docs(ttp): add TTP tagging design (order-of-work step 1)
Pre-implementation spec for the TTP-tagging worker. Defines the ATT&CK-canonical vocabulary, schema (ttp_tag + ttp_rule[_state]), bus topics, worker shape, lifter layering (rule-based v0, behavioral/intel/email v0.5, sigma/biometric later), confidence model, API surface, UI surface, observability, performance targets, and a CDD plan (Appendix E) that splits contracts from tests with xfail discipline so CI stays green between steps.
This commit is contained in:
2864
development/TTP_TAGGING.md
Normal file
2864
development/TTP_TAGGING.md
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user