Skip to content

sodejm/incident-response-sandbox

v0.1.0PolyForm-Noncommercial-1.0.0

Offline incident action planning and fixture-only sandbox execution.

COPS Incident Response Sandbox

This portable package creates typed incident plans and executes two low-risk actions against synthetic local JSON fixtures only: isolate-host and revoke-session. There is no production API adapter.

Use a private directory (0700) for plans, receipts, and a copied fixture. The fixture file should be 0600. Generate a plan with an expiry and unique nonce, then save the output as plan.json:

python3 scripts/ir.py plan --action isolate-host --tenant example-tenant --target host-1 --expires-at 2030-01-01T00:00:00Z --nonce example-1 --approver-assertion analyst-1
python3 scripts/ir.py dry-run plan.json fixture.json > receipt.json
python3 scripts/ir.py execute plan.json receipt.json fixture.json

The second command is mandatory. Execution rejects expired or modified plans, tenant or target mismatch, changed state, stale dry-run receipts, missing fixture permission, throttling, and duplicate plan hashes or nonces. Simulated partial failure records whether rollback succeeded or failed. The fixture execution history prevents replay of recorded attempts.

The approver name is an operator assertion. The plan hash detects accidental or unauthorized changes to the plan content only when compared with a trusted copy; it is not a signature, approval proof, or immutable audit record. This package does not support concurrent writes by untrusted local accounts. Use private staging on shared hosts. Production mutation and trusted approval attestation remain separate work.