Skip to content

feat(docs): vendor report rules (Kaspersky APT + Huorong malware) (#65) - #68

Merged
dhicoc merged 1 commit into
mainfrom
fix/issue-65-vendor-report-rules
Aug 11, 2026
Merged

feat(docs): vendor report rules (Kaspersky APT + Huorong malware) (#65)#68
dhicoc merged 1 commit into
mainfrom
fix/issue-65-vendor-report-rules

Conversation

@dhicoc

@dhicoc dhicoc commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

Closes issue #65 problem 2 (vendor-style professional reports).

Reporter preference (comment):

  • Kaspersky for APT analysis (Securelist + full MATA PDF)
  • Huorong for ordinary malware/program analysis
  • Templates: quality over quantity

Design

  • One structure overlay: skills/docs-generator/references/vendor-report-rules.md
  • Two flavors only (no N parallel full templates):
    • malware (default) — Huorong-style: overview → flow → sample analysis → emergency response → IOC
    • apt — Kaspersky Securelist-style: executive summary → infection chain → investigation → interesting findings → technical analysis → detection/mitigation → IOC
  • Pentest/CTF/JS-sign keep existing task templates + minimal professional elements
  • Structure only — no vendor body text / charts / sample IOCs copied
  • Does not weaken Evidence→Finding→Path (§0 still MUST)

Files

  • skills/docs-generator/references/vendor-report-rules.md (new)
  • skills/docs-generator/SKILL.md (selection + MUST overlay)
  • skills/docs-generator/references/security-report-templates.md (§0.6 + §1b + imports note)

Validation (local)

  • skills/scripts/smoke.ps1ALL PASS
  • skills/scripts/verify-routing-coherence.ps1ALL ROUTING COHERENCE CHECKS PASSED

Merge policy

Collaborator merges locally after tests, then pushes main.

…65)

- Add vendor-report-rules.md: 2 flavors only (apt/malware), structure-only
- Wire docs-generator SKILL + security-report-templates overlay and IOC gates
- Default malware (Huorong-style); apt uses Securelist-style infection chain
@dhicoc

dhicoc commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator Author

本地合并流程已完成:

  1. 审查 PR(vendor-report-rules + SKILL/templates 挂接)
  2. git merge --no-ff 到本地 main
  3. skills/scripts/smoke.ps1ALL PASS
  4. push main

按协作者约定:本地合并 + 测试通过后再上线。

@dhicoc
dhicoc merged commit cf9a698 into main Aug 11, 2026
12 checks passed
@dhicoc
dhicoc deleted the fix/issue-65-vendor-report-rules branch August 11, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant