Cover image for project: NEXUS Alert Triage Framework IN PROGRESS

Technical summary

NEXUS Alert Triage Framework standardizes triage for the 10 most common security, infrastructure and operations alerts in the ecosystem, each with an analytical checklist, escalation and auto-close criteria, severity and decision flow. The plugin records decisions with an audit trail — multi-sector N1/N2/N3 escalation, mitigation or closure — updating the task itself in the panel, and provides an assistant with Mermaid flowcharts, history and statistics.

Executed scope

  • Plugin registration in plugin.php: registerTab('alert-triage', tab.php) with the check-square icon (Security category), registerDoc('alert-triage', doc.md) and 13 API actions via registerApiAction (triage_ prefix).
  • Database: MySQL tables triage_decisions (task_id, playbook_id, alert_title, decision, target_sector, analyst, reasoning, checklist_state LONGTEXT, created_at, with idx_playbook/idx_decision/idx_sector/idx_created_at indexes) for decision audit and triage_sectors (name UNIQUE, level N1/N2/N3, description, is_default) — created with CREATE TABLE IF NOT EXISTS in triage_install(); no install.sql.
  • Default escalation sectors (6): N1 - Initial Triage / SOC L1, N2 - SecOps / Security Engineering (default), N3 - Infrastructure / Cloud / DevOps, DevSecOps / Product Squad, Red Team / Threat Hunting and C-Level / Incident Response & Committee — with custom sector support (triage_sector_save/triage_sector_delete).
  • 10 built-in operational playbooks (triage_get_playbooks), each with category, default severity, sources, symptoms, 4-point checklist, escalation criteria, auto-close criteria, analyst reasoning and Mermaid flow: (1) Critical Dependency Vulnerability SCA/CVE, (2) Secret / Hardcoded Key Leak, (3) SAST Finding / Code Injection (SQLi, XSS, RCE, IDOR), (4) DAST Finding / Endpoint Exposure, (5) Compromised Credentials / Email Leak, (6) Malicious IP Activity / CTI Reputation, (7) Email Authentication Failure / Spoofing, (8) Phishing Alert / Suspicious URL, (9) Satellite / OCI Worker / Container Down and (10) AI Credits Exhaustion / API Quota.
  • Triage decision (triage_decide): 4 verdicts — escalated, closed, mitigated and in_triage — with mandatory reasoning (HTTP 400 if empty) and validated checklist persisted as JSON.
  • Task integration: when task_id is provided, triage_decide adds a formatted audit comment (playbook used, decision, target sector, analyst, technical reasoning, validated items and recommended action) and updates the task — escalated sets priority = 1; closed/mitigated set status = 'done' with done_at.
  • Centralized configuration in triage_settings (via DB::getConfig): default_analyst, default_sector, auto_escalate_p1 and notify_on_escalate.
  • Statistics (triage_stats): total decisions, escalated, closed/mitigated and pending. History (triage_history, 1–100 limit) and clear (triage_history_clear, TRUNCATE).
  • Fast Responses: fastr.json manifest with /triage list, /triage <1-10> (full checklist) and /triage <keyword> (match by keywords such as cve, gitleaks, sqli, dmarc, phishing, quota) via triage_fastr + triage_fastr_suggest.
  • Intel Hub: nx_intel_register_enricher('alert-triage', ['_text'], 'triage_intel_enrich', 40) — suggests the playbook and severity from the analyzed item text.
  • Interface (tab.php, 842 lines): 4 tabs — Playbooks (10 cards with checklist modal and Mermaid flowchart), Decision & Escalation Assistant (form with playbook selector, mandatory checklist, decision and side guide with flow), Decision History and Settings & Sectors — with 4 KPIs (10 Playbooks, total decisions, escalated and closed).

Stack and tools

  • PHP 8 backend (no framework) + MySQL (triage_decisions, triage_sectors)
  • No external API dependencies — content, checklist and process framework (zero cost)
  • Alpine.js + Tailwind CSS (4 tabs, KPIs, decision form and modals)
  • Embedded Mermaid decision flows in playbooks
  • Internal Plugin API (PluginManager tabs/docs/actions + fastr.json + intel enricher)
  • NEXUS API Bearer token authentication on API calls

Operational tags

  • Alerts
  • Playbook
  • Triage
  • SOC
  • SecOps
  • Escalation
  • Checklist
  • Audit
  • Security
  • NEXUS Plugin

Operational result

  • Standardized decision: 10 playbooks with objective escalation and auto-close criteria for the most common alerts.
  • Audit trail: every decision records playbook, verdict, target sector, analyst, reasoning and validated checklist.
  • Task integration: verdict comment in the panel and automatic update (escalated → priority 1; closed/mitigated → done).
  • Multi-sector matrix: N1/N2/N3 escalation with customizable sectors and per-team levels.
  • Visual flows: Mermaid decision diagrams per playbook in the assistant and modals.
  • Quick access: /triage <number or keyword> slash command straight from the Fastr terminal.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS Alert Triage Framework standardizes triage for the 10 most common security, infrastructure and operations alerts in the ecosystem, each with an analytical checklist, escalation and auto-close criteria, severity and decision flow. The plugin records decisions with an audit trail — multi-sector N1/N2/N3 escalation, mitigation or closure — updating the task itself in the panel, and provides an assistant with Mermaid flowcharts, history and statistics.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.