[FEAT] Ingestion incidenti SIEM/SOC/EDR (P1) -> endpoint /services/incidents-ingest
- ServicesController::ingestIncident: crea incidente Art.23 da alert esterno (scope ingest:incidents) - Dedup su external_ref (org+ref), mapSeverity (CVSS/P1-P5/stringhe -> enum) - Classificazione AI best-effort (classifyIncident: IS-1..4, severity, significativita) - Deadline Art.23 (24h/72h/30g) su incidenti significativi + webhook dispatch - Migrazione 023: incidents += source/source_system/external_ref + indice univoco dedup - Route POST:incidentsIngest in index.php Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
094d453e8e
commit
21909994c2
@@ -348,6 +348,7 @@ $actionMap = [
|
||||
'GET:complianceSummary' => 'complianceSummary',
|
||||
'GET:risksFeed' => 'risksFeed',
|
||||
'GET:incidentsFeed' => 'incidentsFeed',
|
||||
'POST:incidentsIngest' => 'ingestIncident', // P1: ingestion alert SIEM/SOC/EDR
|
||||
'GET:controlsStatus' => 'controlsStatus',
|
||||
'GET:assetsCritical' => 'assetsCritical',
|
||||
'GET:suppliersRisk' => 'suppliersRisk',
|
||||
|
||||
Reference in New Issue
Block a user