JiraLink, JiraLinkEntityType, JiraSyncDirection
|
|
from app.models.worklog import Worklog
|
|
from app.models.osint_item import OsintItem
|
|
from app.models.enums import TechniqueStatus, TestState, TestResult, TeamSide
|
|
|
|
__all__ = [
|
|
"User", "Technique", "Test", "TestTemplate", "Evidence",
|
|
"IntelItem", "AuditLog", "Notification", "DataSource",
|
|
"DetectionRule", "ThreatActor", "ThreatActorTechnique",
|
|
"DefensiveTechnique", "DefensiveTechniqueMapping",
|
|
"TestTemplateDetectionRule", "TestDetectionResult",
|
|
"Campaign", "CampaignTest",
|
|
"ComplianceFramework", "ComplianceControl", "ComplianceControlMapping",
|
|
"CoverageSnapshot", "SnapshotTechniqueState",
|
|
"JiraLink", "JiraLinkEntityType", "JiraSyncDirection",
|
|
"Worklog", "OsintItem",
|
|
"TechniqueStatus", "TestState", "TestResult", "TeamSide",
|
|
]
|