# ir-assessment

## Objective
Professional security assessment following NIST SP 800-61r3, MITRE ATT&CK (T1078, T1539, T1528), FIRST CSIRT methodology.

## Methodology
See [docs/methodology.md](docs/methodology.md) for detailed assessment framework.

## Pipeline
See [docs/pipeline.md](docs/pipeline.md).

## Scripts
See [docs/scripts-index.md](docs/scripts-index.md) — категоризация всех
скриптов (core pipeline / TG infra / validation / analysis / one-offs).

## Data Inventory
See [docs/data-inventory.md](docs/data-inventory.md) and [findings/data/index.csv](findings/data/index.csv).

Operational commands:

```bash
make validate-data-index
make data-index-report
```

## Artifact Inventory
See [docs/artifact-inventory.md](docs/artifact-inventory.md) and [artifacts/index.csv](artifacts/index.csv).

Operational commands:

```bash
make validate-artifact-index
make artifact-index-report
```

## Project Structure
```
ir-assessment/
├── CLAUDE.md                  Project map + agent entrypoint
├── README.md                  This file
├── SETUP.md                   Setup + agent onboarding
├── Makefile                   Operational entrypoints
├── docs/
│   ├── methodology.md         Assessment methodology (L1-L4)
│   ├── log-source-discovery.md  Log-source taxonomy + P0 pilot
│   ├── pipeline.md            input → script → output map
│   ├── scripts-index.md       Script categorization
│   ├── quality-criteria.md    Quality and completeness standards
│   ├── threat-modeling-guide.md  Threat scenario format (EC1-EC5)
│   ├── status-workflow.md     Canonical status rules
│   └── processing/            Per-topic analysis notes
├── findings/                  Raw data + findings/data/ aggregates
├── artifacts/                 Deliverables + status-matrix.csv (canonical status)
├── scripts/                   Automation (see docs/scripts-index.md)
├── redteam/                   Per-target dossiers (local-only, gitignored)
└── references/                External standards
```

## Standards
NIST SP 800-61r3, MITRE ATT&CK (T1078, T1539, T1528), FIRST CSIRT

## Status Workflow

See [docs/status-workflow.md](docs/status-workflow.md).

Operational commands:

```bash
make sync-status
make status-report
```

Canonical source remains [artifacts/status-matrix.csv](artifacts/status-matrix.csv).
