296 items across 7 document types — generated 2026-03-15
| UID | Title | Type | Rationale | Importance | Urgency | Vm | Release | Active | Parent links |
|---|---|---|---|---|---|---|---|---|---|
MRS-004 | Multivariate Anomaly Detection | A | — | 5 | 4 | R | Alpha | active | — |
MRS-042 | SONAR Production Anomaly Detection System | A | — | 5 | 5 | R | Alpha | active | — |
MRS-028 | Standardized AD Input | C | — | 2 | 1 | I | Alpha | active | — |
MRS-030 | Deep Learning Technique | F | — | 4 | 4 | A | Alpha | active | — |
MRS-031 | Multiple ML Techniques | F | — | 1 | 1 | R | Alpha | active | — |
MRS-032 | Host and Network Ingestion | F | — | 5 | 4 | T | Alpha | active | — |
MRS-033 | API Data Retrieval | F | — | 4 | 5 | T | Alpha | active | — |
MRS-034 | Standardized AD Output | C | — | 3 | 3 | T | Alpha | active | — |
MRS-039 | Offline AD | F | — | 2 | 2 | T | Alpha | active | — |
MRS-041 | Standalone AD Subsystem | A | — | 3 | 3 | T | Alpha | active | — |
MRS-002 | Command & Control | A | — | — | 5 | R | Alpha | active | — |
MRS-007 | Intrusion Prevention | A | — | 5 | 5 | R | Alpha | active | — |
MRS-023 | MITRE ATT&CK Mapping | F | — | 3 | 3 | T | Alpha | active | — |
MRS-024 | TIP API Integration | I | — | 3 | 3 | T | Alpha | active | — |
MRS-025 | Threat Detection API | I | — | 4 | 4 | T | Alpha | active | — |
MRS-001 | Open-Source Release | B | — | 5 | 1 | I | Alpha | active | — |
MRS-013 | Visual Dashboard | A | — | 4 | 4 | R | Alpha | active | — |
MRS-014 | Data Extraction API | I | — | 4 | 4 | R | Alpha | active | — |
MRS-015 | Software Configuration Management | F | — | 4 | 3 | T | Alpha | active | — |
MRS-016 | Agent (De)Registration | F | — | 4 | 3 | T | Alpha | active | — |
MRS-017 | Monitoring Frontend | A | — | 3 | 2 | R | Alpha | active | — |
MRS-018 | Data Management Subsystem | A | — | 4 | 3 | R | Alpha | active | — |
MRS-019 | 3rd-Party Open-source Signature-based NIDS | A | — | 2 | 1 | R | Alpha | active | — |
MRS-020 | Platform Independence | A | — | 3 | 1 | R | Alpha | active | — |
MRS-021 | IaC Deployment | F | — | 4 | 2 | T | Alpha | active | — |
MRS-022 | Network Endpoint Monitoring | A | — | 4 | 3 | R | Alpha | active | — |
MRS-003 | Agent Data Centralization | A | — | 5 | 5 | R | Alpha | active | — |
MRS-026 | C5-DEC Development Model | C | — | 5 | 5 | R | Alpha | active | — |
MRS-027 | Secure Inter-Component Communication | S | — | 5 | 3 | A | Alpha | active | — |
MRS-029 | Data Collection Scalability | O | — | 3 | 2 | T | Alpha | active | — |
MRS-035 | Secure Log Storage | S | — | 4 | 3 | A | Alpha | active | — |
MRS-036 | Secure pcap Storage | S | — | 4 | 3 | A | Alpha | active | — |
MRS-037 | Multiple Deployment Models | O | — | 3 | 3 | R | Alpha | active | — |
MRS-038 | pcap Support | C | — | 2 | 2 | T | Alpha | active | — |
MRS-040 | Signature-Based NIDS | F | — | 5 | 5 | T | Alpha | active | — |
MRS-005 | Host-based Intrusion Detection | A | — | 5 | 5 | R | Alpha | active | — |
MRS-006 | NIDS Support | A | — | 5 | 5 | R | Alpha | active | — |
MRS-008 | Network Capture Forwarding | F | — | 3 | 4 | T | Alpha | active | — |
MRS-009 | Docker Deployment Option | O | — | 4 | 3 | R | Alpha | active | — |
MRS-010 | [DEPRECATED] Reserved Requirement ID | F | — | 0 | 0 | R | Alpha | inactive | — |
MRS-011 | Signature-based Host IDS | F | — | 5 | 5 | T | Alpha | active | — |
MRS-012 | XDR & SIEM Integration | A | — | 5 | 4 | R | Alpha | active | — |
MRS-SONAR | SONAR Mission Requirements | B | — | 5 | 5 | I | Alpha | active | — |
MRS-RADAR | RADAR Mission Requirements | B | — | 5 | 5 | I | Alpha | active | — |
MRS-ADBox | ADBox v1 Mission Requirements (Maintenance) | B | — | 5 | 5 | I | Alpha | active | — |
MRS-Infrastructure | Infrastructure & Integration Requirements | B | — | 5 | 5 | I | Alpha | active | — |
| UID | Title | Active | Parent links |
|---|---|---|---|
HARC-009 | SONAR subsystem context | active | MRS-032 MRS-039 |
HARC-010 | SONAR component architecture | active | MRS-032 MRS-039 |
HARC-011 | SONAR data flow architecture | active | MRS-032 MRS-039 |
HARC-004 | RADAR architecture | active | MRS-007 MRS-012 |
HARC-005 | RADAR Automated Test Framework architecture | active | MRS-007 |
HARC-006 | RADAR deployment: Remote Agent and Remote Manager mode | active | MRS-007 |
HARC-007 | RADAR deployment: Remote Agent and Local Manager mode | active | MRS-007 |
HARC-008 | RADAR deployment: Local Agent and Local Manager mode | active | MRS-007 |
HARC-012 | RADAR risk engine architecture | active | MRS-007 |
HARC-013 | RADAR Ansible automation architecture | active | MRS-007 MRS-012 |
HARC-014 | RADAR helper architecture | active | MRS-007 |
HARC-015 | RADAR adversarial ML defense architecture | active | MRS-007 MRS-019 |
HARC-001 | ADBox subsystem | active | MRS-002 MRS-004 MRS-032 MRS-033 MRS-039 MRS-041 |
HARC-002 | ADBox architecture | active | MRS-004 MRS-031 MRS-032 MRS-033 MRS-039 MRS-041 |
HARC-003 | IDPS-ESCAPE context | active | MRS-002 MRS-003 MRS-004 MRS-005 MRS-006 MRS-007 MRS-008 MRS-011 MRS-012 MRS-013 MRS-017 MRS-018 MRS-019 MRS-020 MRS-022 MRS-032 MRS-033 MRS-037 MRS-039 MRS-040 MRS-041 |
HARC-SONAR | SONAR High-Level Architecture | active | — |
HARC-RADAR | RADAR High-Level Architecture | active | — |
HARC-ADBox | ADBox v1 High-Level Architecture (Maintenance) | active | — |
HARC-Infrastructure | Infrastructure High-Level Architecture | active | — |
| UID | Title | Status | Importance | Urgency | Risk | Type | Version | Active | Parent links |
|---|---|---|---|---|---|---|---|---|---|
SRS-018 | ML Hyperparameter Tuning | — | 3 | 2 | 2 | F | 0.1 | active | MRS-015 |
SRS-038 | Joint Host-Network Training | — | 5 | 4 | 2 | F | 0.1 | active | MRS-030 |
SRS-039 | Algorithm Selection Option | unavaliable | 3 | 2 | 2 | F | 0.1 | active | MRS-031 |
SRS-040 | Data Management Subpackage | — | 3 | 3 | 3 | A | 0.1 | active | MRS-004 |
SRS-041 | Time Management Package | — | 3 | 2 | 2 | A | 0.1 | active | MRS-004 |
SRS-042 | Prediction Shipping Feature | — | 2 | 2 | 2 | F | 0.1 | active | MRS-018 |
SRS-043 | AD Data Visualization | — | 2 | 2 | 2 | F | 0.1 | active | MRS-017 |
SRS-046 | Cross-platform SONAR deployment | — | 5 | 5 | 2 | F | 0.1 | active | MRS-020 |
SRS-047 | Interactive Use Case Builder | — | — | 2 | — | F | 0.1 | active | MRS-030 |
SRS-048 | Default Detector Training | — | 2 | 2 | 1 | F | 0.1 | active | MRS-030 |
SRS-049 | Anomaly Shipping to Indexer | — | 3 | 3 | 2 | F | 0.1 | active | MRS-021 |
SRS-027 | ML-Based Anomaly Detection | — | 5 | 4 | 2 | F | 0.1 | active | MRS-030 |
SRS-028 | Algorithm Comparison Feature | — | 2 | 1 | 1 | F | 0.1 | active | MRS-031 |
SRS-029 | Host & Network Ingestion | — | 4 | 4 | 1 | F | 0.2 | active | MRS-032 |
SRS-030 | AD Results Visualization | — | 2 | 2 | 2 | F | 0.1 | active | MRS-034 |
SRS-031 | Training Loss Visualization | — | 1 | 1 | — | F | 0.1 | active | MRS-034 |
SRS-032 | Predicted Anomalies Visualization | — | 4 | 3 | 1 | F | 0.1 | active | MRS-034 |
SRS-035 | Offline Anomaly Detection | — | 4 | 4 | 2 | F | 0.1 | active | MRS-039 |
SRS-037 | Anomaly-Based NIDS | To detect deviations from an a priori normal baseline system behavior, possibly caused by malicious actors. | 4 | 3 | 1 | F | 0.1 | active | MRS-004 |
SRS-057 | RADAR scenario: ransomware | — | 5 | 4 | 3 | F | 1.0 | active | MRS-007 |
SRS-058 | RADAR scenario: DLP2 - network data exfiltration | — | 5 | 4 | 3 | F | 0.8 | active | MRS-007 |
SRS-059 | RADAR Scenario Simulation Framework | — | 4 | 2 | 2 | F | 0.8 | active | MRS-007 SWD-039 |
SRS-060 | RADAR Deployment Health Check | — | 4 | 2 | 2 | F | 0.8 | active | SWD-040 |
SRS-061 | RADAR: Tiered active response logic | — | 5 | 4 | 3 | F | 0.8 | active | MRS-007 |
SRS-050 | RADAR scenario: DLP1 - insider data exfiltration | — | 5 | 3 | 2 | F | 0.8 | active | MRS-007 |
SRS-051 | RADAR scenario: suspicious login | — | 4 | 3 | 2 | F | 0.5 | active | MRS-007 |
SRS-052 | RADAR scenario: DDoS detection | — | 2 | 1 | 2 | F | 0.5 | active | MRS-007 |
SRS-053 | RADAR scenario: malware C2 beaconing | — | 4 | 2 | 2 | F | 0.5 | active | MRS-007 |
SRS-054 | RADAR automated test framework | — | 4 | 3 | 2 | F | 0.5 | active | MRS-007 |
SRS-055 | RADAR scenario: Geo-IP AC via whitelisting | — | 5 | 4 | 2 | F | 0.5 | active | MRS-007 |
SRS-056 | RADAR scenario: log size change | — | 5 | 4 | 2 | F | 0.5 | active | MRS-007 |
SRS-001 | Centralized C&C Deployment | — | 5 | 5 | 1 | F | 0.1 | active | MRS-002 |
SRS-010 | Centralized Threat Management | — | 5 | 4 | 1 | F | 0.1 | active | MRS-012 |
SRS-011 | Network Event Visualization | — | 3 | 3 | 1 | F | 0.1 | active | MRS-013 |
SRS-012 | Host Event Visualization | — | 3 | 3 | 1 | F | 0.1 | active | MRS-013 |
SRS-013 | HIDS Agent Status Panel | — | 3 | 2 | 1 | F | 0.1 | active | MRS-013 |
SRS-014 | Event Decoding & Transformation | — | 3 | 1 | 1 | F | 0.1 | active | MRS-014 |
SRS-015 | Custom Rule Support | — | 2 | 1 | 3 | F | 0.1 | active | MRS-014 |
SRS-016 | Indexer Credential Management | — | 3 | 1 | 2 | F/S | 0.1 | active | MRS-015 |
SRS-017 | Custom Data Source | — | 5 | 4 | 4 | F | 0.1 | active | MRS-015 |
SRS-019 | Datatype Transformation Map | — | — | 1 | — | F | 0.1 | active | MRS-015 |
SRS-020 | Ingestion Field Update | — | — | 1 | — | F | 0.1 | active | MRS-015 |
SRS-002 | Endpoint Status Monitoring | — | 5 | 5 | 2 | F | 0.1 | active | MRS-002 |
SRS-021 | Default Use Case Update | — | 3 | 3 | 1 | F | 0.1 | active | MRS-015 |
SRS-022 | Indexer Credentials Update | — | 3 | 3 | 2 | F | 0.1 | active | MRS-015 |
SRS-023 | Agent Registration Process | — | 3 | 3 | 1 | F | 0.1 | active | MRS-016 |
SRS-024 | Event Querying Capability | — | 2 | 4 | 1 | F | 0.1 | active | MRS-018 |
SRS-033 | Remote Endpoint Deployment | — | 5 | 4 | 3 | F | 0.1 | active | MRS-037 |
SRS-034 | [DEPRECATED] Reserved Requirement ID | deprecated | 0 | 0 | 0 | F | 0.0 | inactive | — |
SRS-036 | Custom NIDS Rules | — | 3 | 1 | 3 | F | 0.1 | active | MRS-040 |
SRS-044 | Platform-Independent Deployment | — | 4 | 4 | 2 | F/A | 0.1 | active | MRS-020 |
SRS-045 | High-Level Architecture Overview | — | — | 3 | 1 | S | 0.1 | active | MRS-026 |
SRS-026 | TIP Data Export | — | — | 1 | — | F | 0.1 | active | MRS-025 |
SRS-003 | HIDS Agent Deployment | — | 5 | 5 | 1 | F | 0.1 | active | MRS-005 |
SRS-025 | MITRE ATT&CK Mapping | — | 2 | 2 | 1 | F | 0.1 | active | MRS-023 |
SRS-004 | HIDS Agent Management | — | 5 | 5 | 2 | F | 0.1 | active | MRS-005 |
SRS-005 | Network Monitoring Control | — | 5 | 4 | 2 | F | 0.1 | active | MRS-006 |
SRS-006 | Centralized NIDPS Prevention | — | 2 | 1 | 4 | F | 0.1 | active | MRS-007 |
SRS-007 | Raw Traffic Capture | — | 5 | 5 | 2 | F | 0.1 | active | MRS-008 |
SRS-008 | Dockerized NIDS Deployment | — | 3 | 2 | 2 | F | 0.1 | active | MRS-009 |
SRS-009 | Signature-Based HIDS | — | 5 | 5 | 1 | F | 0.1 | active | MRS-011 |
SRS-SONAR | SONAR System Requirements | — | 5 | 5 | — | B | — | active | — |
SRS-RADAR | RADAR System Requirements | — | 5 | 5 | — | B | — | active | — |
SRS-ADBox | ADBox v1 System Requirements (Maintenance) | — | 5 | 5 | — | B | — | active | — |
SRS-Infrastructure | Infrastructure & Integration System Requirements | — | 5 | 5 | — | B | — | active | — |
| UID | Title | Version | Release | Active | Parent links |
|---|---|---|---|---|---|
LARC-019 | SONAR training pipeline sequence | 0.1 | Alpha | active | SRS-038 SRS-048 |
LARC-020 | SONAR detection pipeline sequence | 0.1 | Alpha | active | SRS-027 SRS-035 SRS-042 |
LARC-015 | RADAR scenario setup flow | 0.4 | Alpha | active | HARC-004 HARC-005 SRS-050 SRS-051 SRS-052 SRS-053 |
LARC-026 | RADAR active response decision pipeline | 0.1 | Alpha | active | HARC-004 HARC-012 HARC-013 LARC-021 SRS-050 SRS-051 SRS-052 SRS-053 SRS-054 SRS-055 SRS-056 SRS-057 SRS-058 |
LARC-027 | RADAR data ingestion pipeline | 0.1 | Alpha | active | HARC-004 HARC-014 LARC-015 SRS-050 SRS-051 SRS-052 SRS-056 |
LARC-028 | RADAR GeoIP detection scenario flow | 0.1 | Alpha | active | HARC-004 HARC-014 LARC-025 LARC-026 SRS-053 SRS-055 |
LARC-029 | RADAR log volume detection scenario flow | 0.1 | Alpha | active | HARC-004 LARC-022 LARC-023 LARC-026 SRS-054 SRS-056 |
LARC-031 | RADAR adversarial defense implementation flow | 0.1 | Alpha | active | HARC-015 LARC-022 |
LARC-016 | RADAR active response flow | 0.4 | Alpha | active | HARC-004 HARC-005 SRS-050 SRS-051 SRS-052 SRS-053 |
LARC-017 | RADAR integration with Opensearch modules | 0.4 | Alpha | active | HARC-004 HARC-005 SRS-050 SRS-051 SRS-052 SRS-053 SRS-054 |
LARC-018 | RADAR logical flow | 0.4 | Alpha | active | HARC-004 SRS-050 SRS-051 SRS-052 SRS-053 |
LARC-021 | RADAR risk engine calculation flow | 0.1 | Alpha | active | HARC-012 SRS-050 SRS-051 SRS-052 SRS-053 SRS-054 SRS-055 SRS-056 SRS-057 SRS-058 |
LARC-022 | RADAR detector creation workflow | 0.1 | Alpha | active | HARC-004 HARC-012 SRS-050 SRS-051 SRS-052 SRS-056 |
LARC-023 | RADAR monitor and webhook workflow | 0.1 | Alpha | active | HARC-004 HARC-012 LARC-022 SRS-050 SRS-051 SRS-052 SRS-056 |
LARC-024 | RADAR Ansible deployment pipeline flow | 0.1 | Alpha | active | HARC-006 HARC-007 HARC-008 HARC-013 |
LARC-025 | RADAR helper enrichment pipeline | 0.1 | Alpha | active | HARC-014 SRS-051 SRS-055 |
LARC-001 | ADBox training pipeline flow | 0.2 | Alpha | active | SRS-038 |
LARC-014 | ADBox Shipper | 0.1 | Alpha | active | SRS-042 |
LARC-002 | ADBox historical data prediction pipeline flow | 0.2 | Alpha | active | SRS-035 |
LARC-003 | ADBox preprocessing flow | 0.1 | Alpha | active | SRS-029 |
LARC-008 | ADBox batch and real-time prediction flow | 0.2 | Alpha | active | SRS-027 |
LARC-009 | ADBox machine learning package | 0.1 | Alpha | active | SRS-039 |
LARC-010 | ADBox data manager | 0.1 | Alpha | active | SRS-040 |
LARC-011 | ADBox TimeManager | 0.1.1 | Alpha | active | SRS-041 |
LARC-012 | ADBox ConfigManager | 0.1.1 | Alpha | active | SRS-018 SRS-021 |
LARC-013 | ADBox RequestResponseHandler | 0.1 | Alpha | active | SRS-042 |
LARC-004 | IDPS-ESCAPE end-point integrated arch. | 0.1 | Alpha | active | SRS-033 |
LARC-005 | IDPS-ESCAPE end-point hybrid arch. | 0.1 | Alpha | active | SRS-033 |
LARC-006 | IDPS-ESCAPE end-point host-only IDS arch. | 0.1 | Alpha | active | SRS-033 |
LARC-007 | IDPS-ESCAPE end-point capture-only arch. | 0.1 | Alpha | active | SRS-033 |
LARC-SONAR | SONAR Low-Level Architecture | — | Alpha | active | — |
LARC-RADAR | RADAR Low-Level Architecture | — | Alpha | active | — |
LARC-ADBox | ADBox v1 Low-Level Architecture (Maintenance) | — | Alpha | active | — |
LARC-Infrastructure | Infrastructure Low-Level Architecture | — | Alpha | active | — |
| UID | Title | Active | Parent links |
|---|---|---|---|
SWD-022 | SONAR class structure and relationships | active | LARC-019 LARC-020 |
SWD-023 | SONAR feature engineering design | active | LARC-019 LARC-020 |
SWD-024 | SONAR data shipping design | active | LARC-019 LARC-020 |
SWD-025 | SONAR debug mode design | active | LARC-019 LARC-020 |
SWD-018 | RATF: ingestion phase | active | LARC-015 |
SWD-039 | RADAR simulation framework software design | active | HARC-005 |
SWD-019 | RATF: setup phase | active | LARC-015 LARC-016 |
SWD-020 | RATF: simulation phase | active | LARC-016 |
SWD-021 | RATF: evaluation phase | active | LARC-016 |
SWD-026 | RADAR risk engine implementation design | active | LARC-021 LARC-026 |
SWD-027 | RADAR active response script design | active | LARC-026 |
SWD-028 | RADAR detector module design | active | LARC-022 |
SWD-029 | RADAR monitor and webhook module design | active | LARC-023 |
SWD-030 | RADAR helper module class design | active | LARC-025 |
SWD-032 | RADAR configuration management design | active | LARC-024 LARC-025 |
SWD-033 | RADAR data ingestion module design | active | LARC-027 |
SWD-034 | RADAR custom rule and decoder patterns | active | LARC-028 LARC-029 |
SWD-035 | RADAR webhook service design | active | LARC-023 LARC-029 |
SWD-036 | RADAR model security and adversarial defense implementation | active | HARC-015 LARC-031 |
SWD-037 | RADAR-SONAR integration design | active | LARC-026 LARC-027 |
SWD-038 | RADAR-DECIPHER FlowIntel integration design | active | LARC-026 |
SWD-031 | RADAR Ansible role architecture | active | LARC-024 |
SWD-040 | RADAR health check software design | active | MRS-002 |
SWD-001 | ADBox training pipeline | active | LARC-001 |
SWD-010 | ADBox data transformer | active | LARC-003 |
SWD-011 | ADBox preprocessing | active | LARC-003 |
SWD-012 | ADBox TimeManager | active | LARC-011 |
SWD-013 | ADBox Prediction pipeline's inner body | active | LARC-002 LARC-008 |
SWD-014 | ADBox config managers | active | LARC-012 |
SWD-015 | ADBox Shipper and Template Handler | active | LARC-014 |
SWD-016 | ADBox shipping of prediction data | active | LARC-014 |
SWD-017 | ADBox creation of a detector stream | active | LARC-014 |
SWD-002 | ADBox prediction pipeline | active | LARC-002 LARC-008 |
SWD-003 | MTAD-GAT training | active | LARC-009 |
SWD-004 | MTAD-GAT prediction | active | LARC-009 |
SWD-005 | Peak-over-threshold (POT) | active | LARC-009 |
SWD-006 | ADBox Predictor score computation | active | LARC-009 |
SWD-007 | ADBox MTAD-GAT anomaly prediction | active | LARC-009 |
SWD-008 | ADBox MTAD-GAT Predictor | active | LARC-009 |
SWD-009 | ADBox data managers | active | LARC-010 |
SWD-SONAR | SONAR Software Design | active | — |
SWD-RADAR | RADAR Software Design | active | — |
SWD-RADAR-Ansible | RADAR Ansible | active | — |
SWD-ADBox | ADBox v1 Software Design (Maintenance) | active | — |
| UID | Title | Platform | Execution type | Verification method | Release | Complexity | Test data | Version | Active | Parent links |
|---|---|---|---|---|---|---|---|---|---|---|
TST-001 | Deploy ADBox via Docker and shell scripts | Ubuntu 22.04.4 LTS | M | T | alpha | 1 | see referenced files | 0.2 | active | SRS-046 |
TST-010 | ADBox use case 2 without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-035 |
TST-011 | ADBox use case 3 with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-027 |
TST-012 | ADBox use case 3 without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.1 | active | SRS-027 |
TST-013 | ADBox use case 4 with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-038 |
TST-014 | ADBox use case 4 without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-038 |
TST-015 | ADBox use case 5 with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-037 |
TST-016 | ADBox use case 5 without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-037 |
TST-017 | ADBox shipping install | Ubuntu 22.04.4 LTS | M | I | alpha | 2 | see referenced files | 0.2 | active | SRS-049 |
TST-018 | ADBox Create detector data stream | Ubuntu 22.04.4 LTS | M | I | alpha | 2 | see referenced files | 0.2 | active | SRS-042 |
TST-033 | ADBox Wazuh integration Dashboard | Ubuntu 22.04.4 LTS | M | I | alpha | 4 | see referenced files | 0.2 | active | SRS-043 |
TST-002 | Installation of ADBox via pipx | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.1 | inactive | — |
TST-034 | ADBox set up indexer host address | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-017 |
TST-035 | ADBox change indexer credentials | MacOS, Windows, GNU/Linux | M | T | — | 2 | see referenced files | 0.2 | active | SRS-022 |
TST-037 | Open prediction file of training data | MacOS, Windows, GNU/Linux | M | I | alpha | 2 | see referenced files | 0.2 | active | SRS-030 |
TST-038 | Visualize train losses | MacOS, Windows, GNU/Linux | M | I | alpha | 1 | see referenced files | 0.2 | active | SRS-031 |
TST-039 | Open prediction raw outcome | MacOS, Windows, GNU/Linux | Automated/Manual | I | alpha | — | see referenced files | 0.2 | active | SRS-032 |
TST-003 | Install ADBox as dev container | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-044 |
TST-004 | Run ADBox console | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-047 |
TST-005 | Run ADBox in default mode with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 3 | see referenced files | 0.2 | active | SRS-048 |
TST-006 | Run ADBox in default mode without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-048 |
TST-007 | ADBox use case 1 with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-027 |
TST-008 | ADBox use case 1 without a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.1 | active | SRS-027 |
TST-009 | ADBox use case 2 with a Wazuh connection | Ubuntu 22.04.4 LTS | M | T | alpha | 2 | see referenced files | 0.2 | active | SRS-035 |
TST-019 | Suricata installation in a containerized environment | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-008 |
TST-028 | Traffic monitoring on Wazuh (remote) | Ubuntu 22.04.4 LTS | M | I | alpha | 4 | see referenced files | 0.2 | active | SRS-011 |
TST-029 | Changing password for Wazuh indexer users | Ubuntu 22.04.4 LTS | Automated/Manual | I | alpha | 4 | see referenced files | 0.2 | active | SRS-016 |
TST-030 | Changing password for Wazuh API users | Ubuntu 22.04.4 LTS | M | I/T | alpha | 4 | see referenced files | 0.2 | active | SRS-016 |
TST-031 | Wazuh filters using the RESTful API | Ubuntu 22.04.4 LTS | M | I | alpha | 4 | see referenced files | 0.2 | active | SRS-024 |
TST-032 | Wazuh filters using the Wazuh Dashboard | Ubuntu 22.04.4 LTS | M | I | alpha | 2 | see referenced files | 0.2 | active | SRS-011 |
TST-036 | Map a detected event to MITRE ATT&CKS | MacOS, Windows, GNU/Linux | Automated/Manual | I | alpha | 2 | see referenced files | 0.2 | active | SRS-025 |
TST-040 | Visualize IDPS-ESCAPE high level architecture | MacOS, Windows, GNU/Linux | M | I | alpha | 1 | see referenced files | 0.2 | active | SRS-045 |
TST-020 | Wazuh installation in a containerized environment | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-001 |
TST-021 | Wazuh agent installation and enrollment: the local machine | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-003 |
TST-022 | Wazuh agent installation and enrollment: remote machine | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-023 |
TST-023 | Wazuh agent deletion and uninstallation | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-004 |
TST-024 | Wazuh agent unenrollment | Ubuntu 22.04.4 LTS | M | I | alpha | 2 | see referenced files | 0.2 | active | SRS-004 |
TST-025 | Suricata and Wazuh Integration | Ubuntu 22.04.4 LTS | M | I | alpha | 3 | see referenced files | 0.2 | active | SRS-010 |
TST-026 | Port mirroring for remote machines | Ubuntu 22.04.4 LTS | M | A | alpha | 4 | see referenced files | 0.2 | active | SRS-007 |
TST-027 | Traffic monitoring on Wazuh (local) | Ubuntu 22.04.4 LTS | M | I | alpha | 4 | see referenced files | 0.2 | active | SRS-011 |
TST-041 | Setup RADAR foundation | GNU/Linux (Ubuntu+Debian) | Manual | T | alpha | 3 | see referenced files | 0.8 | active | — |
TST-042 | Build suspicious login | GNU/Linux (Ubuntu+Debian) | Manual | T | alpha | 3 | see referenced files | 0.8 | active | SRS-051 SRS-061 |
TST-043 | Build non-whitelist GeoIP detection | GNU/Linux (Ubuntu+Debian) | Manual | T | alpha | 3 | see referenced files | 0.8 | active | SRS-055 SRS-061 |
TST-044 | Build log volume abnormal growth | GNU/Linux (Ubuntu+Debian) | Manual | T | alpha | 2 | see referenced files | 0.8 | active | SRS-056 SRS-061 |
TST-045 | Run RADAR for log volume abnormal growth | GNU/Linux (Ubuntu+Debian) | Manual | T | alpha | 3 | see referenced files | 0.8 | active | SRS-056 SRS-061 |
TST-046 | DECIPHER-RADAR detection validation for Suspicious login | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated | T | alpha | 1 | see referenced files | 0.8 | active | SRS-059 |
TST-047 | Detection validation for GeoIP detection | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated | T | alpha | 1 | see referenced files | 0.8 | active | SRS-059 |
TST-048 | Detection validation for Log volume abnormal growth | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated | T | alpha | 1 | see referenced files | 0.8 | active | SRS-059 |
TST-ADBox | — | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated/Manual | Test (T)/Review of design (R)/Inspection (I)/Analysis (A) | alpha | — | see referenced files | 0.1 | active | — |
TST-Foundation | — | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated/Manual | Test (T)/Review of design (R)/Inspection (I)/Analysis (A) | alpha | — | see referenced files | 0.1 | active | — |
TST-RADAR | — | GNU/Linux (Dockerized C5-DEC deployment environment) | Automated/Manual | Test (T)/Review of design (R)/Inspection (I)/Analysis (A) | alpha | — | see referenced files | 0.1 | active | — |
| UID | Title | Test date | Tester | Defect category | Passed steps | Failed steps | Not executed steps | Release version | Verification method | Active | Parent links |
|---|---|---|---|---|---|---|---|---|---|---|---|
TRP-021 | — | yyyy-mm-dd | ACR | 0 = flawless; 1 = insignificant defect; 2 = minor defect; 3 = major defect; 4 = critical defect | 0 | 0 | 0 | 0.3 | T/R/I/A | active | — |
TRP-001 | TCER: Deploy ADBox via Docker and shell scripts | 2024-07-23 | AGI | 0 — flawless | 4 | 0 | 0 | 0.1 | T | active | TST-001 |
TRP-010 | TCER: ADBox use case 2 with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-009 |
TRP-011 | TCER: ADBox use case 3 with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-011 |
TRP-012 | TCER: ADBox use case 4 with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-013 |
TRP-013 | TCER: ADBox use case 5 with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-015 |
TRP-014 | TCER: ADBox use case 5 without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-016 |
TRP-015 | TCER: ADBox use case 4 without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-014 |
TRP-016 | TCER: ADBox use case 3 without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-012 |
TRP-017 | TCER: ADBox use case 2 without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-010 |
TRP-018 | TCER: ADBox use case 1 without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-008 |
TRP-019 | TCER: Run ADBox in default mode without a Wazuh connection | 2024-07-26 | AGI | 0 — flawless | 2 | 0 | 0 | 0.1 | T | active | TST-006 |
TRP-002 | TCER: Installation of ADBox via pipx | 2024-07-24 | AGI | 4 — critical | 3 | 1 | 0 | 0.1 | T | inactive | TST-002 |
TRP-020 | TCER: Install ADBox as dev container | 2024-07-29 | AGI | 0 — flawless | 6 | 0 | 0 | 0.1 | T | active | TST-003 |
TRP-022 | TCER: ADBox shipping install | 2024-12-10 | AAT | 0 — flawless | 1 | 0 | 0 | 0.3 | T | active | TST-017 |
TRP-023 | TCER: ADBox deployment | 2025-01-17 | AAT | 0 — flawless | 4 | 0 | 0 | 0.3 | T | active | TST-001 |
TRP-024 | TCER: ADBox in dev container | 2025-01-17 | AAT | 0 — flawless | 6 | 0 | 0 | 0.3 | T | active | TST-003 |
TRP-025 | TCER: ADBox console | 2025-01-17 | AAT | 0 — flawless | 1 | 0 | 0 | 0.3 | T | active | TST-004 |
TRP-026 | TCER: ADBox in default mode with Wazuh | 2025-01-22 | AAT | 0 — flawless | 2 | 0 | 0 | 0.3 | T | active | TST-005 |
TRP-027 | TCER: ADBox UC scenario 2 with Wazuh | 2025-01-23 | AAT | 0 — flawless | 1 | 0 | 0 | 0.3 | T | active | TST-009 |
TRP-028 | TCER: ADBox UC scenario 3 with Wazuh | 2025-01-23 | AAT | 0 — flawless | 1 | 0 | 0 | 0.3 | T | active | TST-011 |
TRP-003 | TCER: Install ADBox as dev container | 2024-07-24 | AGI | 4 — critical | 5 | 1 | 0 | 0.1 | T | active | TST-003 |
TRP-004 | TCER: Install ADBox as dev container | 2024-07-24 | AGI | 1 — insignificant | 5 | 1 | 0 | 0.1 | T | active | TST-003 |
TRP-005 | TCER: Run ADBox console | 2024-07-24 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-004 |
TRP-006 | TCER: Run ADBox in default mode with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 2 | 0 | 0 | 0.1 | T | active | TST-005 |
TRP-007 | TCER: Run ADBox in default mode without a Wazuh connection | 2024-07-25 | AGI | 2 — minor | 1 | 1 | 0 | 0.1 | T | active | TST-006 |
TRP-008 | TCER: ADBox use case 1 with a Wazuh connection | 2024-07-25 | AGI | 0 — flawless | 1 | 0 | 0 | 0.1 | T | active | TST-007 |
TRP-009 | TCER: ADBox use case 1 without a Wazuh connection | 2024-07-25 | AGI | 2 — minor | 0 | 1 | 0 | 0.1 | T | active | TST-008 |
TRP-029 | — | yyyy-mm-dd | ACR | 0 = flawless; 1 = insignificant defect; 2 = minor defect; 3 = major defect; 4 = critical defect | 0 | 0 | 0 | 0.5 | T/R/I/A | active | — |
TRP-030 | TCER: Setup RADAR foundation | 2026-03-10 | DMA | 0 — flawless | 4 | 0 | 0 | 0.8 | T | active | TST-041 |
TRP-031 | TCER: Build suspicious login | 2026-03-10 | DMA | 0 — flawless | 11 | 0 | 0 | 0.8 | T | active | TST-042 |
TRP-032 | TCER: Build non-whitelist GeoIP detection | 2026-03-10 | DMA | 0 — flawless | 11 | 0 | 0 | 0.8 | T | active | TST-043 |
TRP-033 | TCER: Build log volume abnormal growth | 2026-03-10 | DMA | 0 — flawless | 9 | 0 | 0 | 0.8 | T | active | TST-044 |
TRP-034 | TCER: Run RADAR for log volume abnormal growth | 2026-03-10 | DMA | 0 — flawless | 2 | 0 | 0 | 0.8 | T | active | TST-045 |
TRP-035 | TCER: DECIPHER-RADAR detection validation for suspicious login | 2026-03-10 | DMA | 0 — flawless | 3 | 0 | 0 | 0.8 | T | active | TST-046 |
TRP-036 | TCER: Detection validation for GeoIP detection | 2026-03-10 | DMA | 0 — flawless | 3 | 0 | 0 | 0.8 | T | active | TST-047 |
TRP-037 | TCER: Detection validation for log volume abnormal growth | 2026-03-11 | DMA | 0 — flawless | 5 | 0 | 0 | 0.8 | T | active | TST-048 |