Skip to content

Malicious-extension feeds: ThreatListEntry + threat_match #31

Description

@richardmhope

Proposal

Force known-bad extensions to critical.

  • New model ThreatListEntry(store, extension_id, source, reason, added_at) + a loader (scheduled pull and POST /api/threatlist so SOAR can push).
  • Matcher in the score path forces critical + a threat_match finding and fires a threat_match alert event (reuses the scoring-override hook + notifications).

Acceptance

  • Add an ID to the threat list → extension flips to critical + threat_match alert + AlertLog row.

From the PLAN.md roadmap to a SOC-consumable Marvin.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestpriority: highAddress first — availability/security impactsecuritySecurity / auth / data exposure

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions