IN PROGRESS
Technical summary
NEXUS Alert Triage Framework standardizes triage for the 10 most common security, infrastructure and operations alerts in the ecosystem, each with an analytical checklist, escalation and auto-close criteria, severity and decision flow. The plugin records decisions with an audit trail — multi-sector N1/N2/N3 escalation, mitigation or closure — updating the task itself in the panel, and provides an assistant with Mermaid flowcharts, history and statistics.
Executed scope
- Plugin registration in
plugin.php:registerTab('alert-triage', tab.php)with thecheck-squareicon (Security category),registerDoc('alert-triage', doc.md)and 13 API actions viaregisterApiAction(triage_prefix). - Database: MySQL tables
triage_decisions(task_id, playbook_id, alert_title, decision, target_sector, analyst, reasoning, checklist_state LONGTEXT, created_at, withidx_playbook/idx_decision/idx_sector/idx_created_atindexes) for decision audit andtriage_sectors(name UNIQUE, level N1/N2/N3, description, is_default) — created withCREATE TABLE IF NOT EXISTSintriage_install(); no install.sql. - Default escalation sectors (6): N1 - Initial Triage / SOC L1, N2 - SecOps / Security Engineering (default), N3 - Infrastructure / Cloud / DevOps, DevSecOps / Product Squad, Red Team / Threat Hunting and C-Level / Incident Response & Committee — with custom sector support (
triage_sector_save/triage_sector_delete). - 10 built-in operational playbooks (
triage_get_playbooks), each with category, default severity, sources, symptoms, 4-point checklist, escalation criteria, auto-close criteria, analyst reasoning and Mermaid flow: (1) Critical Dependency Vulnerability SCA/CVE, (2) Secret / Hardcoded Key Leak, (3) SAST Finding / Code Injection (SQLi, XSS, RCE, IDOR), (4) DAST Finding / Endpoint Exposure, (5) Compromised Credentials / Email Leak, (6) Malicious IP Activity / CTI Reputation, (7) Email Authentication Failure / Spoofing, (8) Phishing Alert / Suspicious URL, (9) Satellite / OCI Worker / Container Down and (10) AI Credits Exhaustion / API Quota. - Triage decision (
triage_decide): 4 verdicts —escalated,closed,mitigatedandin_triage— with mandatory reasoning (HTTP 400 if empty) and validated checklist persisted as JSON. - Task integration: when
task_idis provided,triage_decideadds a formatted audit comment (playbook used, decision, target sector, analyst, technical reasoning, validated items and recommended action) and updates the task —escalatedsetspriority = 1;closed/mitigatedsetstatus = 'done'withdone_at. - Centralized configuration in
triage_settings(viaDB::getConfig):default_analyst,default_sector,auto_escalate_p1andnotify_on_escalate. - Statistics (
triage_stats): total decisions, escalated, closed/mitigated and pending. History (triage_history, 1–100 limit) and clear (triage_history_clear, TRUNCATE). - Fast Responses:
fastr.jsonmanifest with/triage list,/triage <1-10>(full checklist) and/triage <keyword>(match by keywords such as cve, gitleaks, sqli, dmarc, phishing, quota) viatriage_fastr+triage_fastr_suggest. - Intel Hub:
nx_intel_register_enricher('alert-triage', ['_text'], 'triage_intel_enrich', 40)— suggests the playbook and severity from the analyzed item text. - Interface (
tab.php, 842 lines): 4 tabs — Playbooks (10 cards with checklist modal and Mermaid flowchart), Decision & Escalation Assistant (form with playbook selector, mandatory checklist, decision and side guide with flow), Decision History and Settings & Sectors — with 4 KPIs (10 Playbooks, total decisions, escalated and closed).
Stack and tools
- PHP 8 backend (no framework) + MySQL (
triage_decisions,triage_sectors) - No external API dependencies — content, checklist and process framework (zero cost)
- Alpine.js + Tailwind CSS (4 tabs, KPIs, decision form and modals)
- Embedded Mermaid decision flows in playbooks
- Internal Plugin API (PluginManager tabs/docs/actions +
fastr.json+ intel enricher) - NEXUS API Bearer token authentication on API calls
Operational tags
- Alerts
- Playbook
- Triage
- SOC
- SecOps
- Escalation
- Checklist
- Audit
- Security
- NEXUS Plugin
Operational result
- Standardized decision: 10 playbooks with objective escalation and auto-close criteria for the most common alerts.
- Audit trail: every decision records playbook, verdict, target sector, analyst, reasoning and validated checklist.
- Task integration: verdict comment in the panel and automatic update (escalated → priority 1; closed/mitigated → done).
- Multi-sector matrix: N1/N2/N3 escalation with customizable sectors and per-team levels.
- Visual flows: Mermaid decision diagrams per playbook in the assistant and modals.
- Quick access:
/triage <number or keyword>slash command straight from the Fastr terminal.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS Alert Triage Framework standardizes triage for the 10 most common security, infrastructure and operations alerts in the ecosystem, each with an analytical checklist, escalation and auto-close criteria, severity and decision flow. The plugin records decisions with an audit trail — multi-sector N1/N2/N3 escalation, mitigation or closure — updating the task itself in the panel, and provides an assistant with Mermaid flowcharts, history and statistics.
Architecture and organization
- PHP 8
- MySQL
- Alpine.js
- Tailwind CSS
- Mermaid
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.