394 Commits
Author SHA1 Message Date
iimp0ster 9464482335 Merge pull request #167 from iimp0ster/data/edge-jul16-infra-refresh
edge-exploits: fix stale SAP/SonicWall prose + rebuild infra tables from live data
2026-07-16 21:18:51 -06:00
imposterandClaude Opus 4.8 23a565f698 trends/edge-exploits: recompute the webshell-command table for the live window
The post-exploit command table was the last frozen Mar-Apr artifact. Recomputed
the cmd.gz.war -> /cmd.gz/cmd.jsp webshell POSTs (SD-WAN vManage, CVE-2026-20127)
from the live-window exports: only 33 executions, 3 distinct commands (id x21,
dir x10, ls x2), all trivial enumeration from a handful of IPs.

The baseline's full chain (819 id, 372 XMRig via kernel.sh, /etc/shadow reads,
gs-netcat reverse shells) did not recur. Preserved that finding as labeled
historical context in the callout; the table now leads with live reality.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 21:12:34 -06:00
imposterandClaude Opus 4.8 848764acc7 trends/edge-exploits: fix stale prose + rebuild infra tables from live data
Living-doc consistency pass after the Jul 16 data refresh (PR #163). The
hand-written deep-dives and infra tables were still on the frozen Mar-Apr
baseline and contradicted the auto-updated charts.

Prose fixes:
- SAP: was "third most targeted, 1,179 hits". Now #6 at 1,638 (1,024 on the
  CVE-2022-22536 Apr 9-11 burst + 614 on CVE-2025-31324 across the window).
  Reframed as a historical burst, dropped the stale ranking.
- SonicWall: was "478 attempts / 284 IPs, most distributed". Now 1,693 hits;
  dropped the "most distributed" superlative (it contradicted the Next.js
  section) and documented the verified libredtail-http/apache.selfrep worm
  staging rotation (31.57 -> 204.76 -> 125.135 -> 14.46 -> 217.60).
- Dropped the stale "31-day observation window" anchors (window is now ~4 mo).

Infra rebuild from the raw live-window exports (Apr 19 - Jul 16, newest-wins
day-dedup via scripts/extract_edge_infra.py), ASN/geo via Team Cymru + IPinfo:
- Scanner-UA chart: self-identification collapsed 38.7% -> ~5% as the
  browser-spoofing CitrixBleed 2 flood took over; recomputed tool families.
- Staging Infrastructure: current worm-rotation hosts + new campaigns
  (softwaretech loader, Next.js cloak stager, Cloudflare-fronted installer).
- Multi-Device Operators: current cross-decoy scanners; known research
  scanners (ONYPHE, LeakIX) excluded.
- Replaced the unverifiable "Active" status badge with an Observed telemetry
  window (no liveness probe of live malicious hosts).
- Flagged the webshell-command breakdown as a Mar-Apr baseline capture.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 20:58:55 -06:00
iimp0ster 01aadcae09 Merge pull request #166 from iimp0ster/iimp0ster/trusted-binary-dll-sideloading
fix: restore constant card and Sigma highlighting
2026-07-16 20:57:58 -06:00
imposterandClaude Opus 4.8 b922882538 scripts: add extract_edge_infra.py for scanner/staging/operator recompute
The edge-exploits page's scanner-UA, staging, and multi-device-operator
tables were hand-curated from a one-off Mar-Apr pass and had no build step,
so every data refresh left them stale. This is that missing step.

Reads the raw Defused exports in ~/Downloads, applies the same newest-wins
day-dedup as transform_defused_csv.py so its numbers reconcile with the
page charts, and prints a defanged, curated view (named-tool vs
browser-masquerade UA split, staging URLs with first/last-seen, operator
IP -> decoy coverage). Persists nothing to the repo (decision #009); ASN
for chosen hosts is filled via Team Cymru / enrich_staging_domains.py.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 20:52:54 -06:00
iimp0ster 597898c904 Merge pull request #164 from iimp0ster/feat/clickgrab-carson-2026-07-17
ClickFix cradle refresh (Carson 2026-07-17): rotation back to remote download cradles
2026-07-16 20:20:06 -06:00
imposter a935d56d49 fix: restore constant card and Sigma highlighting 2026-07-16 19:48:14 -06:00
imposterandClaude Opus 4.8 2613361e54 chore(clickgrab): full-page refresh to 2026-07-16 (volume, landscape, lure keywords)
Complete the living-document refresh on top of the Carson cradle rebuild:
- daily/volume: +3 MHaggis days (Jul 14-16) via analyze_clickgrab; total_sites_crawled
  26,969 -> 27,269, window now through 2026-07-16.
- carson_landscape refreshed to 3,774 (gist, Jul 16). total_domains held at the Carson
  XLSX set (3,777) -- analyze preserves it distinct from the landscape count, no clobber.
- clickfix_lure_keywords.yml regenerated from the updated MHaggis cache (IOK / URLScan
  page.body pivots; feeds IOK rules, not rendered on the trends page).

Frozen by design, not refreshed (DECISIONS #011): payload_examples (rich generator gone,
pre-Oct-2025 reports LFS-locked) and staging_domains (21 entries, all already
ASN-enriched; new infra is manual curation, and enrich_staging_domains is local-only).
Detection recs are all behavior/chokepoint-anchored and already cover the summer cradle
reversal (the cradle-agnostic rule caught msiexec and the PowerShell comeback), so no new
rule -- adding one would be false coverage.

Verified: jekyll builds clean (exit 0, full build ~341s), clickgrab page renders with the
refreshed data.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 19:41:11 -06:00
iimp0ster ee254bf6fb Merge pull request #165 from iimp0ster/iimp0ster/trusted-binary-dll-sideloading
Iimp0ster/trusted binary dll sideloading
2026-07-16 19:27:07 -06:00
imposter 804429d9d1 test: add DLL chokepoint regression gates 2026-07-16 19:12:18 -06:00
imposter e66139ed78 fix: complete DLL side-loading site preview 2026-07-16 19:10:08 -06:00
imposter 7b46bf56e6 feat: add trusted binary DLL side-loading chokepoint 2026-07-16 19:10:08 -06:00
imposterandClaude Opus 4.8 916885a169 feat(clickgrab): refresh cradle behaviour to the 2026-07-17 Carson export
Rebuild the clean per-domain command classification from the July 17 Carson
ClickFix Hunter export via build_domain_monthly.py (manual/local, not CI).
3,321 -> 3,777 domains; June completed (74 -> 424, the prior export only had
June through the 16th), July added. domain_monthly / domain_cradles_total /
domain_evasion_totals refreshed; payload_examples / daily / staging_domains
byte-preserved.

The trend this surfaces: the cradle mix rotated back to remote download cradles.
IWR is 28% of June domains and 36% of July, WebClient 15% then 24%, curl 33% in
July, while msiexec (the late-2025 story) fell to <=1% since May and 0% in July.
The spring inline-encoding wave (base64's one-month May campaign, hex-XOR heavy
Apr-May) faded to near-zero by July.

Completing June corrected two now-false hardcoded claims: hex-XOR did NOT climb
"back to 84% in June" -- that was the partial n=74 export; complete June is 16%
(69/424), declining to 0% July. Fixed both spots, extended the msiexec trajectory
through July, and added a callout for the summer remote-fetch reversal.

Verified: historical months (through May) byte-stable, cradle + evasion charts
screenshot-verified (June IWR resurgence and hex-XOR decline render correctly),
0 console errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 19:08:41 -06:00
iimp0ster bdcef0ebca Merge pull request #163 from iimp0ster/feat/edge-exploits-jul16-backfill
Backfill edge-exploits May 20-Jul 16 (CitrixBleed 2 surge); gap-render row-capped days
2026-07-16 18:17:26 -06:00
iimp0ster 532d42311e Merge pull request #156 from iimp0ster/data/clickgrab-auto
chore: update clickgrab trends data [2026-07-13]
2026-07-16 18:11:16 -06:00
iimp0ster 674a599733 Merge pull request #154 from iimp0ster/dependabot/github_actions/github-actions-c81c38844b
ci(deps): bump the github-actions group across 1 directory with 7 updates
2026-07-16 18:09:54 -06:00
iimp0ster 41312061c8 Merge pull request #135 from iimp0ster/dependabot/pip/pip-f69fb2051f
chore(deps): bump the pip group across 1 directory with 11 updates
2026-07-16 18:09:36 -06:00
iimp0ster 2010868330 Merge pull request #133 from iimp0ster/dependabot/npm_and_yarn/npm-4e38a52fea
chore(deps): bump js-yaml from 4.1.1 to 5.2.0 in the npm group across 1 directory
2026-07-16 18:09:15 -06:00
imposterandClaude Opus 4.8 2e45a13223 fix(trends): use AS handle when the provenance org label overflows
transform_provenance.py short() hard-truncated the AS org description at 28
chars, cutting mid-word -- the top provider read "Emil Vitukhnovskii trading
a". Fall back to the AS handle when the org would overflow, so the label reads
the recognizable "GreatFlower". Labels that already fit are unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 17:45:25 -06:00
imposterandClaude Opus 4.8 810f810d85 feat(trends): refresh edge-exploits hosting provenance to Jul 16
Regenerate _data/edge_exploits_provenance.yml for the Apr-Jul 2026 window
(was Jul 3), 2,998 cumulative unique source IPs.

The local enrich_asns.py had been raw-summing overlapping exports, inflating
June 6.6x (105,888 vs the correct 16,113) and floating one ASN (datacampus,
the truncated Jun 10 spike's host) into the top purely as a double-counting
artifact. Gave it the same per-day MAX-wins merge + Jun 10 gap + :port strip
as transform_defused_csv.py, so per-month ASN totals now match the event page
exactly (May 50,016 / Jun 16,113 / Jul 3,537).

enrich_asns.py / hll.py / bulletproof_asns.yml are gitignored, local-only
(they touch raw IPs + an optional key, decision #009); only the IP-free
aggregate yml is committed. Keyless Team Cymru only; IPinfo cross-check skipped.

Verified: per-month totals reconciled to the event page; provenance stacked
chart screenshot-verified (May dominant = GreatFlower, the CitrixBleed 2 surge host).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 17:29:15 -06:00
imposterandClaude Opus 4.8 6016b19c1b feat(trends): backfill edge-exploits May 20-Jul 16, gap-render capped days
Fill the May 20-Jun 9 hole (uploaded 46,209-row export) and extend the
edge-exploits page to Jul 16. Total 75,420 -> 88,299. The story is a
CitrixBleed 2 (CVE-2025-5777) surge: 62,205 hits (70% of all traffic),
peaking May 26 at 29,274 hits from a single source (193.202.84.145).

transform_defused_csv.py:
- day merge is now per-day MAX-wins, not newest-wins, so a newer export's
  partial window-start day can't overwrite an older complete count
  (fixed Jun 16: 10 -> true 139).
- a row-capped export's truncated oldest day renders as a GAP, not a
  partial bar (supersedes the 2026-07-03 partial flag). Jun 10 is the
  first such gap; a narrow uncapped re-export closes it automatically.
- strip the source :port newer exports append to Attacker IP, keeping
  unique-IP counts consistent across export formats (32,258 -> 2,988).
- CitrixBleed 2 daily series now spans the live window.

page: refreshed volume/target/CitrixBleed/Next.js/cPanel prose to the new
totals and the May 26 single-source surge; extended the CB2 chart to Jul 16;
dropped the now-dormant partial-day styling.

Verified: transform output cross-checked against an independent max-wins
re-derivation; page built under Jekyll, both charts screenshot-verified.

edge_exploits_provenance.yml (ASN section) not regenerated -- separate
IP->ASN pipeline, follow-up.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 16:47:39 -06:00
iimp0ster d8231f40b1 Merge pull request #162 from iimp0ster/fix/mobile-nav-pixel-icons
fix(nav): custom pixel section icons in mobile hamburger menu
2026-07-13 22:37:33 -06:00
iimp0ster ec360f042b Merge pull request #161 from iimp0ster/feat/pdf-sigma-variants
feat(sigma): supplementary detection variants from PDF deck (experimental)
2026-07-13 22:36:57 -06:00
imposterandClaude Fable 5 a235e6def0 fix(nav): use custom pixel section icons in mobile hamburger menu
The desktop nav shows the arcade pixel section icons (chokepoint,
attack-chain, trends, framework .png) next to each item, but the mobile
hamburger menu used generic hand-drawn SVG glyphs instead, breaking the
icon theme between desktop and mobile.

Swap the four section items' m-ic SVGs for the same pixel icons the
desktop nav uses; add a scoped .m-ic img rule (20px, image-rendering:
pixelated) so they stay crisp. Contribute keeps its glyph (it has no
section pixel icon on desktop either).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 22:31:32 -06:00
imposterandClaude Fable 5 e87f583a6a feat(sigma): add hunt tier pixel icon to supplementary variant badges
The supplementary variant cards showed a bare 'Hunt' badge while every
other rule card renders the tier's pixel icon (research/hunt/analyst.png)
inside the badge. All four supplementary variants are hunt-tier, so add
the hunt.png icon to match the established badge styling.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 22:28:20 -06:00
imposterandClaude Fable 5 676c42362a feat(sigma): supplementary detection variants from PDF deck (experimental)
Adds four experimental Sigma variants extracted from the Detection
Chokepoints slide deck, covering angles the existing repo rules do not.
All are status: experimental and render in a new guarded 'Supplementary
Variants' block on their chokepoint page (mirrors the hunt-network
precedent: additive, only renders where the file exists).

New rules:
- clickfix/hunt-registry.yml     ClickFix RunMRU/TypedPaths registry write
                                 (URL + lure keywords/LOLBins) - registry_set
- clickfix/hunt-downloadfix.yml  DownloadFix - browser-written :Zone.Identifier
                                 ADS on a fix/repair-themed filename. Credits
                                 mr.d0x (FileFix origin) and links jfmaes'
                                 DownloadFix PoC (github.com/jfmaes/downloadfix)
- renamed-rmm/hunt-signer.yml    Renamed RMM keyed on Authenticode Company
                                 signer (durable vs image-name). EXAMPLE A-C
                                 signer subset; full list from LOLRMM
- ransomware-service/hunt-process.yml  Direct taskkill of a named EDR *process*
                                 (vs the service-name rules). Sophos example

Plumbing (additive, cannot affect other pages):
- scripts/aggregate.py: register the four new basenames in SIGMA_LEVELS
- _layouts/chokepoint.html: guarded 'Supplementary Variants' block that
  inlines any present variant with GitHub/Download/Copy actions

Provenance: transcribed from Detection Chokepoints.pdf (rules were embedded
images). renamed-rmm signer list and ransomware process list are deliberate
illustrative subsets, documented inline. Detection-reviewer pass: 3 APPROVED,
downloadfix revised (dropped mismapped T1553.005). Rules are authored, NOT
capture-validated - experimental until telemetry confirms.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 19:48:22 -06:00
iimp0ster ff43b81470 Merge pull request #160 from iimp0ster/fix/osint-pivot-links
fix(osint): every pivot card links, and links execute the displayed query
2026-07-13 18:37:28 -06:00
iimp0ster 419393f12a Merge pull request #159 from iimp0ster/fix/arcade-font-selfhost
fix(theme): self-host arcade fonts, end heading color flash
2026-07-13 18:37:24 -06:00
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00
imposterandClaude Fable 5 899ca50455 fix(theme): self-host arcade fonts, end heading color flash
theme-arcade.css opened with a cross-origin @import to Google Fonts,
which delayed the whole overlay sheet: H1s painted white from
style.css first, then snapped orange when the arcade layer applied.
On slow or mobile connections both states were visible, reading as
inconsistent heading colors across pages.

- Self-host Press Start 2P + VT323 woff2 (OFL) under assets/fonts/,
  replace the @import with local @font-face blocks
- Preload the two latin subsets in the default layout head
- Drop the dead 'color: var(--text)' H1 declarations on the three
  trend pages (clickgrab, edge-exploits, masq-infra) that the
  overlay's !important was silently overriding; arcade orange is
  the confirmed canonical H1 treatment sitewide

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:28:11 -06:00
github-actions[bot] dd90b12a34 chore: update clickgrab trends data [2026-07-13] 2026-07-13 08:51:37 +00:00
iimp0ster e416c72d91 Merge pull request #155 from iimp0ster/chore/edge-exploits-refresh-2026-07-03
chore(trends): refresh edge-exploits from Jul 3 export, flag gap + row-cap day
2026-07-08 12:58:05 -06:00
imposterandClaude Sonnet 5 3ace655d55 chore(trends): refresh edge-exploits from Jul 3 export, flag gap + row-cap day
Merges the new Defused export (Jun 10 - Jul 3) into the accumulating
edge-exploits history: 25,420 -> 75,420 events. CitrixBleed 2 (CVE-2025-5777)
exploitation jumped 11,145 -> 56,338 hits, NetScaler now >90% of decoy traffic.

transform_defused_csv.py now detects two conditions automatically instead of
relying on hardcoded date constants:
- Gap days: no export covers May 20 - Jun 9, 2026 (21 days), rendered as a
  visible gap on the page.
- Row-cap truncation: this export hit a suspected 50,000-row console cap
  (unverified exact limit) with a clean mid-record cutoff on its oldest day,
  Jun 10 -- flagged partial (undercounts) rather than dropped or trusted as-is.

index.html's gap/volume text is now Liquid-bound to meta.date_range_note and
meta.live_decoy_count instead of hardcoded, so it won't go stale on the next
refresh. The daily chart distinguishes row-cap-partial days from the existing
export-cutoff artifact day.

--check-seed passes clean against the original seed data.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011suj1d1CVCVeJDtgPKrMzi
2026-07-03 13:58:31 -06:00
dependabot[bot] 82835b868e chore(deps): bump the pip group across 1 directory with 11 updates
Updates the requirements on [anthropic](https://github.com/anthropics/anthropic-sdk-python), [requests](https://github.com/psf/requests), [pyyaml](https://github.com/yaml/pyyaml), [mmh3](https://github.com/hajimes/mmh3), [python-dateutil](https://github.com/dateutil/dateutil), [python-dotenv](https://github.com/theskumar/python-dotenv), [httpx](https://github.com/encode/httpx), [tldextract](https://github.com/john-kurkowski/tldextract), [streamlit](https://github.com/streamlit/streamlit), [pandas](https://github.com/pandas-dev/pandas) and [plotly](https://github.com/plotly/plotly.py) to permit the latest version.

Updates `anthropic` to 0.115.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-python/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/anthropics/anthropic-sdk-python/compare/v0.40.0...v0.115.1)

Updates `requests` to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.31.0...v2.34.2)

Updates `pyyaml` to 6.0.3
- [Release notes](https://github.com/yaml/pyyaml/releases)
- [Changelog](https://github.com/yaml/pyyaml/blob/6.0.3/CHANGES)
- [Commits](https://github.com/yaml/pyyaml/compare/6.0...6.0.3)

Updates `mmh3` to 5.2.1
- [Release notes](https://github.com/hajimes/mmh3/releases)
- [Changelog](https://github.com/hajimes/mmh3/blob/master/CHANGELOG.md)
- [Commits](https://github.com/hajimes/mmh3/compare/v4.1.0...v5.2.1)

Updates `python-dateutil` to 2.9.0.post0
- [Release notes](https://github.com/dateutil/dateutil/releases)
- [Changelog](https://github.com/dateutil/dateutil/blob/master/NEWS)
- [Commits](https://github.com/dateutil/dateutil/compare/2.8.0...2.9.0.post0)

Updates `python-dotenv` to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.0.0...v1.2.2)

Updates `httpx` to 0.28.1
- [Release notes](https://github.com/encode/httpx/releases)
- [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md)
- [Commits](https://github.com/encode/httpx/compare/0.27.0...0.28.1)

Updates `tldextract` to 5.3.1
- [Release notes](https://github.com/john-kurkowski/tldextract/releases)
- [Changelog](https://github.com/john-kurkowski/tldextract/blob/master/CHANGELOG.md)
- [Commits](https://github.com/john-kurkowski/tldextract/compare/5.0.0...5.3.1)

Updates `streamlit` to 1.58.0
- [Release notes](https://github.com/streamlit/streamlit/releases)
- [Commits](https://github.com/streamlit/streamlit/compare/1.35.0...1.58.0)

Updates `pandas` to 3.0.3
- [Release notes](https://github.com/pandas-dev/pandas/releases)
- [Commits](https://github.com/pandas-dev/pandas/compare/v2.2.0...v3.0.3)

Updates `plotly` to 6.8.0
- [Release notes](https://github.com/plotly/plotly.py/releases)
- [Changelog](https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md)
- [Commits](https://github.com/plotly/plotly.py/compare/v5.22.0...v6.8.0)

---
updated-dependencies:
- dependency-name: anthropic
  dependency-version: 0.109.1
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: httpx
  dependency-version: 0.28.1
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: mmh3
  dependency-version: 5.2.1
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: pandas
  dependency-version: 3.0.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: plotly
  dependency-version: 6.8.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: python-dateutil
  dependency-version: 2.9.0.post0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: python-dotenv
  dependency-version: 1.2.2
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: pyyaml
  dependency-version: 6.0.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: streamlit
  dependency-version: 1.58.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: tldextract
  dependency-version: 5.3.1
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 23:49:00 +00:00
dependabot[bot] 19e1c99c89 ci(deps): bump the github-actions group across 1 directory with 7 updates
Bumps the github-actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.3.1` | `7.0.0` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `6.3.0` |
| [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.313.0` | `1.315.0` |
| [actions/configure-pages](https://github.com/actions/configure-pages) | `5.0.0` | `6.0.0` |
| [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) | `3.0.1` | `5.0.0` |
| [actions/deploy-pages](https://github.com/actions/deploy-pages) | `4.0.5` | `5.0.0` |
| [actions/cache](https://github.com/actions/cache) | `4.3.0` | `6.1.0` |



Updates `actions/checkout` from 4.3.1 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/34e114876b0b11c390a56381ad16ebd13914f8d5...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

Updates `actions/setup-python` from 5.6.0 to 6.3.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/a26af69be951a213d495a4c3e4e4022e16d87065...ece7cb06caefa5fff74198d8649806c4678c61a1)

Updates `ruby/setup-ruby` from 1.313.0 to 1.315.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](https://github.com/ruby/setup-ruby/compare/89f90524b88a01fe6e0b732220432cc6142926af...0dafeac902942906541bc140009cdbf32665b601)

Updates `actions/configure-pages` from 5.0.0 to 6.0.0
- [Release notes](https://github.com/actions/configure-pages/releases)
- [Commits](https://github.com/actions/configure-pages/compare/983d7736d9b0ae728b81ab479565c72886d7745b...45bfe0192ca1faeb007ade9deae92b16b8254a0d)

Updates `actions/upload-pages-artifact` from 3.0.1 to 5.0.0
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](https://github.com/actions/upload-pages-artifact/compare/56afc609e74202658d3ffba0e8f6dda462b719fa...fc324d3547104276b827a68afc52ff2a11cc49c9)

Updates `actions/deploy-pages` from 4.0.5 to 5.0.0
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](https://github.com/actions/deploy-pages/compare/d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e...cd2ce8fcbc39b97be8ca5fce6e763baed58fa128)

Updates `actions/cache` from 4.3.0 to 6.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/0057852bfaa89a56745cba8c7296529d2fc39830...55cc8345863c7cc4c66a329aec7e433d2d1c52a9)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: ruby/setup-ruby
  dependency-version: 1.315.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/configure-pages
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/upload-pages-artifact
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 23:48:02 +00:00
dependabot[bot] 049cd8e482 chore(deps): bump js-yaml in the npm group across 1 directory
Bumps the npm group with 1 update in the / directory: [js-yaml](https://github.com/nodeca/js-yaml).


Updates `js-yaml` from 4.1.1 to 5.2.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...5.2.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 23:47:47 +00:00
iimp0ster 3853e3c041 Merge pull request #153 from iimp0ster/feat/og-preview-cards
feat(social): per-section link-preview cards (chokepoints / attack-chains / trends)
2026-07-01 10:28:58 -06:00
imposterandClaude Opus 4.8 7e9bd97379 feat(social): per-section link-preview cards for chokepoints, attack-chains, trends
A shared link now signals what it is — a new chokepoint, attack chain, or trends
entry — instead of the generic site card. Home and generic pages keep og.png.

- templates/og-card.html: HTML card template (build tool, excluded from site),
  rendered at 1200x630 with Press Start 2P / VT323 + the section pixel icon.
- assets/img/social/og-{chokepoints,attack-chains,trends}.png: the three cards.
- assets/img/pixel/trends.png: stripped the baked-in U-frame so the wave icon
  floats like the other nav icons.
- _config.yml: scoped jekyll-seo-tag defaults (chokepoints collection /
  attack-chains / trends); site-wide default unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-07-01 10:13:15 -06:00
iimp0ster b04b752382 Merge pull request #152 from iimp0ster/feat/attack-chain-convergence-viz
feat(attack-chains): convergence highlight + matrix row-mirror on actor select
2026-06-29 12:46:53 -06:00
iimp0ster 468988f597 Merge pull request #151 from iimp0ster/data/clickgrab-auto
chore: update clickgrab trends data [2026-06-29]
2026-06-29 12:44:26 -06:00
imposterandClaude Opus 4.8 fd3dae2a02 feat(attack-chains): convergence highlight + matrix row-mirror on actor select
Selecting 2+ actors on any attack-chain page now highlights the techniques they
all share in cyan (.state-converge) and fades single-actor cells (.state-partial),
so the convergence reads without inspecting per-actor dots. The same selection
mirrors onto the convergence matrix: selected actors' rows light in their own
colour, the rest dim, and the chokepoint (tfoot) invariant row stays fixed.
Legend hint updated to describe the cyan glow.

Verified on the ransomware page (Akira+Play = 19 shared cyan cells) at 1440 and
375 breakpoints, 0 console errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-06-29 12:04:25 -06:00
github-actions[bot] b3d19ec21a chore: update clickgrab trends data [2026-06-29] 2026-06-29 10:24:57 +00:00
iimp0ster 8319ceee31 Merge pull request #150 from iimp0ster/claude/clickgrab-conflicts-gh-actions-ytum2y
ci(clickgrab): weekly cadence + single rolling PR (stop the daily PR pileup)
2026-06-21 12:55:25 -06:00
iimp0ster 4017e54ead Merge pull request #149 from iimp0ster/data/clickgrab-2026-06-21
chore: update clickgrab trends data [2026-06-21]
2026-06-21 12:54:46 -06:00
github-actions[bot] 974ec6accd chore: update clickgrab trends data [2026-06-21] 2026-06-21 09:43:37 +00:00
Claude a0bb7bdddb ci(clickgrab): weekly cadence + single rolling PR
The daily cron cut a fresh dated branch (data/clickgrab-${DATE}) and opened
a new PR every run. Since each PR edits the tail + meta of the same growing
_data/clickgrab_trends.yml, they mutually conflict the moment one merges,
leaving a pileup of stuck PRs (#146/#147/#148).

Fixes the structure rather than the symptom:
- Publish to a fixed rolling branch (data/clickgrab-auto), force-pushed each
  run and refreshed via `gh pr edit`, so at most one ClickGrab PR is ever
  open and it always shows a clean append-only diff vs main.
- Drop cadence from daily to weekly (Mondays 06:00 UTC). The generator's
  14-day lookback + watermark dedup backfills every daily bucket regardless,
  so weekly captures the same data with far less churn.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YQzGNdzZK4svMZPTK9BikA
2026-06-21 04:20:55 +00:00
iimp0ster 5ec3a0d076 Merge pull request #145 from iimp0ster/data/clickgrab-2026-06-17
chore: update clickgrab trends data [2026-06-17]
2026-06-18 21:06:08 -06:00
github-actions[bot] 12fd998c56 chore: update clickgrab trends data [2026-06-17] 2026-06-17 10:47:50 +00:00
iimp0ster 39d56051b6 Merge pull request #144 from iimp0ster/feat/clickgrab-consolidated-source
ClickFix trends: re-source ingest + clean Carson three-feed model + classifier fix
2026-06-16 13:34:18 -06:00
iimp0ster a1ddcb7c78 Merge pull request #143 from iimp0ster/feat/edge-exploits-provenance
feat(trends): hosting-provenance section for edge-exploits
2026-06-16 13:34:01 -06:00