Skip to the content.

Audit-Only Correlation Service

The reference receiver retains every verified event, including event names it does not recognize. Correlation runs only after the event-chain and remote anchor checks succeed. Client binaries receive no decision or account action.

Rule format

Install a rule with authenticated POST /v1/rules:

{
  "rule_id": "kernel-memory-correlation",
  "version": 1,
  "required_events": [
    "kernel_thread_start_unlinked",
    "executable_private_region"
  ],
  "window_events": 4096,
  "outcome": "suspicious_session",
  "require_attestation": true,
  "min_samples": 100,
  "max_false_positive_rate": 0.01
}

Rule versions are immutable and monotonically increasing. Every newly installed version starts in audit_only, even when an earlier version was active. A decision stores the exact session_id:event_seq inputs, rule ID, rule version, outcome, and rollout mode.

Measurement and promotion

Submit reviewed decision feedback to POST /v1/decisions/<decision-id>/feedback with {"false_positive":false}. POST /v1/rules/<rule-id>/promote succeeds only after the configured sample count is reached and the reviewed false-positive rate is within the rule threshold. Promotion changes server-side decision classification only; it does not send enforcement instructions to clients.

Read current metrics through GET /v1/rules/<rule-id> and session decisions through GET /v1/sessions/<session-id>/decisions.

Rollback and audit

POST /v1/rules/<rule-id>/rollback with {"version":1} changes the current version pointer without deleting later versions, decisions, feedback, or raw events. Install, promotion, feedback, and rollback operations are retained in correlation_rule_audit.

The SQLite implementation is a reference service. Production deployments must place administrative routes behind a dedicated authorization policy and replicate rule, decision, feedback, and audit tables to append-only storage.