23 Commits
Author SHA1 Message Date
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00
imposterandClaude Opus 4.8 f93cd02398 feat(magicsword): prevention integration + transparent logo
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Sonnet 4.6 04e84dbab8 feat(site): weekly chokepoint updates and site improvements
Update 9 published chokepoints with accuracy fixes and variant additions.
Update layouts, attack chains, trends pages, and framework content.

Note: _config.yml, _includes/nav.html, assets/css/style.css, and index.html
contain in-progress MagicSword affiliate integration -- held back from this PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:33 -06:00
imposterandClaude Opus 4.6 6c61955380 refactor(chokepoints): tighten Detection Logic prose and layout cleanup
- Condense Logic fields across 8 chokepoint pages (22 blocks total) from pseudocode-style WHERE/AND/OR constructs into plain-language 1-3 sentence descriptions matching the clickfix reference pattern. Technical specificity preserved (event IDs, access masks, paths, thresholds).
- LSASS page: align structure with clickfix template (remove redundant AttackerControls/AttackerCannotControl blocks, reformat RawLogs samples to match clickfix style with Key signal comments, add URL fields to OSINT pivots so queries are clickable)
- Layout: remove tier badges from chokepoint stage headers and raw log sample cards so badges only appear on Sigma rule examples where they add context. Switch detection logic block from white-space:pre to pre-wrap with word-break so long rules wrap instead of hiding under the horizontal scrollbar.
- Remove remaining em dashes from chokepoint layout intro copy ("Each stage is an invariant condition...", "Tools and methods that exploit this chokepoint...")

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:56:12 -06:00
imposter ce0c0b8311 feat(03-01): add copy-button .copied CSS state and tier accent left-border CSS
- Add .sigma-block--research/hunt/analyst with 4px left border accent (UX-02)
- Add .sigma-btn.copied rule with green color and border feedback (UX-01)
- Update copyCode() to toggle .copied class on click and remove after 1.8s (UX-01)
2026-04-12 08:33:32 -06:00
imposter 7f76a6895c refactor(02-01): voice tighten Description fields and remove remaining em dashes
- browser-credential-theft.yml: rewrite Description to lead with invariant (target paths), break stat dump into short sentences; fix em dashes in Invocation and References Name fields
- web-shells.yml: rewrite Description to open with mechanism ("A script lives in the web root"); fix em dashes in Invocation code comments, detection logic, and References Name fields
- renamed-rmm-tools.yml: rewrite Description to drop passive opener, state 4-step invariant concisely; fix em dashes in Invocation code comments, Sources list items, and References Name fields
- byosi-scripting-interpreters.yml: rewrite Description to drop "Adversaries bring" opener, lead with vendor-signed interpreter pattern; fix em dashes in References Name fields
- ransomware-service-manipulation.yml: rewrite Description to drop "This service manipulation phase" opener, tighten to five short sentences; fix em dash in Invocation code comment; preserve Windows Event Log quoted strings (Service State Change, Service Start Type Changed)
2026-04-11 19:40:06 -06:00
imposterandClaude Opus 4.6 d54c031940 refactor: clean up writing style across all chokepoint pages
Remove em dashes from prose throughout all 7 remaining chokepoints,
replacing with periods, commas, or semicolons for tighter writing.
Remove AttackerControls/AttackerCannotControl bulleted lists (redundant
with chokepoint stage descriptions). Intel reference names preserved.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 14:57:48 -06:00
imposterandClaude Opus 4.6 8ea94fa7a2 feat: complete site redesign — framework section, stage-grouped detections, variant command blocks, accuracy fixes
Landing page:
- Add Graeber chokepoint framework section with 6-step grid
- Add collapsible badge guide with all 9 badge types
- Framework section is collapsible for returning visitors

Chokepoint page template:
- Redesign Attack Chokepoints to Input/Chokepoint/Observable format
- Add controls-vs-constants table (AttackerControls/AttackerCannotControl)
- Add pill-shaped flow connectors between stages
- Add "Why unavoidable" callouts (red border)
- Add expandable True Positive examples (green header)
- Add Command/Artifact blocks for post-compromise variants
- Add Lure/Payload sections for initial-access variants
- Replace tab-based Detection Strategy with stage-grouped layout
- Add sticky sidebar navigation with scroll spy
- Add "Learn the framework" back-reference link

All 8 chokepoint pages populated:
- ClickFix: 9 variants with lures, payloads, chokepoint mappings
- EDR Bypass: 14 variants with command/artifact blocks
- Ransomware: 5 variants with service stop commands
- Web Shells: 11 variants with shell deployment commands
- Browser Credential Theft: 12 variants with stealer chains
- BYOSI: 8 variants with interpreter deployment commands
- Remote Execution: 7 variants with tool invocations
- Renamed RMM: 9 variants with masquerade patterns

Sigma rules (26 rules across 8 chokepoints):
- Fix invalid UUIDs (5 rules with non-hex characters)
- Fix invalid modifiers (|contains|any, |re:, |not|endswith)
- Add filter_legit_software blocks to all rules
- Trim verbose descriptions to 1-3 sentences
- Fix misleading titles (remote-exec research, web-shells hunt)
- New: hunt-network.yml for ClickFix Stage 3

Accuracy fixes from comprehensive review:
- Fix swapped SigmaRef cross-references (ClickFix Stages 2/3)
- Fix T1204.003→T1204.004 in ClickFix analyst rule
- Fix POORTRY FirstSeen (2024-Q1→2022-Q4)
- Fix invalid variant Status values (Inactive→Legacy, etc.)
- Fix fabricated Sysmon EID 10 raw log in Browser Theft
- Broaden EDR Bypass Stage 2 invariant for userland variants
- Broaden Web Shell/BYOSI invariants for in-memory variants
- Fix AnyDesk breach date (January→February 2024)
- Fix CrackMapExec commands (nxc→cme)
- Add 37 missing SourceURLs, fix 5 broken URLs
- Fix all URLScan OSINT queries (remove wildcards/parens)

Attack chains landing page:
- Add "Why Map Attack Chains?" convergence principle section
- Add cross-chain ecosystem flow diagram
- Add "How to read an attack chain" collapsible guide

Contributor resources:
- Rewrite chokepoint template with Graeber framework attribution
- Update FRAMEWORK.md with 6-step methodology
- Update CONTRIBUTING.md with new required fields

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 16:09:16 -06:00
iimp0ster 8f1081fbfe feat: combine Variations and Evolution Timeline into unified interactive section
- Merge variant cards and evolution timeline into single chronological view
- Add click-to-filter: chip selection highlights related timeline entries
- Add per-variant intel links for analyst pivoting to threat reports
- Add variant chip strip for quick scanning of all variants with status
- Add TheConstant box showing the invariant detection anchor
- Update all 7 chokepoint YAML files with VariantId and EventType fields
- Update chokepoint layout template with combined section and filtering JS
- Add new CSS for combined timeline, chips, filtering states, and intel links
2026-03-28 16:21:32 +00:00
Claude fb1171be45 Commit 5: Trim Intel Resources to foundational-only (per-chokepoint judgment)
YAML: Removed variant-specific, single-incident, secondary, and annual
report entries from all 7 chokepoint Intel sections. Migrated variant-
specific sources to SourceURL on variation cards (Commit 3). Added
Tier: primary to entries that lacked the field. No Tier: supporting entries
remain in any chokepoint file.

Entry counts after trim:
  clickfix:             18 → 9
  renamed-rmm:           7 → 4
  edr-bypass:           10 → 4  (Tier field added to all kept entries)
  ransomware-svc:        8 → 3
  browser-credential:    9 → 5  (Tier field added to all kept entries)
  web-shells:           10 → 5  (Tier field added to all kept entries)
  remote-execution:      9 → 7

Layout: Replaced tiered Intel rendering (primary card grid + supporting
collapsible toggle) with a uniform flat link list — title (link) + one
sentence description. Removed intel-card, intel-grid, intel-card-name,
intel-card-desc, intel-linked, intel-link-tag, intel-supporting-toggle CSS.
Removed intel-supporting-toggle JS event handler.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:50:00 +00:00
Claude cdcba301a3 Commit 3: Add SourceURL to variation cards
YAML: Added SourceURL to top-level Variations entries across all 7
chokepoint files (24 total). One authoritative primary source per variant;
omitted field where no clear primary source exists. No SourceURL added to
nested structures (MasqueradeThemes in renamed-rmm-tools).

Layout: Added .variant-source-link CSS class (small monospace text, subtle
accent border, hover underline — matches chain-sigma-link pattern). Added
{% if v.SourceURL %} footer block to var-card template rendering
"Source →" link at the bottom of each variation card.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:45:53 +00:00
Claude d2032a3540 Commit 2: Revert to 3 chokepoint stages per chokepoint (per-chokepoint judgment)
clickfix: merge Lure Page Delivery + Clipboard Seeding into Lure/Delivery
  (Research); rename User Execution → Execution (Hunt); rename Outbound
  Network Connection → Second Stage Retrieval (Analyst). Clipboard ETW
  content folded into merged stage LogSources and BypassNote.

renamed-rmm: drop Payload Hosting stage; fold hosting/reachability
  invariant into Browser Download WhyCantBypass. Result: Browser Download
  (Research) → User Execution (Hunt) → Outbound RMM Connection (Analyst).

ransomware-service-manipulation: drop Privilege Verification stage; fold
  Admin/SYSTEM privilege requirement into Service Enumeration WhyCantBypass.
  Result: Service Enumeration (Research) → Service Stop and Disable (Hunt)
  → Service Deletion (Analyst).

remote-execution-tools: drop Network Access stage; fold protocol-port
  reachability requirement into Remote Execution Primitive WhyCantBypass.
  Result: Credential Acquisition (Research) → Remote Execution Primitive
  (Analyst) → Lateral Spread (Hunt).

edr-bypass, browser-credential-theft, web-shells: no Chokepoints section
  exists in these files — left as-is per "fewer than 3 stages" rule.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:41:37 +00:00
imposterandClaude Sonnet 4.6 d4d9287791 Commit 5: Move hunt.io entries to Intel Resources; trim OSINT Notes to one sentence
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 15:51:50 -06:00
imposterandClaude Sonnet 4.6 281d33b261 Commit 4: Tiered Intel Resources — primary cards, supporting collapsed list
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 15:46:10 -06:00
imposterandClaude Sonnet 4.6 2014a9d613 Commit 2: Collapse timeline by default; strip TheConstant; trim Change to one sentence
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:36:14 -06:00
imposterandClaude Sonnet 4.6 d9b462a632 Commit 1: Replace Variations table with card grid; add NotesShort field
Added NotesShort (<=20 words) before Notes on every Variation entry across
all 4 chokepoint YAML files. Replaced the Variations HTML table in
chokepoint.html with a 2-col card grid showing Name, FirstSeen, Status badge,
and NotesShort by default; full Notes revealed via inline More/Less toggle.
Added corresponding CSS and expand/collapse JS.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:32:25 -06:00
imposterandClaude Sonnet 4.6 87ff0d7957 Commit 0: Add per-stage Detection Chain to all chokepoint pages
Adds a new `Chokepoints:` YAML block to all four chokepoint entries
(ClickFix, Renamed RMM Tools, Ransomware Service Manipulation, Remote
Execution Tools), each with Stage, Invariant, WhyCantBypass, LogSources,
DetectionTier, SigmaRef, and optional BypassNote fields per attack stage.

Layout: replaces the flat Prerequisites section with a trimmed
environmental-precondition list, then adds a new collapsible Detection
Chain section — numbered stage bubbles, tier badges (Research/Hunt/Analyst)
with urgency subtitles (Baseline / Active Hunt / SOC Alert), segmented
connector lines, and a red BypassNote callout on affected stages.

Schema and template updated with Chokepoints block definition.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:18:59 -06:00
imposter 6852574bcb new trends section 2026-03-14 20:57:39 -06:00
imposterandClaude Sonnet 4.6 4a836cfa0d feat(detection-tests): add raw log samples and emulation scripts for all chokepoints
Adds RawLogs and EmulationScript fields to all 6 remaining chokepoints and
creates PowerShell emulation scripts that generate real Sysmon/WEL telemetry
for detection validation without requiring live malware.

Chokepoints covered:
- clickfix-techniques: 3 log samples (Sysmon EID 1/3/22), VBScript→PowerShell shim
- renamed-rmm-tools: 3 log samples (Sysmon EID 11/1/3), binary rename + metadata mismatch
- edr-bypass-techniques: 4 log samples (Sysmon EID 6/10, WEL 7036/7040), process handle + service stop
- ransomware-service-manipulation: 5 log samples (Sysmon EID 1, WEL 7036/7040), bulk service kill pattern
- remote-execution-tools: 4 log samples (WEL 4624/5145/7045, Sysmon EID 1), IPC$+random service pattern
- web-shells: 4 log samples (Sysmon EID 11/1/3), w3wp.exe→cmd.exe parent chain

Each emulation script:
- Generates authentic Sysmon/WEL telemetry matching Research/Hunt/Analyst rule logic
- Documents exactly which sigma rule tier each step triggers
- Is safe for isolated lab use (no real malware, no credentials exfiltrated)
- Includes cleanup, verbose mode, and selective skip flags

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-08 20:42:32 -06:00
Claude c690e8ad0f fix(osint): improve OsintSources across all remaining chokepoint files
Applied the same methodology used for clickfix-techniques.yml to evaluate
and improve the OsintSources blocks in all five remaining chokepoint files.

renamed-rmm-tools.yml (moderate):
- Expanded URLScan filename query with support*.exe and verify*.exe pretexts
- Updated Shodan note to also cover SimpleHelp (CISA AA25-163A, June 2025)
- Replaced Censys AnyDesk cert query with SimpleHelp (AnyDesk certs were
  revoked after the Feb 2024 breach, making that query largely historical)
- Added VT Intelligence PE metadata query for renamed RMM binaries in the wild
- Added LOLRMM.io — the community catalog of RMM tool file/network indicators

remote-execution-tools.yml (significant):
- Removed port:445 country:US — returns millions of results with zero
  signal for hunting attack infrastructure; was an exposure audit query,
  not a threat hunting query
- Repositioned WinRM query with clearer notes about its scope (exposure
  audit, not attacker infra hunting)
- Added Shodan JARM fingerprint query for Cobalt Strike team servers —
  the correct approach for hunting C2 infra paired with Impacket/NetExec
- Added hunt.io for real-time C2 infrastructure mapping

ransomware-service-manipulation.yml (minor):
- Fixed ANY.RUN URL from general trends page to the actual public
  submissions feed with ransomware filter
- Added Ransomware.live for real-time ransomware group activity tracking
- VT Intelligence and GitHub queries were solid; kept as-is

web-shells.yml (minor):
- Expanded Shodan title query with FilesMan and Antak Webshell
- Expanded URLScan filename query with webshell.php and cmd.aspx
- Added Censys eval(base64_decode) query for live obfuscated PHP shells
- VT Intelligence tag:webshell query was the strongest in any file; kept

edr-bypass-techniques.yml (minor):
- Added LOLDrivers (loldrivers.io) — the canonical community catalog of
  vulnerable and malicious drivers used in BYOVD attacks; was absent
  entirely despite being the most important resource for this chokepoint
- All three existing queries were solid; kept as-is

https://claude.ai/code/session_01CeEB6yuJimygkCBi7ubSh3
2026-03-08 15:45:59 +00:00
imposterandClaude Sonnet 4.6 d312295365 Fix YAML scanner errors: quote Name values containing colons
Five Name fields containing ": " were parsed as YAML mapping separators.
Wrapped affected values in double-quotes across three chokepoint files.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-07 16:28:26 -07:00
imposter 78ca6afc24 updated chokepoints with accurate data 2026-03-07 16:09:31 -07:00
Claude 39b5437ecd Restructure repo to LOLBAS-style: YAML chokepoints, real sigma rules, new nav
## What changed

### Structure
- Converted 4 chokepoints from freeform markdown to structured YAML under
  chokepoints/<tactic>/ with standardized schema (schema/chokepoint-schema.yml)
- Added 12 Sigma rules (Research/Hunt/Analyst) for all 4 chokepoints under
  sigma-rules/<technique>/
- Moved attack chains to attack-chains/, trends to trends/, templates to templates/
- Added CONTRIBUTING.md modeled after LOLBAS contribution guide

### Slide-to-repo gaps addressed
- README.md: Added military chokepoint hook (Thermopylae, Fulda Gap),
  thesis statement "TTPs evolve. Chokepoints don't.", chokepoint index table
  with Priority/Prevalence/Difficulty ratings, RaaS TTR compression context
- intel/clickgrab.md: Documented ClickGrab (was referenced in slides/references
  but not in the repo); includes hunt query examples and integration guidance
- HackTools/remote-execution: Completed all 3 sigma rule levels
  (slides showed only a placeholder)
- Source citations: Added HudsonRock, RedCanary, Cyberint, Mandiant M-Trends 2025
  attributions throughout

### New files
CONTRIBUTING.md, schema/chokepoint-schema.yml, intel/clickgrab.md,
templates/chokepoint-template.yml, 12 Sigma rule files,
attack-chains/ransomware.md, attack-chains/infostealers.md,
trends/2025-q1.md, trends/chokepoint-shifts.md

https://claude.ai/code/session_01LWLhVRq5vYHXiDKn86PXhr
2026-02-28 23:24:10 +00:00