Threat Management contracts
- Add typed CyberSecure posture summaries for HOUR, DAY, WEEK and MONTH, including nullable subscription/inspection fields and gateway signature status.
- Add strict IPS/category and Traffic Identification updates with fresh fetch/merge/save, controller catalog validation, and field-level persistence verification. Uncertain outcomes are reported without replay; unexpected changes to preserved fields are identified separately.
- Preserve protected-network scope and controller-owned settings.
ipsInlinemay be preserved when already configured but cannot be newly selected. - Keep the legacy seven-field event projection compatible with existing consumers; add an explicit threat-event projection for category and source/destination roles.
- Expose
advanced_filtering_preferencein the typed settings read. Existing Network consumers may see this additive field before the new tools arrive.
Verified on Network 10.6.106: all four posture periods, approved device-fingerprinting apply/readback/restore, and one ActiveX-category removal/readback/restore. Both settings restored; configuration persistence does not establish packet-level detection behavior.
Related: #385, #757. The Network/API tools ship separately with a minimum dependency on this Core version.