Files
reverse-skill/skills/ops/evidence-finding-path.md
T
yhc ec61a6f951 feat(ops): analysis decision framework R1-R51 (#77)
Add analysis-decision-framework cookbook (P0 full / P1 short / P2 index).
R4* validated sufficiency (compatible >=1 bind). Thin hooks in evidence-
finding-path, re-agent-workflow Synthesis, RULES(+zh), verify anchors.
Not a second master workflow; keep #65 gates and A-T/U-AV superior.
2026-08-14 20:26:03 +08:00

132 lines
4.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Evidence → Finding → Path 证据链
> 灵感来自 Z3r0 Evidence Plane,落地为 **Markdown 字段契约**。
> reverse-skill 特色:与 `docs-generator` 报告模板、`field-journal` 脱敏回写、可复现命令绑定。
## 1. Evidence(不可变观察)
每条证据独立一段或表行:
```markdown
### E-{nnn}
- title:
- observed_at:
- source_type: command | screenshot | file | log | memory | network | manual
- source_ref: {path or command id}
- content_hash: {sha256 of artifact if file, else n/a}
- artifact_path: {relative path under case root when content_hash is recorded, else n/a}
- repro_command: |
{exact command}
- raw_excerpt: |
{脱敏摘录}
- linked_workitem: WI-{nnn} | n/a
- supersedes: E-{nnn} | none
```
**MUST**:Finding 引用的 Evidence 至少 1 条;`repro_command` 第三方可跑或标明离线限制。
**CLI helper**(写入 `work/<case>/evidence/E-*.md`):
```powershell
powershell -File skills/scripts/append-evidence.ps1 -CaseRoot work/<case> `
-Id E-001 -Title "..." -ReproCommand "..." -Severity info -Status observed
```
When the evidence is a case-local file, pass `-ArtifactPath` to record a SHA-256 fixity value and a relative artifact path. Review the complete case graph before handoff:
```bash
python3 skills/case-review/scripts/review_case.py work/<case> --verify-hashes --strict
```
The review is read-only and checks scope fields, Evidence records, work item and timeline references, structured Findings, Paths, and artifact hash matches.
## 2. Finding(安全/逆向结论)
```markdown
### F-{nnn}
- title:
- severity: critical | high | medium | low | info | n/a_re
- category: vuln | misconfig | design | reverse_algo | bypass | other
- status: candidate | validated | false_positive | accepted_risk
- evidence_ids: [E-001, E-002]
- location: {file:line | addr | url | class.method}
- impact:
- confidence: high | medium | low
- repro_steps:
1.
2.
- remediation: {or n/a for pure RE}
- optional_attack: {ATT&CK ID or empty}
```
**MUST**:`evidence_ids` 非空;`status=validated` 时 confidence 不得为 low(除非标注 residual risk)。
## 3. Path(攻击路径 / 调用路径 / 解题路径)
统一叫 **Path**,按任务类型解释:
| 任务 | Path 含义 |
|------|-----------|
| 渗透 / 攻击链 | 攻击路径步骤 |
| 逆向 | 关键调用/数据流步骤 |
| CTF | 解题步骤 |
```markdown
### P-{nnn}
- title:
- path_type: attack | callflow | solve
- start:
- goal:
- steps:
1. action: — evidence: E-xxx — finding: F-xxx | none
2. action: — evidence: E-xxx — finding: F-yyy | none
- residual_risks:
```
**MUST**:每步可关联 Evidence;攻击路径终点 Finding 若声明「已拿权限/数据」必须有 validated 证据。
## 4. 报告中的位置
`docs-generator` 安全报告 **MUST** 含:
1. Scope 摘要(链到 case `scope.md`)
2. Evidence 表或章节
3. Findings 列表(含 evidence_ids)
4. 至少 1 条 Path(攻击/调用/解题)
5. Timeline 摘要(可选全文链到 `timeline.md`)
详见 `docs-generator/references/security-report-templates.md` 中 **Evidence Chain** 节。
## 5. field-journal 挂钩
回写 journal 时 **SHOULD** 摘录:
- 3 条内关键 Evidence id + 命令
- 1 条核心 Finding
- 可复用 Path 模式一句话
完整敏感内容只在用户项目报告中;journal **MUST** 脱敏(`anonymization.md`)。
## 6. 与 Z3r0 的差异(特色)
| Z3r0 | reverse-skill |
|------|----------------|
| PG 不可变行 + API | Markdown 文件 + hash 字段 |
| UI 审阅队列 | 报告 + next-step 菜单 + journal |
| ATT&CK 深度绑定 | 可选标签,不强制 UI |
## Validated sufficiency (Issue #77 / R4*)
Global bind rule remains: every Finding references **>=1** Evidence.
Promotion to status=validated is stricter (decision cookbook):
| status | Evidence bar |
|--------|----------------|
| preliminary / candidate | >=1 (unchanged) |
| **validated** | **SHOULD >=2 independent** Evidence (best: 1 static + 1 dynamic). A single Evidence item alone MUST NOT silently promote to validated — keep candidate/preliminary, or record residual_risk + human confirm. |
| blocked promotion | record Evidence E-insufficient-evidence |
Full recipes: [nalysis-decision-framework.md](analysis-decision-framework.md) (R4*, R1, R41, R44).