Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).
Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
wrong slug -> correct article)
Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Update 9 published chokepoints with accuracy fixes and variant additions.
Update layouts, attack chains, trends pages, and framework content.
Note: _config.yml, _includes/nav.html, assets/css/style.css, and index.html
contain in-progress MagicSword affiliate integration -- held back from this PR.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Condense Logic fields across 8 chokepoint pages (22 blocks total) from pseudocode-style WHERE/AND/OR constructs into plain-language 1-3 sentence descriptions matching the clickfix reference pattern. Technical specificity preserved (event IDs, access masks, paths, thresholds).
- LSASS page: align structure with clickfix template (remove redundant AttackerControls/AttackerCannotControl blocks, reformat RawLogs samples to match clickfix style with Key signal comments, add URL fields to OSINT pivots so queries are clickable)
- Layout: remove tier badges from chokepoint stage headers and raw log sample cards so badges only appear on Sigma rule examples where they add context. Switch detection logic block from white-space:pre to pre-wrap with word-break so long rules wrap instead of hiding under the horizontal scrollbar.
- Remove remaining em dashes from chokepoint layout intro copy ("Each stage is an invariant condition...", "Tools and methods that exploit this chokepoint...")
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- confidence_label maps 0-100 score to confirmed/high/medium/low
- rescore_record uses behavioral signals (chain_observed 40pts, multi_source 20pts)
- SHA-256 presence drops from 30pts to 5pts (structural, not behavioral)
- Feed membership scores 0pts (not behavioral per PIPE-02)
- Single source of truth for scoring logic across all pipeline scripts
- Add .sigma-block--research/hunt/analyst with 4px left border accent (UX-02)
- Add .sigma-btn.copied rule with green color and border feedback (UX-01)
- Update copyCode() to toggle .copied class on click and remove after 1.8s (UX-01)
- clickfix-techniques.yml: fix 10 em dashes in Notes, Detections, and References Name fields; cut weak closer from Description; quote YAML Name values with colons
- edr-bypass-techniques.yml: fix 7 em dashes in Context and References/Variation Name fields; quote YAML Name values with colons
- remote-execution-tools.yml: fix 5 em dashes in References Name fields; quote YAML Name values
- trends/clickgrab.md: fix 15 em dashes in titles, prose paragraphs, and callouts; preserve Liquid empty-cell placeholders
- trends/index.md: fix 5 em dashes in hero text, pillar descriptions, and front matter description
- trends/masq-infra.md: fix 5 em dashes in front matter, methodology, and chokepoints prose; preserve 7 Liquid table placeholder instances
Unquoted colon in Invariant field caused yaml.scanner.ScannerError
in aggregate.py CI step.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Remove em dashes from prose throughout all 7 remaining chokepoints,
replacing with periods, commas, or semicolons for tighter writing.
Remove AttackerControls/AttackerCannotControl bulleted lists (redundant
with chokepoint stage descriptions). Intel reference names preserved.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Merge variant cards and evolution timeline into single chronological view
- Add click-to-filter: chip selection highlights related timeline entries
- Add per-variant intel links for analyst pivoting to threat reports
- Add variant chip strip for quick scanning of all variants with status
- Add TheConstant box showing the invariant detection anchor
- Update all 7 chokepoint YAML files with VariantId and EventType fields
- Update chokepoint layout template with combined section and filtering JS
- Add new CSS for combined timeline, chips, filtering states, and intel links
YAML: Removed variant-specific, single-incident, secondary, and annual
report entries from all 7 chokepoint Intel sections. Migrated variant-
specific sources to SourceURL on variation cards (Commit 3). Added
Tier: primary to entries that lacked the field. No Tier: supporting entries
remain in any chokepoint file.
Entry counts after trim:
clickfix: 18 → 9
renamed-rmm: 7 → 4
edr-bypass: 10 → 4 (Tier field added to all kept entries)
ransomware-svc: 8 → 3
browser-credential: 9 → 5 (Tier field added to all kept entries)
web-shells: 10 → 5 (Tier field added to all kept entries)
remote-execution: 9 → 7
Layout: Replaced tiered Intel rendering (primary card grid + supporting
collapsible toggle) with a uniform flat link list — title (link) + one
sentence description. Removed intel-card, intel-grid, intel-card-name,
intel-card-desc, intel-linked, intel-link-tag, intel-supporting-toggle CSS.
Removed intel-supporting-toggle JS event handler.
https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
YAML: Added SourceURL to top-level Variations entries across all 7
chokepoint files (24 total). One authoritative primary source per variant;
omitted field where no clear primary source exists. No SourceURL added to
nested structures (MasqueradeThemes in renamed-rmm-tools).
Layout: Added .variant-source-link CSS class (small monospace text, subtle
accent border, hover underline — matches chain-sigma-link pattern). Added
{% if v.SourceURL %} footer block to var-card template rendering
"Source →" link at the bottom of each variation card.
https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
Added NotesShort (<=20 words) before Notes on every Variation entry across
all 4 chokepoint YAML files. Replaced the Variations HTML table in
chokepoint.html with a 2-col card grid showing Name, FirstSeen, Status badge,
and NotesShort by default; full Notes revealed via inline More/Less toggle.
Added corresponding CSS and expand/collapse JS.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds a new `Chokepoints:` YAML block to all four chokepoint entries
(ClickFix, Renamed RMM Tools, Ransomware Service Manipulation, Remote
Execution Tools), each with Stage, Invariant, WhyCantBypass, LogSources,
DetectionTier, SigmaRef, and optional BypassNote fields per attack stage.
Layout: replaces the flat Prerequisites section with a trimmed
environmental-precondition list, then adds a new collapsible Detection
Chain section — numbered stage bubbles, tier badges (Research/Hunt/Analyst)
with urgency subtitles (Baseline / Active Hunt / SOC Alert), segmented
connector lines, and a red BypassNote callout on affected stages.
Schema and template updated with Chokepoints block definition.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Applied the same methodology used for clickfix-techniques.yml to evaluate
and improve the OsintSources blocks in all five remaining chokepoint files.
renamed-rmm-tools.yml (moderate):
- Expanded URLScan filename query with support*.exe and verify*.exe pretexts
- Updated Shodan note to also cover SimpleHelp (CISA AA25-163A, June 2025)
- Replaced Censys AnyDesk cert query with SimpleHelp (AnyDesk certs were
revoked after the Feb 2024 breach, making that query largely historical)
- Added VT Intelligence PE metadata query for renamed RMM binaries in the wild
- Added LOLRMM.io — the community catalog of RMM tool file/network indicators
remote-execution-tools.yml (significant):
- Removed port:445 country:US — returns millions of results with zero
signal for hunting attack infrastructure; was an exposure audit query,
not a threat hunting query
- Repositioned WinRM query with clearer notes about its scope (exposure
audit, not attacker infra hunting)
- Added Shodan JARM fingerprint query for Cobalt Strike team servers —
the correct approach for hunting C2 infra paired with Impacket/NetExec
- Added hunt.io for real-time C2 infrastructure mapping
ransomware-service-manipulation.yml (minor):
- Fixed ANY.RUN URL from general trends page to the actual public
submissions feed with ransomware filter
- Added Ransomware.live for real-time ransomware group activity tracking
- VT Intelligence and GitHub queries were solid; kept as-is
web-shells.yml (minor):
- Expanded Shodan title query with FilesMan and Antak Webshell
- Expanded URLScan filename query with webshell.php and cmd.aspx
- Added Censys eval(base64_decode) query for live obfuscated PHP shells
- VT Intelligence tag:webshell query was the strongest in any file; kept
edr-bypass-techniques.yml (minor):
- Added LOLDrivers (loldrivers.io) — the canonical community catalog of
vulnerable and malicious drivers used in BYOVD attacks; was absent
entirely despite being the most important resource for this chokepoint
- All three existing queries were solid; kept as-is
https://claude.ai/code/session_01CeEB6yuJimygkCBi7ubSh3