mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
Replace em/en dashes, arrows, middots, smart quotes, ellipsis, and emoji/icon glyphs with plain ASCII across docs, UI, source, and agents. INKO branding is text-only; empty placeholder is "-"; nav icons removed.
4.9 KiB
4.9 KiB
SquidC5 documentation
SquidSec open-source C5 - GitHub - Releases
Authorized use only. Public OpenAPI is not served by the running server (
/docson the C2 stays off). These guides live in GitHub.
How docs are organized (Diátaxis)
| Need | Doc type | Where |
|---|---|---|
| Learn by doing | Tutorial / quickstart | Root README - Operator runbook |
| Solve a job | How-to | Operator runbook - Deployment |
| Look up a feature | Reference | User guide - AGENTS.md (CLI surface) |
| Understand design | Explanation | Vision - Threat model |
Section templates (consistency)
User guide (every feature chapter):
## Feature name <- match Ops nav label when possible
### What
### Why
### How
### Example
### Pitfalls <- optional table
### See also
Operator runbook (every procedure):
## Procedure name
### Goal
### Prerequisites
### Steps
### Verify
### If it fails
### See also
Deployment (every topic):
## Topic
### Context
### Configuration
### Commands
### Verify
### See also
Start here
| Audience | Start with |
|---|---|
| New operator | User guide - Overview -> Runbook - Connect CLI |
| Day-2 ops | Operator runbook |
| Deploy / upgrade | Deployment |
| Security review | Threat model - SECURITY.md |
| AI agents / contributors | AGENTS.md - CONTRIBUTING.md |
Catalog
Operators
| Document | Description |
|---|---|
| User guide | Feature reference (What / Why / How / Example) - Ops UI, INKO, Profiles, Artifacts, OAST, CLI |
| Operator runbook | Day-2 procedures: shells, beacons, OAST, implants, collab |
| Deployment | Docker lab, OAST, TLS, binary prod + systemd |
Security & architecture
| Document | Description |
|---|---|
| Threat model | Assets, trust boundaries, STRIDE, controls |
| Vision | Product / security architecture |
| SECURITY.md | Vulnerability disclosure |
Planning (engineering)
| Document | Description |
|---|---|
| Roadmap 2026-2027 | Long-range priorities (10 focus areas) |
| Five-star program | Pack A-E status toward category leadership |
| Prod readiness | Phased security/ops execution checklist |
Project
| Document | Description |
|---|---|
| Changelog | Releases + OPSEC notes |
| Contributing | PR / git cycle |
| AGENTS.md | Full CLI surface + agent operating memory |
| Root README | Public quickstart |
Implant & modules
| Path | Description |
|---|---|
| agents/sc5beacon | Native Go beacon (Linux / Windows / macOS) |
| agents/windows | Windows notes |
| agents/linux | Linux notes |
| modules/bof | BOF-style lab modules |
Ops console map
Nav labels in /ops (match User guide):
| Nav | Guide section |
|---|---|
| Dashboard | Status overview |
| Sessions | Sessions |
| Listeners | Listeners |
| Payloads | Payloads and implants |
| Profiles | C2 profiles |
| Artifacts | Artifacts |
| Post-Ex | Post-Ex |
| Collab | Multi-operator collab |
| INKO | INKO |
| Observe | Observability |
| Admin | Tokens - LLM connections - Feature toggles - TLS certificates |
Top bar INKO opens the chat flyout (same INKO stack as the nav page).
Link conventions
- Prefer relative paths:
user-guide.md#sessions,../AGENTS.md - Heading anchors: lowercase, hyphens for spaces; avoid em dashes in headings when deep-linking
- CLI full surface: AGENTS.md is source of truth; user guide CLI section is a summary
- Never document live tokens, keys, or commit
data/
