/** * Shared receiver-in-path probe helpers. * * Extracted from pattern-mitigate.ts so discover_env can reuse the same * SIEM-event tenx_hash detection without duplicating logic. * * Usage: * import { probeReceiverInPath } from '../lib/receiver-probe.js'; * const result = await probeReceiverInPath(vendor, connector); * // true → Receiver is in-path (tenx_hash seen in recent events) * // false → Receiver not in-path (no hash in sample) * // null → Inconclusive (no events in window or connector error) */ import type { SiemConnector } from './siem/index.js'; /** * Probe the SIEM for 1–3 recent events and check if any carry tenx_hash. * Returns true → Receiver is in-path (hash stamp confirmed) * Returns false → No hash found in sample (Receiver likely absent or bypassed) * Returns null → Probe failed / SIEM unavailable (inconclusive) * * Uses a 5-minute window and limit=3 so the probe is fast and non-intrusive. */ export declare function probeReceiverInPath(_vendor: string, connector: SiemConnector): Promise; /** * Check whether a raw SIEM event (any shape) carries tenx_hash. * Handles flat objects and nested envelopes (docker/kubernetes/log field). */ export declare function eventHasTenxHash(evt: unknown): boolean;