From ac38dc37c2dbe1f1c483a6dfe12953790bc4a66e Mon Sep 17 00:00:00 2001 From: drjones Date: Tue, 7 Jul 2026 06:12:35 +0000 Subject: [PATCH] Update documentation with Phase 2 advanced features and testing guide MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Documentation updates: - Added AI-Powered Intelligence section to Features - Listed advanced features: AI translation, attack paths, security coach, PDF reports - Added comprehensive API testing guide with curl examples - Updated Features section to reflect Phase 2 completion - Added instructions for testing AI features without API keys Phase 2 Completion Summary: ✅ AI Finding Translation - converts technical findings to business language ✅ Attack Path Visualization - generates attack graphs with nodes/edges ✅ AI Security Coach - answers questions about findings ✅ PDF Report Generation - creates professional reports ✅ Mock AI System - demo mode for all features without API keys All APIs tested and verified working. Frontend fully operational. Co-Authored-By: Claude Haiku 4.5 --- README.md | 71 ++++++++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 68 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 888bd6d..a3babd7 100644 --- a/README.md +++ b/README.md @@ -322,13 +322,27 @@ graph TD - **Baseline Snapshots** - Point-in-time assessments for comparison - **Board-Ready Formatting** - Professional layouts for stakeholders -### Planned Features (Phase 2 & 3) +### Advanced Features (Phase 2 - NEW) + +#### AI-Powered Intelligence +- **✅ AI Finding Translation** - Automated conversion of technical vulnerabilities to business language (OpenAI/Anthropic) +- **✅ Attack Path Visualization** - Graph-based attack vector diagrams with nodes and edges +- **✅ AI Security Coach** - Interactive Q&A system for questions about specific findings +- **✅ PDF Report Generation** - Professional PDF exports with findings, scores, and metrics +- **✅ Mock AI System** - Demo mode functional without API keys, ready for production API integration + +#### Advanced Remediation +- **Attack Path Analysis** - Understand how attackers would reach sensitive data +- **Remediation Priority** - AI-suggested fix sequences based on exploit complexity +- **Impact Quantification** - Estimated business cost of each security issue + +### Planned Features (Phase 3) - **Continuous Monitoring Engine** - Daily automated assessments -- **Attack Path Visualization** - Interactive diagrams showing attack vectors -- **AI Security Coach** - Interactive Q&A about specific findings - **Executive Protection Services** - Enhanced monitoring for leadership - **Advanced Integrations** - Cloud APIs, SIEM connectors, threat intelligence feeds +- **Workflow Automation** - Auto-remediation for certain findings +- **Executive Briefing Generator** - Automated executive summaries --- @@ -584,6 +598,57 @@ The seed script creates a demo tenant "Acme Corp" with three users: | IT Admin | it@acmecorp.io | TrustOS2024! | | TrustOS Admin | admin@trustos.com | TrustOS-Admin-2024! | +### Testing AI Features + +After logging in with any demo account, try these API endpoints to test the AI-powered features: + +**1. Get Dashboard** +```bash +curl -X GET http://localhost:8000/api/v1/dashboard/acme-corp-demo-001 \ + -H "Authorization: Bearer YOUR_TOKEN" +``` +Returns: Cyber health score, critical issues count, top risks + +**2. Trigger AI Finding Translation** +```bash +curl -X POST http://localhost:8000/api/v1/findings/{finding_id}/ai-translate \ + -H "Authorization: Bearer YOUR_TOKEN" +``` +Response: Translation queued (processes asynchronously) + +**3. Ask AI Security Coach** +```bash +curl -X POST http://localhost:8000/api/v1/findings/{finding_id}/ai-question \ + -H "Authorization: Bearer YOUR_TOKEN" \ + -H "Content-Type: application/json" \ + -d '{"question":"What are the main risks of this vulnerability?"}' +``` +Returns: AI-generated answer about the finding + +**4. Generate Attack Path** +```bash +curl -X POST http://localhost:8000/api/v1/attack-paths/{finding_id}/generate \ + -H "Authorization: Bearer YOUR_TOKEN" +``` +Response: Path generation queued (generates attack vectors) + +**5. Retrieve Attack Graph** +```bash +curl http://localhost:8000/api/v1/attack-paths/{finding_id} \ + -H "Authorization: Bearer YOUR_TOKEN" | jq +``` +Returns: Graph nodes and edges showing attack vectors + +**6. Download PDF Report** +```bash +curl -X POST http://localhost:8000/api/v1/audit-reports/acme-corp-demo-001/pdf-snapshot \ + -H "Authorization: Bearer YOUR_TOKEN" \ + -o report.pdf +``` +Downloads: Professional PDF report with findings and scores + +**Note**: AI features work without OpenAI/Anthropic API keys using mock data. Set `OPENAI_API_KEY` or `ANTHROPIC_API_KEY` in `.env` for real AI translations. + ### Stopping the Services ```bash