{
    "$schema": "cispar-rules-engine-v3",
    "version": "3.0",
    "description": "CISPAR SOC rules engine — L1/L2/L3 tier routing via schemas and playbooks",
    "matchMode": "substring-any-lowercase",
    "tiers": {
        "l1": {
            "description": "Alert triage, enrichment, classification",
            "auto_trigger": true,
            "skills": [
                "cispar-l1-triage",
                "cispar-network"
            ]
        },
        "l2": {
            "description": "Investigation, containment, evidence collection, playbook execution",
            "auto_trigger": false,
            "trigger_from": "l1",
            "trigger_condition": "severity >= medium AND classification = TP",
            "skills": [
                "cispar-l2-respond",
                "cispar-network"
            ]
        },
        "l3": {
            "description": "Proactive threat hunting, detection engineering, hardening",
            "auto_trigger": false,
            "trigger_from": "operator OR schedule",
            "skills": [
                "cispar-l3-hunt",
                "cispar-network"
            ]
        }
    },
    "rules": [
        {
            "id": "monitor",
            "tier": "l1",
            "priority": 0,
            "triggers": [
                "monitor",
                "monitorea",
                "vigila",
                "watch",
                "daemon",
                "background"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l1-triage/schemas/monitor_system.json",
            "note": "Inicia monitoreo continuo del sistema"
        },
        {
            "id": "scan",
            "tier": "l1",
            "priority": 1,
            "triggers": [
                "escanea",
                "scan",
                "nmap",
                "puertos",
                "port scan",
                "recon",
                "reconocimiento",
                "descubrimiento",
                "discovery"
            ],
            "tool": "exec",
            "schema": "skills/cispar-network/schemas/scan_ports.json",
            "backtrack": {
                "on_failure": "list_ports",
                "fallback_schema": "skills/cispar-network/schemas/list_ports.json"
            }
        },
        {
            "id": "close-port",
            "tier": "l2",
            "priority": 1,
            "triggers": [
                "cierra puerto",
                "close port",
                "bloquea",
                "block",
                "deniega",
                "deny",
                "drop",
                "firewall"
            ],
            "tool": "exec",
            "schema": "skills/cispar-network/schemas/close_port.json",
            "backtrack": {
                "on_failure": "kill_process",
                "fallback_schema": "skills/cispar-network/schemas/kill_process.json"
            }
        },
        {
            "id": "contain",
            "tier": "l2",
            "priority": 0,
            "triggers": [
                "contiene",
                "contain",
                "aísla",
                "isolate",
                "bloquea ip",
                "block ip",
                "cuarentena",
                "quarantine"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l2-respond/schemas/contain.json",
            "playbook_hint": "Match event type to playbooks/*.json"
        },
        {
            "id": "investigate",
            "tier": "l2",
            "priority": 1,
            "triggers": [
                "investiga",
                "investigate",
                "analiza",
                "analyze",
                "correlaciona",
                "timeline",
                "kill chain",
                "qué pasó",
                "root cause"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l2-respond/schemas/investigate.json"
        },
        {
            "id": "evidence",
            "tier": "l2",
            "priority": 1,
            "triggers": [
                "evidencia",
                "evidence",
                "forense",
                "forensics",
                "recolecta",
                "collect",
                "preserva",
                "captura estado"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l2-respond/schemas/collect_evidence.json"
        },
        {
            "id": "playbook",
            "tier": "l2",
            "priority": 0,
            "triggers": [
                "playbook",
                "ejecuta playbook",
                "run playbook",
                "respuesta automática",
                "automated response"
            ],
            "tool": "read",
            "schema": "skills/cispar-l2-respond/schemas/run_playbook.json",
            "note": "Read playbook JSON from agents/cispar/playbooks/, execute steps sequentially"
        },
        {
            "id": "hunt",
            "tier": "l3",
            "priority": 1,
            "triggers": [
                "hunt",
                "caza",
                "busca amenazas",
                "threat hunt",
                "busca TTPs",
                "proactivo",
                "proactive",
                "busca indicadores"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l3-hunt/schemas/threat_hunt.json"
        },
        {
            "id": "coverage",
            "tier": "l3",
            "priority": 1,
            "triggers": [
                "coverage",
                "cobertura",
                "gaps",
                "brechas",
                "qué nos falta",
                "detection gaps",
                "attack surface"
            ],
            "tool": "read",
            "schema": "skills/cispar-l3-hunt/schemas/coverage_gap.json",
            "mitre_ref": "agents/cispar/mitre/attack-map.json"
        },
        {
            "id": "harden",
            "tier": "l3",
            "priority": 1,
            "triggers": [
                "harden",
                "endurece",
                "hardening",
                "seguriza",
                "asegura",
                "fix config",
                "remediate",
                "patch"
            ],
            "tool": "exec",
            "schema": "skills/cispar-l3-hunt/schemas/harden.json"
        },
        {
            "id": "vuln-scan",
            "tier": "l1",
            "priority": 1,
            "triggers": [
                "nuclei",
                "vuln",
                "vulnerability",
                "vulnerabilidades",
                "CVE",
                "exploit",
                "cve scan"
            ],
            "tool": "exec",
            "schema": "skills/cispar-network/schemas/vuln_scan.json"
        },
        {
            "id": "report",
            "tier": "l2",
            "priority": 2,
            "triggers": [
                "reporte",
                "report",
                "resumen",
                "summary",
                "executive",
                "estado",
                "status",
                "estadísticas"
            ],
            "tool": "exec",
            "schema": "skills/cispar-report/schemas/incident_report.json"
        },
        {
            "id": "anomaly-check",
            "tier": "all",
            "priority": 0,
            "triggers": [],
            "auto": true,
            "tool": "exec",
            "schema": "skills/cispar-anomaly/schemas/anomaly_check.json",
            "note": "Runs automatically after every action — no manual trigger"
        }
    ],
    "on_failure": {
        "strategy": "autonomous_retry",
        "max_attempts": 3,
        "fallback_chain": [
            "iptables → nftables → fail2ban",
            "kill -9 → pkill -u → cgroup freeze",
            "usermod -L → chage -E 1970 → revoke ssh keys",
            "close_port → drop all traffic from subnet → null-route"
        ],
        "after_max_attempts": "mark PARTIAL_CONTAINED, document in THINKING.md, keep monitoring",
        "never": "stop acting, wait for humans, ask for approval"
    },
    "learning": {
        "after_resolved": "append to FEEDBACK.md: [date] SIEMPRE/NUNCA: <rule>",
        "after_failed": "append to FEEDBACK.md: [date] NUNCA: <what failed and why>",
        "after_new_incident_type": "create new playbook in playbooks/"
    },
    "files": {
        "thinkingFile": "agents/cispar/THINKING.md",
        "contextFile": "agents/cispar/CONTEXT.md",
        "feedbackFile": "agents/cispar/FEEDBACK.md",
        "mitreMap": "agents/cispar/mitre/attack-map.json",
        "playbooksDir": "agents/cispar/playbooks/"
    }
}