25 Commits
Author SHA1 Message Date
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00
imposterandClaude Opus 4.8 f93cd02398 feat(magicsword): prevention integration + transparent logo
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Sonnet 4.6 04e84dbab8 feat(site): weekly chokepoint updates and site improvements
Update 9 published chokepoints with accuracy fixes and variant additions.
Update layouts, attack chains, trends pages, and framework content.

Note: _config.yml, _includes/nav.html, assets/css/style.css, and index.html
contain in-progress MagicSword affiliate integration -- held back from this PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:33 -06:00
imposterandClaude Opus 4.6 6c61955380 refactor(chokepoints): tighten Detection Logic prose and layout cleanup
- Condense Logic fields across 8 chokepoint pages (22 blocks total) from pseudocode-style WHERE/AND/OR constructs into plain-language 1-3 sentence descriptions matching the clickfix reference pattern. Technical specificity preserved (event IDs, access masks, paths, thresholds).
- LSASS page: align structure with clickfix template (remove redundant AttackerControls/AttackerCannotControl blocks, reformat RawLogs samples to match clickfix style with Key signal comments, add URL fields to OSINT pivots so queries are clickable)
- Layout: remove tier badges from chokepoint stage headers and raw log sample cards so badges only appear on Sigma rule examples where they add context. Switch detection logic block from white-space:pre to pre-wrap with word-break so long rules wrap instead of hiding under the horizontal scrollbar.
- Remove remaining em dashes from chokepoint layout intro copy ("Each stage is an invariant condition...", "Tools and methods that exploit this chokepoint...")

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:56:12 -06:00
imposter 4bbb840ef4 feat(04-01): create pipeline_utils.py with behavioral confidence scoring
- confidence_label maps 0-100 score to confirmed/high/medium/low
- rescore_record uses behavioral signals (chain_observed 40pts, multi_source 20pts)
- SHA-256 presence drops from 30pts to 5pts (structural, not behavioral)
- Feed membership scores 0pts (not behavioral per PIPE-02)
- Single source of truth for scoring logic across all pipeline scripts
2026-04-12 10:47:12 -06:00
imposter d3b7c418a6 fix(03-gap): restore Phase 1 Liquid fix and Phase 2 _config.yml em dash lost in merge 2026-04-12 10:18:58 -06:00
imposter ce0c0b8311 feat(03-01): add copy-button .copied CSS state and tier accent left-border CSS
- Add .sigma-block--research/hunt/analyst with 4px left border accent (UX-02)
- Add .sigma-btn.copied rule with green color and border feedback (UX-01)
- Update copyCode() to toggle .copied class on click and remove after 1.8s (UX-01)
2026-04-12 08:33:32 -06:00
imposter 5756319e51 fix(02-gap): voice-tighten edr-bypass and remote-execution descriptions; fix _config.yml em dash 2026-04-11 22:33:46 -06:00
imposter 02d545e7f2 refactor(02-01): remove prose em dashes from YAML and Markdown files
- clickfix-techniques.yml: fix 10 em dashes in Notes, Detections, and References Name fields; cut weak closer from Description; quote YAML Name values with colons
- edr-bypass-techniques.yml: fix 7 em dashes in Context and References/Variation Name fields; quote YAML Name values with colons
- remote-execution-tools.yml: fix 5 em dashes in References Name fields; quote YAML Name values
- trends/clickgrab.md: fix 15 em dashes in titles, prose paragraphs, and callouts; preserve Liquid empty-cell placeholders
- trends/index.md: fix 5 em dashes in hero text, pillar descriptions, and front matter description
- trends/masq-infra.md: fix 5 em dashes in front matter, methodology, and chokepoints prose; preserve 7 Liquid table placeholder instances
2026-04-11 18:58:02 -06:00
imposterandClaude Opus 4.6 77b60bc52c fix: quote YAML value containing colon in remote-execution-tools
Unquoted colon in Invariant field caused yaml.scanner.ScannerError
in aggregate.py CI step.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 15:08:21 -06:00
imposterandClaude Opus 4.6 d54c031940 refactor: clean up writing style across all chokepoint pages
Remove em dashes from prose throughout all 7 remaining chokepoints,
replacing with periods, commas, or semicolons for tighter writing.
Remove AttackerControls/AttackerCannotControl bulleted lists (redundant
with chokepoint stage descriptions). Intel reference names preserved.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 14:57:48 -06:00
imposterandClaude Opus 4.6 8ea94fa7a2 feat: complete site redesign — framework section, stage-grouped detections, variant command blocks, accuracy fixes
Landing page:
- Add Graeber chokepoint framework section with 6-step grid
- Add collapsible badge guide with all 9 badge types
- Framework section is collapsible for returning visitors

Chokepoint page template:
- Redesign Attack Chokepoints to Input/Chokepoint/Observable format
- Add controls-vs-constants table (AttackerControls/AttackerCannotControl)
- Add pill-shaped flow connectors between stages
- Add "Why unavoidable" callouts (red border)
- Add expandable True Positive examples (green header)
- Add Command/Artifact blocks for post-compromise variants
- Add Lure/Payload sections for initial-access variants
- Replace tab-based Detection Strategy with stage-grouped layout
- Add sticky sidebar navigation with scroll spy
- Add "Learn the framework" back-reference link

All 8 chokepoint pages populated:
- ClickFix: 9 variants with lures, payloads, chokepoint mappings
- EDR Bypass: 14 variants with command/artifact blocks
- Ransomware: 5 variants with service stop commands
- Web Shells: 11 variants with shell deployment commands
- Browser Credential Theft: 12 variants with stealer chains
- BYOSI: 8 variants with interpreter deployment commands
- Remote Execution: 7 variants with tool invocations
- Renamed RMM: 9 variants with masquerade patterns

Sigma rules (26 rules across 8 chokepoints):
- Fix invalid UUIDs (5 rules with non-hex characters)
- Fix invalid modifiers (|contains|any, |re:, |not|endswith)
- Add filter_legit_software blocks to all rules
- Trim verbose descriptions to 1-3 sentences
- Fix misleading titles (remote-exec research, web-shells hunt)
- New: hunt-network.yml for ClickFix Stage 3

Accuracy fixes from comprehensive review:
- Fix swapped SigmaRef cross-references (ClickFix Stages 2/3)
- Fix T1204.003→T1204.004 in ClickFix analyst rule
- Fix POORTRY FirstSeen (2024-Q1→2022-Q4)
- Fix invalid variant Status values (Inactive→Legacy, etc.)
- Fix fabricated Sysmon EID 10 raw log in Browser Theft
- Broaden EDR Bypass Stage 2 invariant for userland variants
- Broaden Web Shell/BYOSI invariants for in-memory variants
- Fix AnyDesk breach date (January→February 2024)
- Fix CrackMapExec commands (nxc→cme)
- Add 37 missing SourceURLs, fix 5 broken URLs
- Fix all URLScan OSINT queries (remove wildcards/parens)

Attack chains landing page:
- Add "Why Map Attack Chains?" convergence principle section
- Add cross-chain ecosystem flow diagram
- Add "How to read an attack chain" collapsible guide

Contributor resources:
- Rewrite chokepoint template with Graeber framework attribution
- Update FRAMEWORK.md with 6-step methodology
- Update CONTRIBUTING.md with new required fields

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 16:09:16 -06:00
iimp0ster 8f1081fbfe feat: combine Variations and Evolution Timeline into unified interactive section
- Merge variant cards and evolution timeline into single chronological view
- Add click-to-filter: chip selection highlights related timeline entries
- Add per-variant intel links for analyst pivoting to threat reports
- Add variant chip strip for quick scanning of all variants with status
- Add TheConstant box showing the invariant detection anchor
- Update all 7 chokepoint YAML files with VariantId and EventType fields
- Update chokepoint layout template with combined section and filtering JS
- Add new CSS for combined timeline, chips, filtering states, and intel links
2026-03-28 16:21:32 +00:00
Claude fb1171be45 Commit 5: Trim Intel Resources to foundational-only (per-chokepoint judgment)
YAML: Removed variant-specific, single-incident, secondary, and annual
report entries from all 7 chokepoint Intel sections. Migrated variant-
specific sources to SourceURL on variation cards (Commit 3). Added
Tier: primary to entries that lacked the field. No Tier: supporting entries
remain in any chokepoint file.

Entry counts after trim:
  clickfix:             18 → 9
  renamed-rmm:           7 → 4
  edr-bypass:           10 → 4  (Tier field added to all kept entries)
  ransomware-svc:        8 → 3
  browser-credential:    9 → 5  (Tier field added to all kept entries)
  web-shells:           10 → 5  (Tier field added to all kept entries)
  remote-execution:      9 → 7

Layout: Replaced tiered Intel rendering (primary card grid + supporting
collapsible toggle) with a uniform flat link list — title (link) + one
sentence description. Removed intel-card, intel-grid, intel-card-name,
intel-card-desc, intel-linked, intel-link-tag, intel-supporting-toggle CSS.
Removed intel-supporting-toggle JS event handler.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:50:00 +00:00
Claude cdcba301a3 Commit 3: Add SourceURL to variation cards
YAML: Added SourceURL to top-level Variations entries across all 7
chokepoint files (24 total). One authoritative primary source per variant;
omitted field where no clear primary source exists. No SourceURL added to
nested structures (MasqueradeThemes in renamed-rmm-tools).

Layout: Added .variant-source-link CSS class (small monospace text, subtle
accent border, hover underline — matches chain-sigma-link pattern). Added
{% if v.SourceURL %} footer block to var-card template rendering
"Source →" link at the bottom of each variation card.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:45:53 +00:00
Claude d2032a3540 Commit 2: Revert to 3 chokepoint stages per chokepoint (per-chokepoint judgment)
clickfix: merge Lure Page Delivery + Clipboard Seeding into Lure/Delivery
  (Research); rename User Execution → Execution (Hunt); rename Outbound
  Network Connection → Second Stage Retrieval (Analyst). Clipboard ETW
  content folded into merged stage LogSources and BypassNote.

renamed-rmm: drop Payload Hosting stage; fold hosting/reachability
  invariant into Browser Download WhyCantBypass. Result: Browser Download
  (Research) → User Execution (Hunt) → Outbound RMM Connection (Analyst).

ransomware-service-manipulation: drop Privilege Verification stage; fold
  Admin/SYSTEM privilege requirement into Service Enumeration WhyCantBypass.
  Result: Service Enumeration (Research) → Service Stop and Disable (Hunt)
  → Service Deletion (Analyst).

remote-execution-tools: drop Network Access stage; fold protocol-port
  reachability requirement into Remote Execution Primitive WhyCantBypass.
  Result: Credential Acquisition (Research) → Remote Execution Primitive
  (Analyst) → Lateral Spread (Hunt).

edr-bypass, browser-credential-theft, web-shells: no Chokepoints section
  exists in these files — left as-is per "fewer than 3 stages" rule.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
2026-03-22 23:41:37 +00:00
imposterandClaude Sonnet 4.6 d4d9287791 Commit 5: Move hunt.io entries to Intel Resources; trim OSINT Notes to one sentence
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 15:51:50 -06:00
imposterandClaude Sonnet 4.6 432b4c25ec Commit 3: Known Bypasses — 2-col table; remove Detection column; drop N/A mitigations
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:41:39 -06:00
imposterandClaude Sonnet 4.6 2014a9d613 Commit 2: Collapse timeline by default; strip TheConstant; trim Change to one sentence
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:36:14 -06:00
imposterandClaude Sonnet 4.6 d9b462a632 Commit 1: Replace Variations table with card grid; add NotesShort field
Added NotesShort (<=20 words) before Notes on every Variation entry across
all 4 chokepoint YAML files. Replaced the Variations HTML table in
chokepoint.html with a 2-col card grid showing Name, FirstSeen, Status badge,
and NotesShort by default; full Notes revealed via inline More/Less toggle.
Added corresponding CSS and expand/collapse JS.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:32:25 -06:00
imposterandClaude Sonnet 4.6 87ff0d7957 Commit 0: Add per-stage Detection Chain to all chokepoint pages
Adds a new `Chokepoints:` YAML block to all four chokepoint entries
(ClickFix, Renamed RMM Tools, Ransomware Service Manipulation, Remote
Execution Tools), each with Stage, Invariant, WhyCantBypass, LogSources,
DetectionTier, SigmaRef, and optional BypassNote fields per attack stage.

Layout: replaces the flat Prerequisites section with a trimmed
environmental-precondition list, then adds a new collapsible Detection
Chain section — numbered stage bubbles, tier badges (Research/Hunt/Analyst)
with urgency subtitles (Baseline / Active Hunt / SOC Alert), segmented
connector lines, and a red BypassNote callout on affected stages.

Schema and template updated with Chokepoints block definition.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 14:18:59 -06:00
imposterandClaude Sonnet 4.6 4a836cfa0d feat(detection-tests): add raw log samples and emulation scripts for all chokepoints
Adds RawLogs and EmulationScript fields to all 6 remaining chokepoints and
creates PowerShell emulation scripts that generate real Sysmon/WEL telemetry
for detection validation without requiring live malware.

Chokepoints covered:
- clickfix-techniques: 3 log samples (Sysmon EID 1/3/22), VBScript→PowerShell shim
- renamed-rmm-tools: 3 log samples (Sysmon EID 11/1/3), binary rename + metadata mismatch
- edr-bypass-techniques: 4 log samples (Sysmon EID 6/10, WEL 7036/7040), process handle + service stop
- ransomware-service-manipulation: 5 log samples (Sysmon EID 1, WEL 7036/7040), bulk service kill pattern
- remote-execution-tools: 4 log samples (WEL 4624/5145/7045, Sysmon EID 1), IPC$+random service pattern
- web-shells: 4 log samples (Sysmon EID 11/1/3), w3wp.exe→cmd.exe parent chain

Each emulation script:
- Generates authentic Sysmon/WEL telemetry matching Research/Hunt/Analyst rule logic
- Documents exactly which sigma rule tier each step triggers
- Is safe for isolated lab use (no real malware, no credentials exfiltrated)
- Includes cleanup, verbose mode, and selective skip flags

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-08 20:42:32 -06:00
Claude c690e8ad0f fix(osint): improve OsintSources across all remaining chokepoint files
Applied the same methodology used for clickfix-techniques.yml to evaluate
and improve the OsintSources blocks in all five remaining chokepoint files.

renamed-rmm-tools.yml (moderate):
- Expanded URLScan filename query with support*.exe and verify*.exe pretexts
- Updated Shodan note to also cover SimpleHelp (CISA AA25-163A, June 2025)
- Replaced Censys AnyDesk cert query with SimpleHelp (AnyDesk certs were
  revoked after the Feb 2024 breach, making that query largely historical)
- Added VT Intelligence PE metadata query for renamed RMM binaries in the wild
- Added LOLRMM.io — the community catalog of RMM tool file/network indicators

remote-execution-tools.yml (significant):
- Removed port:445 country:US — returns millions of results with zero
  signal for hunting attack infrastructure; was an exposure audit query,
  not a threat hunting query
- Repositioned WinRM query with clearer notes about its scope (exposure
  audit, not attacker infra hunting)
- Added Shodan JARM fingerprint query for Cobalt Strike team servers —
  the correct approach for hunting C2 infra paired with Impacket/NetExec
- Added hunt.io for real-time C2 infrastructure mapping

ransomware-service-manipulation.yml (minor):
- Fixed ANY.RUN URL from general trends page to the actual public
  submissions feed with ransomware filter
- Added Ransomware.live for real-time ransomware group activity tracking
- VT Intelligence and GitHub queries were solid; kept as-is

web-shells.yml (minor):
- Expanded Shodan title query with FilesMan and Antak Webshell
- Expanded URLScan filename query with webshell.php and cmd.aspx
- Added Censys eval(base64_decode) query for live obfuscated PHP shells
- VT Intelligence tag:webshell query was the strongest in any file; kept

edr-bypass-techniques.yml (minor):
- Added LOLDrivers (loldrivers.io) — the canonical community catalog of
  vulnerable and malicious drivers used in BYOVD attacks; was absent
  entirely despite being the most important resource for this chokepoint
- All three existing queries were solid; kept as-is

https://claude.ai/code/session_01CeEB6yuJimygkCBi7ubSh3
2026-03-08 15:45:59 +00:00
imposter 78ca6afc24 updated chokepoints with accurate data 2026-03-07 16:09:31 -07:00
Claude 39b5437ecd Restructure repo to LOLBAS-style: YAML chokepoints, real sigma rules, new nav
## What changed

### Structure
- Converted 4 chokepoints from freeform markdown to structured YAML under
  chokepoints/<tactic>/ with standardized schema (schema/chokepoint-schema.yml)
- Added 12 Sigma rules (Research/Hunt/Analyst) for all 4 chokepoints under
  sigma-rules/<technique>/
- Moved attack chains to attack-chains/, trends to trends/, templates to templates/
- Added CONTRIBUTING.md modeled after LOLBAS contribution guide

### Slide-to-repo gaps addressed
- README.md: Added military chokepoint hook (Thermopylae, Fulda Gap),
  thesis statement "TTPs evolve. Chokepoints don't.", chokepoint index table
  with Priority/Prevalence/Difficulty ratings, RaaS TTR compression context
- intel/clickgrab.md: Documented ClickGrab (was referenced in slides/references
  but not in the repo); includes hunt query examples and integration guidance
- HackTools/remote-execution: Completed all 3 sigma rule levels
  (slides showed only a placeholder)
- Source citations: Added HudsonRock, RedCanary, Cyberint, Mandiant M-Trends 2025
  attributions throughout

### New files
CONTRIBUTING.md, schema/chokepoint-schema.yml, intel/clickgrab.md,
templates/chokepoint-template.yml, 12 Sigma rule files,
attack-chains/ransomware.md, attack-chains/infostealers.md,
trends/2025-q1.md, trends/chokepoint-shifts.md

https://claude.ai/code/session_01LWLhVRq5vYHXiDKn86PXhr
2026-02-28 23:24:10 +00:00