100 Commits
Author SHA1 Message Date
iimp0ster 9464482335 Merge pull request #167 from iimp0ster/data/edge-jul16-infra-refresh
edge-exploits: fix stale SAP/SonicWall prose + rebuild infra tables from live data
2026-07-16 21:18:51 -06:00
imposterandClaude Opus 4.8 23a565f698 trends/edge-exploits: recompute the webshell-command table for the live window
The post-exploit command table was the last frozen Mar-Apr artifact. Recomputed
the cmd.gz.war -> /cmd.gz/cmd.jsp webshell POSTs (SD-WAN vManage, CVE-2026-20127)
from the live-window exports: only 33 executions, 3 distinct commands (id x21,
dir x10, ls x2), all trivial enumeration from a handful of IPs.

The baseline's full chain (819 id, 372 XMRig via kernel.sh, /etc/shadow reads,
gs-netcat reverse shells) did not recur. Preserved that finding as labeled
historical context in the callout; the table now leads with live reality.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 21:12:34 -06:00
imposterandClaude Opus 4.8 848764acc7 trends/edge-exploits: fix stale prose + rebuild infra tables from live data
Living-doc consistency pass after the Jul 16 data refresh (PR #163). The
hand-written deep-dives and infra tables were still on the frozen Mar-Apr
baseline and contradicted the auto-updated charts.

Prose fixes:
- SAP: was "third most targeted, 1,179 hits". Now #6 at 1,638 (1,024 on the
  CVE-2022-22536 Apr 9-11 burst + 614 on CVE-2025-31324 across the window).
  Reframed as a historical burst, dropped the stale ranking.
- SonicWall: was "478 attempts / 284 IPs, most distributed". Now 1,693 hits;
  dropped the "most distributed" superlative (it contradicted the Next.js
  section) and documented the verified libredtail-http/apache.selfrep worm
  staging rotation (31.57 -> 204.76 -> 125.135 -> 14.46 -> 217.60).
- Dropped the stale "31-day observation window" anchors (window is now ~4 mo).

Infra rebuild from the raw live-window exports (Apr 19 - Jul 16, newest-wins
day-dedup via scripts/extract_edge_infra.py), ASN/geo via Team Cymru + IPinfo:
- Scanner-UA chart: self-identification collapsed 38.7% -> ~5% as the
  browser-spoofing CitrixBleed 2 flood took over; recomputed tool families.
- Staging Infrastructure: current worm-rotation hosts + new campaigns
  (softwaretech loader, Next.js cloak stager, Cloudflare-fronted installer).
- Multi-Device Operators: current cross-decoy scanners; known research
  scanners (ONYPHE, LeakIX) excluded.
- Replaced the unverifiable "Active" status badge with an Observed telemetry
  window (no liveness probe of live malicious hosts).
- Flagged the webshell-command breakdown as a Mar-Apr baseline capture.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 20:58:55 -06:00
iimp0ster 01aadcae09 Merge pull request #166 from iimp0ster/iimp0ster/trusted-binary-dll-sideloading
fix: restore constant card and Sigma highlighting
2026-07-16 20:57:58 -06:00
imposterandClaude Opus 4.8 b922882538 scripts: add extract_edge_infra.py for scanner/staging/operator recompute
The edge-exploits page's scanner-UA, staging, and multi-device-operator
tables were hand-curated from a one-off Mar-Apr pass and had no build step,
so every data refresh left them stale. This is that missing step.

Reads the raw Defused exports in ~/Downloads, applies the same newest-wins
day-dedup as transform_defused_csv.py so its numbers reconcile with the
page charts, and prints a defanged, curated view (named-tool vs
browser-masquerade UA split, staging URLs with first/last-seen, operator
IP -> decoy coverage). Persists nothing to the repo (decision #009); ASN
for chosen hosts is filled via Team Cymru / enrich_staging_domains.py.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 20:52:54 -06:00
iimp0ster 597898c904 Merge pull request #164 from iimp0ster/feat/clickgrab-carson-2026-07-17
ClickFix cradle refresh (Carson 2026-07-17): rotation back to remote download cradles
2026-07-16 20:20:06 -06:00
imposter a935d56d49 fix: restore constant card and Sigma highlighting 2026-07-16 19:48:14 -06:00
imposterandClaude Opus 4.8 2613361e54 chore(clickgrab): full-page refresh to 2026-07-16 (volume, landscape, lure keywords)
Complete the living-document refresh on top of the Carson cradle rebuild:
- daily/volume: +3 MHaggis days (Jul 14-16) via analyze_clickgrab; total_sites_crawled
  26,969 -> 27,269, window now through 2026-07-16.
- carson_landscape refreshed to 3,774 (gist, Jul 16). total_domains held at the Carson
  XLSX set (3,777) -- analyze preserves it distinct from the landscape count, no clobber.
- clickfix_lure_keywords.yml regenerated from the updated MHaggis cache (IOK / URLScan
  page.body pivots; feeds IOK rules, not rendered on the trends page).

Frozen by design, not refreshed (DECISIONS #011): payload_examples (rich generator gone,
pre-Oct-2025 reports LFS-locked) and staging_domains (21 entries, all already
ASN-enriched; new infra is manual curation, and enrich_staging_domains is local-only).
Detection recs are all behavior/chokepoint-anchored and already cover the summer cradle
reversal (the cradle-agnostic rule caught msiexec and the PowerShell comeback), so no new
rule -- adding one would be false coverage.

Verified: jekyll builds clean (exit 0, full build ~341s), clickgrab page renders with the
refreshed data.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 19:41:11 -06:00
iimp0ster ee254bf6fb Merge pull request #165 from iimp0ster/iimp0ster/trusted-binary-dll-sideloading
Iimp0ster/trusted binary dll sideloading
2026-07-16 19:27:07 -06:00
imposter 804429d9d1 test: add DLL chokepoint regression gates 2026-07-16 19:12:18 -06:00
imposter e66139ed78 fix: complete DLL side-loading site preview 2026-07-16 19:10:08 -06:00
imposter 7b46bf56e6 feat: add trusted binary DLL side-loading chokepoint 2026-07-16 19:10:08 -06:00
imposterandClaude Opus 4.8 916885a169 feat(clickgrab): refresh cradle behaviour to the 2026-07-17 Carson export
Rebuild the clean per-domain command classification from the July 17 Carson
ClickFix Hunter export via build_domain_monthly.py (manual/local, not CI).
3,321 -> 3,777 domains; June completed (74 -> 424, the prior export only had
June through the 16th), July added. domain_monthly / domain_cradles_total /
domain_evasion_totals refreshed; payload_examples / daily / staging_domains
byte-preserved.

The trend this surfaces: the cradle mix rotated back to remote download cradles.
IWR is 28% of June domains and 36% of July, WebClient 15% then 24%, curl 33% in
July, while msiexec (the late-2025 story) fell to <=1% since May and 0% in July.
The spring inline-encoding wave (base64's one-month May campaign, hex-XOR heavy
Apr-May) faded to near-zero by July.

Completing June corrected two now-false hardcoded claims: hex-XOR did NOT climb
"back to 84% in June" -- that was the partial n=74 export; complete June is 16%
(69/424), declining to 0% July. Fixed both spots, extended the msiexec trajectory
through July, and added a callout for the summer remote-fetch reversal.

Verified: historical months (through May) byte-stable, cradle + evasion charts
screenshot-verified (June IWR resurgence and hex-XOR decline render correctly),
0 console errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 19:08:41 -06:00
iimp0ster bdcef0ebca Merge pull request #163 from iimp0ster/feat/edge-exploits-jul16-backfill
Backfill edge-exploits May 20-Jul 16 (CitrixBleed 2 surge); gap-render row-capped days
2026-07-16 18:17:26 -06:00
iimp0ster 532d42311e Merge pull request #156 from iimp0ster/data/clickgrab-auto
chore: update clickgrab trends data [2026-07-13]
2026-07-16 18:11:16 -06:00
iimp0ster 674a599733 Merge pull request #154 from iimp0ster/dependabot/github_actions/github-actions-c81c38844b
ci(deps): bump the github-actions group across 1 directory with 7 updates
2026-07-16 18:09:54 -06:00
iimp0ster 41312061c8 Merge pull request #135 from iimp0ster/dependabot/pip/pip-f69fb2051f
chore(deps): bump the pip group across 1 directory with 11 updates
2026-07-16 18:09:36 -06:00
iimp0ster 2010868330 Merge pull request #133 from iimp0ster/dependabot/npm_and_yarn/npm-4e38a52fea
chore(deps): bump js-yaml from 4.1.1 to 5.2.0 in the npm group across 1 directory
2026-07-16 18:09:15 -06:00
imposterandClaude Opus 4.8 2e45a13223 fix(trends): use AS handle when the provenance org label overflows
transform_provenance.py short() hard-truncated the AS org description at 28
chars, cutting mid-word -- the top provider read "Emil Vitukhnovskii trading
a". Fall back to the AS handle when the org would overflow, so the label reads
the recognizable "GreatFlower". Labels that already fit are unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 17:45:25 -06:00
imposterandClaude Opus 4.8 810f810d85 feat(trends): refresh edge-exploits hosting provenance to Jul 16
Regenerate _data/edge_exploits_provenance.yml for the Apr-Jul 2026 window
(was Jul 3), 2,998 cumulative unique source IPs.

The local enrich_asns.py had been raw-summing overlapping exports, inflating
June 6.6x (105,888 vs the correct 16,113) and floating one ASN (datacampus,
the truncated Jun 10 spike's host) into the top purely as a double-counting
artifact. Gave it the same per-day MAX-wins merge + Jun 10 gap + :port strip
as transform_defused_csv.py, so per-month ASN totals now match the event page
exactly (May 50,016 / Jun 16,113 / Jul 3,537).

enrich_asns.py / hll.py / bulletproof_asns.yml are gitignored, local-only
(they touch raw IPs + an optional key, decision #009); only the IP-free
aggregate yml is committed. Keyless Team Cymru only; IPinfo cross-check skipped.

Verified: per-month totals reconciled to the event page; provenance stacked
chart screenshot-verified (May dominant = GreatFlower, the CitrixBleed 2 surge host).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 17:29:15 -06:00
imposterandClaude Opus 4.8 6016b19c1b feat(trends): backfill edge-exploits May 20-Jul 16, gap-render capped days
Fill the May 20-Jun 9 hole (uploaded 46,209-row export) and extend the
edge-exploits page to Jul 16. Total 75,420 -> 88,299. The story is a
CitrixBleed 2 (CVE-2025-5777) surge: 62,205 hits (70% of all traffic),
peaking May 26 at 29,274 hits from a single source (193.202.84.145).

transform_defused_csv.py:
- day merge is now per-day MAX-wins, not newest-wins, so a newer export's
  partial window-start day can't overwrite an older complete count
  (fixed Jun 16: 10 -> true 139).
- a row-capped export's truncated oldest day renders as a GAP, not a
  partial bar (supersedes the 2026-07-03 partial flag). Jun 10 is the
  first such gap; a narrow uncapped re-export closes it automatically.
- strip the source :port newer exports append to Attacker IP, keeping
  unique-IP counts consistent across export formats (32,258 -> 2,988).
- CitrixBleed 2 daily series now spans the live window.

page: refreshed volume/target/CitrixBleed/Next.js/cPanel prose to the new
totals and the May 26 single-source surge; extended the CB2 chart to Jul 16;
dropped the now-dormant partial-day styling.

Verified: transform output cross-checked against an independent max-wins
re-derivation; page built under Jekyll, both charts screenshot-verified.

edge_exploits_provenance.yml (ASN section) not regenerated -- separate
IP->ASN pipeline, follow-up.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
2026-07-16 16:47:39 -06:00
iimp0ster d8231f40b1 Merge pull request #162 from iimp0ster/fix/mobile-nav-pixel-icons
fix(nav): custom pixel section icons in mobile hamburger menu
2026-07-13 22:37:33 -06:00
iimp0ster ec360f042b Merge pull request #161 from iimp0ster/feat/pdf-sigma-variants
feat(sigma): supplementary detection variants from PDF deck (experimental)
2026-07-13 22:36:57 -06:00
imposterandClaude Fable 5 a235e6def0 fix(nav): use custom pixel section icons in mobile hamburger menu
The desktop nav shows the arcade pixel section icons (chokepoint,
attack-chain, trends, framework .png) next to each item, but the mobile
hamburger menu used generic hand-drawn SVG glyphs instead, breaking the
icon theme between desktop and mobile.

Swap the four section items' m-ic SVGs for the same pixel icons the
desktop nav uses; add a scoped .m-ic img rule (20px, image-rendering:
pixelated) so they stay crisp. Contribute keeps its glyph (it has no
section pixel icon on desktop either).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 22:31:32 -06:00
imposterandClaude Fable 5 e87f583a6a feat(sigma): add hunt tier pixel icon to supplementary variant badges
The supplementary variant cards showed a bare 'Hunt' badge while every
other rule card renders the tier's pixel icon (research/hunt/analyst.png)
inside the badge. All four supplementary variants are hunt-tier, so add
the hunt.png icon to match the established badge styling.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 22:28:20 -06:00
imposterandClaude Fable 5 676c42362a feat(sigma): supplementary detection variants from PDF deck (experimental)
Adds four experimental Sigma variants extracted from the Detection
Chokepoints slide deck, covering angles the existing repo rules do not.
All are status: experimental and render in a new guarded 'Supplementary
Variants' block on their chokepoint page (mirrors the hunt-network
precedent: additive, only renders where the file exists).

New rules:
- clickfix/hunt-registry.yml     ClickFix RunMRU/TypedPaths registry write
                                 (URL + lure keywords/LOLBins) - registry_set
- clickfix/hunt-downloadfix.yml  DownloadFix - browser-written :Zone.Identifier
                                 ADS on a fix/repair-themed filename. Credits
                                 mr.d0x (FileFix origin) and links jfmaes'
                                 DownloadFix PoC (github.com/jfmaes/downloadfix)
- renamed-rmm/hunt-signer.yml    Renamed RMM keyed on Authenticode Company
                                 signer (durable vs image-name). EXAMPLE A-C
                                 signer subset; full list from LOLRMM
- ransomware-service/hunt-process.yml  Direct taskkill of a named EDR *process*
                                 (vs the service-name rules). Sophos example

Plumbing (additive, cannot affect other pages):
- scripts/aggregate.py: register the four new basenames in SIGMA_LEVELS
- _layouts/chokepoint.html: guarded 'Supplementary Variants' block that
  inlines any present variant with GitHub/Download/Copy actions

Provenance: transcribed from Detection Chokepoints.pdf (rules were embedded
images). renamed-rmm signer list and ransomware process list are deliberate
illustrative subsets, documented inline. Detection-reviewer pass: 3 APPROVED,
downloadfix revised (dropped mismapped T1553.005). Rules are authored, NOT
capture-validated - experimental until telemetry confirms.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 19:48:22 -06:00
iimp0ster ff43b81470 Merge pull request #160 from iimp0ster/fix/osint-pivot-links
fix(osint): every pivot card links, and links execute the displayed query
2026-07-13 18:37:28 -06:00
iimp0ster 419393f12a Merge pull request #159 from iimp0ster/fix/arcade-font-selfhost
fix(theme): self-host arcade fonts, end heading color flash
2026-07-13 18:37:24 -06:00
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00
imposterandClaude Fable 5 899ca50455 fix(theme): self-host arcade fonts, end heading color flash
theme-arcade.css opened with a cross-origin @import to Google Fonts,
which delayed the whole overlay sheet: H1s painted white from
style.css first, then snapped orange when the arcade layer applied.
On slow or mobile connections both states were visible, reading as
inconsistent heading colors across pages.

- Self-host Press Start 2P + VT323 woff2 (OFL) under assets/fonts/,
  replace the @import with local @font-face blocks
- Preload the two latin subsets in the default layout head
- Drop the dead 'color: var(--text)' H1 declarations on the three
  trend pages (clickgrab, edge-exploits, masq-infra) that the
  overlay's !important was silently overriding; arcade orange is
  the confirmed canonical H1 treatment sitewide

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:28:11 -06:00
iimp0ster e416c72d91 Merge pull request #155 from iimp0ster/chore/edge-exploits-refresh-2026-07-03
chore(trends): refresh edge-exploits from Jul 3 export, flag gap + row-cap day
2026-07-08 12:58:05 -06:00
imposterandClaude Sonnet 5 3ace655d55 chore(trends): refresh edge-exploits from Jul 3 export, flag gap + row-cap day
Merges the new Defused export (Jun 10 - Jul 3) into the accumulating
edge-exploits history: 25,420 -> 75,420 events. CitrixBleed 2 (CVE-2025-5777)
exploitation jumped 11,145 -> 56,338 hits, NetScaler now >90% of decoy traffic.

transform_defused_csv.py now detects two conditions automatically instead of
relying on hardcoded date constants:
- Gap days: no export covers May 20 - Jun 9, 2026 (21 days), rendered as a
  visible gap on the page.
- Row-cap truncation: this export hit a suspected 50,000-row console cap
  (unverified exact limit) with a clean mid-record cutoff on its oldest day,
  Jun 10 -- flagged partial (undercounts) rather than dropped or trusted as-is.

index.html's gap/volume text is now Liquid-bound to meta.date_range_note and
meta.live_decoy_count instead of hardcoded, so it won't go stale on the next
refresh. The daily chart distinguishes row-cap-partial days from the existing
export-cutoff artifact day.

--check-seed passes clean against the original seed data.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011suj1d1CVCVeJDtgPKrMzi
2026-07-03 13:58:31 -06:00
iimp0ster 3853e3c041 Merge pull request #153 from iimp0ster/feat/og-preview-cards
feat(social): per-section link-preview cards (chokepoints / attack-chains / trends)
2026-07-01 10:28:58 -06:00
imposterandClaude Opus 4.8 7e9bd97379 feat(social): per-section link-preview cards for chokepoints, attack-chains, trends
A shared link now signals what it is — a new chokepoint, attack chain, or trends
entry — instead of the generic site card. Home and generic pages keep og.png.

- templates/og-card.html: HTML card template (build tool, excluded from site),
  rendered at 1200x630 with Press Start 2P / VT323 + the section pixel icon.
- assets/img/social/og-{chokepoints,attack-chains,trends}.png: the three cards.
- assets/img/pixel/trends.png: stripped the baked-in U-frame so the wave icon
  floats like the other nav icons.
- _config.yml: scoped jekyll-seo-tag defaults (chokepoints collection /
  attack-chains / trends); site-wide default unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-07-01 10:13:15 -06:00
iimp0ster b04b752382 Merge pull request #152 from iimp0ster/feat/attack-chain-convergence-viz
feat(attack-chains): convergence highlight + matrix row-mirror on actor select
2026-06-29 12:46:53 -06:00
iimp0ster 468988f597 Merge pull request #151 from iimp0ster/data/clickgrab-auto
chore: update clickgrab trends data [2026-06-29]
2026-06-29 12:44:26 -06:00
imposterandClaude Opus 4.8 fd3dae2a02 feat(attack-chains): convergence highlight + matrix row-mirror on actor select
Selecting 2+ actors on any attack-chain page now highlights the techniques they
all share in cyan (.state-converge) and fades single-actor cells (.state-partial),
so the convergence reads without inspecting per-actor dots. The same selection
mirrors onto the convergence matrix: selected actors' rows light in their own
colour, the rest dim, and the chokepoint (tfoot) invariant row stays fixed.
Legend hint updated to describe the cyan glow.

Verified on the ransomware page (Akira+Play = 19 shared cyan cells) at 1440 and
375 breakpoints, 0 console errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-06-29 12:04:25 -06:00
iimp0ster 8319ceee31 Merge pull request #150 from iimp0ster/claude/clickgrab-conflicts-gh-actions-ytum2y
ci(clickgrab): weekly cadence + single rolling PR (stop the daily PR pileup)
2026-06-21 12:55:25 -06:00
iimp0ster 4017e54ead Merge pull request #149 from iimp0ster/data/clickgrab-2026-06-21
chore: update clickgrab trends data [2026-06-21]
2026-06-21 12:54:46 -06:00
iimp0ster 5ec3a0d076 Merge pull request #145 from iimp0ster/data/clickgrab-2026-06-17
chore: update clickgrab trends data [2026-06-17]
2026-06-18 21:06:08 -06:00
iimp0ster 39d56051b6 Merge pull request #144 from iimp0ster/feat/clickgrab-consolidated-source
ClickFix trends: re-source ingest + clean Carson three-feed model + classifier fix
2026-06-16 13:34:18 -06:00
iimp0ster a1ddcb7c78 Merge pull request #143 from iimp0ster/feat/edge-exploits-provenance
feat(trends): hosting-provenance section for edge-exploits
2026-06-16 13:34:01 -06:00
imposterandClaude Opus 4.8 6e4cd4bf93 docs(clickgrab): note build_domain_monthly + build_lure_keywords are manual-only
Both rebuild from the full local dataset (Carson XLSX / full MHaggis crawl history) that a fresh CI checkout cannot hold, so running them in the daily workflow would shrink the committed full-history files. Document them as manual/local refresh steps and correct the MHaggis feed label (volume, not behavioural — DECISIONS #012).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:58:28 -06:00
imposterandClaude Opus 4.8 a2f4d32bc8 fix(clickgrab): correct classifier regexes + refresh to 2026-06-16 export
Resolve the two classifier defects deferred in DECISIONS #013 and refresh the behavioural data to the current Carson export.

Classifier (build_domain_monthly.py): no_url now means 'no remote fetch' via REMOTE_FETCH_RE, catching single-slash http:/, ftp, UNC/WebDAV (\host, \IP@port\DavWWWRoot), and scheme-less bare-IPv4 fetches; base64 matches -e..-encodedcommand abbreviations via a base64-blob lookahead that excludes -ExecutionPolicy. Validated against the prior XLSX: reproduced the judge's predicted deltas exactly (May inline 93.9%, Feb 6.2%, +31 base64).

Data: regenerated from clickfix-domains-all-2026-06-16.xlsx (3321 domains, Aug 2025-Jun 2026). Trends prose re-derived - May base64 67% (354/528, 352/354 one token), May inline 92.4%, msiexec total 1054. June (partial) shows hex-XOR reclaiming 84% as the May base64 spike collapsed to 1%, framing May as a single campaign rather than a re-tooling.

Validated: scripts/validate_schema.py passes; render-checked.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:40:32 -06:00
imposterandClaude Opus 4.8 66034135c3 feat(clickgrab): re-source ingest + clean Carson three-feed trend model
Re-source ClickGrab ingest off the dead Git-LFS path onto raw GitHub blobs and re-architect the ClickFix trends page around three feeds, each used only for what it is reliable for (DECISIONS #010-012).

Ingest (#010-011): fetch MHaggis ClickGrab as raw blobs (upstream LFS quota exhausted); append-only idempotent volume generator + daily GHA for volume and Carson gist landscape count.

Behaviour (#012): rebuild the per-domain command classification from Carson's ClickFix Hunter export (build_domain_monthly.py) and re-plumb charts/cards to it, separating hex-XOR from base64 (the prior site-crawl source conflated them and measured ~93-99% noise). Trends prose corrected to the honest figures: May base64 69% (316/458), inline 95.2%, Nov msiexec 87% (669/767).

Workstream B: rank MHaggis lure-page HTML keywords (build_lure_keywords.py) into data-driven URLScan OSINT pivots on the clickfix chokepoint and enrich the multilingual IOK matcher.

Validated: scripts/validate_schema.py passes (13 chokepoints, 3 trends files). Deferred: two classifier regex bugs distort Dec-Apr months only; headline figures robust (DECISIONS #013).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:59:48 -06:00
imposterandClaude Opus 4.8 32260237fe chore: gitignore internal M3 provenance plan
Keep docs/M3-PROVENANCE-PLAN.md out of the public repo, matching the internal-material convention (DECISIONS.md, ATTEMPTS.md, .planning/). It is internal research synthesis for a separate workstream (DECISIONS #007), not site content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:58:44 -06:00
imposterandClaude Fable 5 123aedf7ed feat(trends): hosting-provenance section for edge-exploits
Publishes the ASN/hosting provenance the local enrichment produces -- a stacked
per-month chart + top-ASN table on the page, so abuse-tolerant hosting rotation
becomes visible over time. Aggregates only; no IPs in the repo (decision #009).

- transform_provenance.py: cache/edge_exploits_asn.json (local enrichment output)
  -> _data/edge_exploits_provenance.yml. Deterministic, IP-free, no external calls.
- index.html: "Hosting Provenance" section -- stacked ASN-by-month chart + top-ASN
  table with bulletproof flags + nav entry.
- validate_schema.py: structural spec for the new provenance data file.
- refresh_edge_exploits.py: weekly job now regenerates volume + provenance
  (runs the local enrichment when present; volume-only otherwise).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-15 00:09:20 -06:00
iimp0ster 35e5159e3f Merge pull request #142 from iimp0ster/chore/gitignore-enrichment
chore: keep ASN enrichment tooling local (gitignore)
2026-06-14 23:39:43 -06:00
iimp0ster ee17d6a0b0 Merge pull request #140 from iimp0ster/feat/validate-trends-data
feat(ci): extend data validator to trends _data files
2026-06-14 23:39:01 -06:00
iimp0ster 2f0720c964 Merge pull request #139 from iimp0ster/feat/edge-exploits-recon-leadtime
feat(trends): recon-vs-exploitation split + recon->exploit lead-time
2026-06-14 23:38:19 -06:00
imposterandClaude Fable 5 d88a7cd365 chore: keep ASN enrichment tooling local (gitignore)
Enrichment touches IPs/keys/external lookups and must not live in the repo --
the repo holds only published site data (decision #009). Mirrors the existing
scripts/enrich_staging_domains.py entry. The scripts run locally and write only
IP-free aggregates to cache/, which the page publishes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 21:11:52 -06:00
imposterandClaude Fable 5 2abf933982 feat(ci): extend data validator to trends _data files
validate_schema.py now also checks the generated trends data files
(edge_exploits, clickgrab_trends, masq_infra_hunts) against the structure
their page templates depend on: required meta keys, list sections, and the
field types the templates do date/number work on. Catches a transform bug or
hand-edit that would render a page blank or break the build.

- declarative TRENDS_SPECS per file; each validated only once it goes data-driven
- validate-data.yml now also triggers on _data/** changes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 16:50:22 -06:00
imposterandClaude Fable 5 7a1a748c4a feat(trends): add recon-vs-exploitation split + lead-time to edge-exploits
Classify each Defused alert by its Alert verb -- weaponized exploitation
("Vulnerability Exploited") vs targeted recon (probing / vuln-check /
exposure) -- and surface two views on the edge-exploits page:

- daily stacked exploitation-vs-recon chart (live window; 67% / 33%)
- per-CVE recon->exploit lead-time table, where probing preceded the first
  weaponized hit (e.g. CVE-2025-55182 led by 6 days)

No export change -- pure classification of the existing high/critical data.
Live window only (the baseline kept no per-alert verbs). Aggregates only; no IPs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 12:59:25 -06:00
iimp0ster ff20a9864f Merge pull request #136 from iimp0ster/feat/data-validation
feat(ci): chokepoint schema validator + link audit
2026-06-14 12:28:20 -06:00
iimp0ster a7ba507d59 Merge pull request #137 from iimp0ster/feat/masq-infra-publish
feat(trends): publish masq-infra hunts + weekly refresher
2026-06-14 12:28:04 -06:00
iimp0ster 821eea1a64 Merge pull request #138 from iimp0ster/feat/edge-exploits-automation
feat(trends): automate edge-exploits page from Defused exports
2026-06-14 12:27:29 -06:00
imposterandClaude Fable 5 6c242433db feat(trends): automate edge-exploits page from Defused exports
Render trends/edge-exploits/ from _data/edge_exploits.yml instead of
hand-typed numbers, accumulating history across exports.

- transform_defused_csv.py merges export(s) by day onto a frozen first-
  export baseline (combined = baseline + live); aggregates only, no IPs
- edge_exploits_baseline.yml freezes the un-retained Mar 14-Apr 13 window
- index.html renders stats, meta, daily/CitrixBleed charts, target bars
  from site.data (SRI hashes preserved; inline data jsonify-escaped)
- refresh_edge_exploits.py: weekly detect-only / --open-pr refresher
- adds the high/critical severity scope note, corrects the 2,653->2,683
  Next.js stat, and fixes export-cutoff artifact greying (data flag)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-13 23:33:15 -06:00
imposterandClaude Opus 4.8 f8a6004df5 feat(trends): publish masq-infra hunts + weekly refresher
The infra-malware-delivery-hunter skill writes hunt intel to the local
de-intel-pipeline; transform_intel_hunts.py aggregates it into
_data/masq_infra_hunts.yml. That data file was gitignored from when the
workflow was being tested, so the trends page guard
(`{% if site.data.masq_infra_hunts %}`) silently hid the section on the
live site. Un-ignore it (and its producer) so the section publishes.

- un-ignore _data/masq_infra_hunts.yml + scripts/transform_intel_hunts.py
- commit the current aggregated data (5 hunts, 5 brands)
- add scripts/refresh_masq_infra.py: local weekly refresher that
  regenerates from the hunts folder and opens a review PR only when real
  hunt data changed (ignores the generated: timestamp); preserves the
  working tree when run unattended

enrich_staging_domains.py stays ignored (belongs to the clickgrab trend).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 13:29:03 -06:00
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00
iimp0ster 5386944603 Merge pull request #132 from iimp0ster/chore/tame-dependabot
chore(deps): tame Dependabot (group + monthly)
2026-06-12 21:00:45 -06:00
imposterandClaude Opus 4.8 93655c550d chore(deps): tame Dependabot — group updates, monthly cadence
First-run Dependabot opened one PR per outdated dependency across 4
ecosystems (a dozen+ at once). Group all bumps per ecosystem into a
single PR and switch weekly -> monthly so a scan yields at most ~4 PRs.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:49:11 -06:00
iimp0ster cdcaad05d2 Merge pull request #119 from iimp0ster/security/hardening
security: harden supply chain, escaping, Actions, and governance
2026-06-12 20:43:15 -06:00
imposterandClaude Opus 4.8 0c3709aa7e security: harden site supply chain, escaping, Actions, and governance
XSS:
- Escape `</` in all 5 jsonify-into-<script> data blobs so contributed
  YAML cannot break out of the script context (verified: JSON still
  parses, no </script breakout)
- Add `| escape` to contributor-controlled fields in chokepoint-card.html
  and ~71 value outputs in the chokepoint detail layout

Supply chain (SRI):
- Pin highlight.js, d3, and Chart.js CDN includes with sha384 integrity +
  crossorigin (hashes computed from the immutable versioned URLs)
- Document why cdn.tailwindcss.com cannot take SRI + the real fix

GitHub Actions:
- SHA-pin all 7 third-party actions to commit SHAs (version in comment)

Governance:
- SECURITY.md (private disclosure policy + scope: detection content is
  intentional, not a vuln)
- CODEOWNERS routing review to @iimp0ster
- Dependabot for github-actions / bundler / npm / pip

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:24:30 -06:00
iimp0ster 14d42ef5b5 Merge pull request #118 from iimp0ster/feat/social-preview
feat(seo): add social preview card for link shares
2026-06-12 15:30:48 -06:00
imposterandClaude Opus 4.8 4b21a96965 fix(seo): kicker line matches site nav headings
SIGMA -> CHOKEPOINTS in the social card kicker.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:26:39 -06:00
imposterandClaude Opus 4.8 8094344d9f feat(seo): add social preview card for link shares
1200x630 og:image in the playingwithpackets card style: navy field,
Press Start 2P title, tagline, framed arcade artwork strip, site URL.
Wired site-wide via jekyll-seo-tag front matter defaults with
twitter:card summary_large_image; pages can override with their own
image front matter.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:24:23 -06:00
iimp0ster 3089493ec8 Merge pull request #117 from iimp0ster/docs/readme-refresh
docs(readme): sync README with live site content
2026-06-12 07:47:43 -06:00
imposterandClaude Opus 4.8 fc34754138 docs(readme): sync README with live site content
- Chokepoint index: 9 -> 13 entries (adds AiTM WebSocket Kit Relay,
  OAuth Device Code Phishing, Graph API Recon Burst, Device PRT
  Enrollment); names and tactic columns now match the canonical YAML
- Why This Exists: replace misattributed dwell-time stat with verified
  figures (M-Trends 2025 median dwell 11 days; Unit 42 GIRR 2026
  first-quartile time-to-exfiltration 72 minutes)
- Attack chains: fill in ransomware coverage (260 procedures, 36 reports)
- Trends: add missing Software Impersonation Infrastructure entry;
  refresh ClickFix and Edge Exploit figures to current dashboards
- Framework: question list now verbatim with the site; mention the
  interactive relationship map
- New Prevention Layer section (per-chokepoint prevention opportunities
  + MagicSword application-control mapping)

Audited against the live site and chokepoint YAMLs as of 2026-06-12.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 07:37:56 -06:00
iimp0ster 141dfa4b82 Merge pull request #116 from iimp0ster/feat/readme-pixel-logo
docs(readme): add arcade pixel-art repo logo
2026-06-12 06:58:21 -06:00
imposterandClaude Opus 4.8 2b7e3d3328 docs(readme): add arcade pixel-art repo logo
RNC-with-body-triangle artwork in a versus-game frame with the Press
Start 2P title band and tagline, matching the Tacklebox README lockup.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 06:55:45 -06:00
iimp0ster e349c48119 Merge pull request #115 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
fix(nav): full-screen mobile menu with Trends accordion
2026-06-11 10:27:48 -06:00
imposterandClaude Opus 4.8 0d0c14d7c3 fix(nav): full-screen mobile menu with Trends accordion
Replace the overflowing right-column mobile menu with a full-screen overlay: decluttered top bar (brand + hamburger), one item per row with large tap targets, a collapsible Trends accordion (no longer dumped inline), and theme/GitHub/MagicSword in a footer row. Move the overlay outside .site-nav so position:fixed isn't trapped by the nav's backdrop-filter containing block, and bind the theme toggle to all .js-theme-toggle buttons. Desktop nav unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 10:23:34 -06:00
iimp0ster 04c0e3005a Merge pull request #114 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
Site: MagicSword integration, TTP graph, redesign + logo fix
2026-06-11 09:20:19 -06:00
imposterandClaude Opus 4.8 a8728bb20b fix(nav): prevent brand/toolbar overlap on mobile
On <=900px the Press Start 2P brand (~240px) collided with the nav toolbar. Pare the toolbar to theme + hamburger (GitHub stays in the menu's Contribute, MagicSword on the homepage card), shrink the brand to .6rem, and cap its width with ellipsis so the full title fits at 375px and truncates cleanly on narrower screens. Desktop unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:31:51 -06:00
imposterandClaude Opus 4.8 d3d3538f17 content: chokepoint, trends, and framework updates
Refresh chokepoint YAML entries, trends pages (incl. masq-infra rewrite), framework page, search index script, build aggregation, and pixel nav/section icons.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 5982b5e468 style: arcade theme layer + chokepoint page redesign
Arcade theme stylesheet, premium chokepoint hero/sidebar styling, trends submenu, and hero treatments.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 f93cd02398 feat(magicsword): prevention integration + transparent logo
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00
imposterandClaude Opus 4.8 e80dea6bd9 chore: gitignore internal planning and intel material
Keep GSD planning, draft detections, mockups, local intel hunt data, and intel-pipeline scripts out of the public repo.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00
iimp0ster 2588b2ee36 Merge pull request #111 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
fix(styles): add missing cp-section-icon/card/heading CSS inline
2026-05-29 21:32:37 -06:00
imposterandClaude Sonnet 4.6 2054e7c709 fix(styles): add missing cp-section-icon/card/heading CSS inline
Section icon HTML was committed without its companion CSS, leaving
SVGs unconstrained and rendering full-page on all chokepoint pages.
Inlines the four missing rules directly in chokepoint.html until
assets/css/style.css is committed as part of the MagicSword rollout.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 21:27:44 -06:00
iimp0ster 03c59a30fa Merge pull request #110 from iimp0ster/clean/public-site
Clean/public site
2026-05-29 21:14:31 -06:00
iimp0ster d88a45a53b Merge pull request #109 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
feat(chokepoints): add 4 AiTM / Tycoon 2FA chokepoints + site updates
2026-05-29 21:03:43 -06:00
imposterandClaude Sonnet 4.6 ccd74299b0 fix(template): xml_escape note/description fields to prevent bare HTML tags
Payload Note and variant Notes fields output unescaped, so literal HTML
tags in YAML prose (e.g. "<a> element" in DownloadFix variant note) were
parsed by htmlproofer as real anchor tags with missing href.

Add xml_escape to p.Note, v.Notes/NotesShort, and src.Notes outputs.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 21:00:00 -06:00
imposterandClaude Sonnet 4.6 57a8b751de fix(ci): strip baseurl prefix so htmlproofer resolves _site paths correctly
Jekyll builds with --baseurl "/detection-chokepoints", so all absolute
links in the HTML carry that prefix. htmlproofer checks these against
_site/ directly, so without --swap-urls it looks for
_site/detection-chokepoints/... instead of _site/... and fails on
every internal link — CSS, nav, chokepoint cross-refs, everything.

--swap-urls "^/detection-chokepoints:" strips the prefix before each
path lookup, making the checker match the actual _site/ layout.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:39:17 -06:00
imposterandClaude Sonnet 4.6 25c5f836e0 fix(ci): exclude assets/lures/ from htmlproofer link checks
Lure files use bare <a> elements intentionally (defanged phishing samples).
Add --ignore-files regex to skip the entire lures directory.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:24:48 -06:00
imposterandClaude Sonnet 4.6 a9dd68778b fix(ci): fix all html-proofer 5.x flag incompatibilities
- Pin gem to ~> 5.2 to prevent future silent upgrades
- Drop OpenGraph from --checks (not valid in 5.x; valid: Links,Images,Scripts)
- Add explicit .html argument to --assume-extension (required in 5.x)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:12:19 -06:00
imposterandClaude Sonnet 4.6 fbe79e5c0d fix(ci): drop --ignore-urls flag (changed in html-proofer 5.x)
Flag format changed between 4.x and 5.x; pattern was being treated as a
directory path. Redundant anyway since --disable-external skips all
external URLs including github.com links.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:04:01 -06:00
imposterandClaude Sonnet 4.6 04298039e8 fix(ci): update htmlproofer flags for html-proofer 5.x
--check-html and --typhoeus-config were removed in html-proofer 5.x.
Replace with --checks Links,Images,Scripts,OpenGraph (explicit defaults).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:00:22 -06:00
imposterandClaude Sonnet 4.6 2a4d06baef fix(yaml): fix mapping-values-not-allowed parse errors in 3 chokepoints
Plain scalars with "key: value" patterns (authenticationProtocol: deviceCode,
incomingTokenType: primaryRefreshToken, Account Discovery/Manipulation colons)
rejected by PyYAML. Fixed with > block scalar indicators and quoted Name/TheConstant
values.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 19:57:01 -06:00
imposterandClaude Sonnet 4.6 424a81212a feat(chokepoints): add 4 AiTM Tycoon 2FA chokepoints from Elastic research (2026-05-27)
Promotes intel-pipeline drafts to canonical chokepoints/. All entries sourced
from Elastic Security Labs Tycoon 2FA AiTM detection engineering article.

New entries:
- credential-access/aitm-websocket-relay (T1539, T1078.004) -- CRITICAL
  Node.js UA on Entra sign-in + two-tier ASN correlation. Covers Tycoon 2FA
  and EvilProxy variants.
- defense-evasion/oauth-device-code-phishing (T1550.001) -- HIGH
  MAB app ID + deviceCode + isInteractive = high-confidence victim redemption.
  CA policy "Block device code flow" documented as prevention.
- discovery/graph-api-recon-burst (T1087.004, T1069.003, T1526) -- HIGH
  4+ Graph API endpoint categories in 60s = automated operator console.
  Requires Graph Activity Logs. c_sid pivot mistake documented.
- persistence/aitm-device-prt-enrollment (T1098.005) -- HIGH
  axios UA on DRS enrollment generates audit event; device PRT survives
  revokeSignInSessions. IR playbook fix: delete devices BEFORE revoking.

12 Sigma rules (research/hunt/analyst per chokepoint). KQL implementations
documented inline for graph-api-recon-burst and aitm-device-prt-enrollment
analyst rules that require multi-table correlation.

Pending lab validation (documented inline):
- RawLogs samples not yet attached
- filter_legit_automation placeholders need tenant-specific UPNs
- AuditLogs UserAgent field name to verify for prt-enrollment
- graph-api-recon-burst: KQL required (Sigma cannot express category-count)

Closes: intel/aitm-drafts-2026-05 (drafts branch; this promotes to canonical)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:53 -06:00
imposterandClaude Sonnet 4.6 04e84dbab8 feat(site): weekly chokepoint updates and site improvements
Update 9 published chokepoints with accuracy fixes and variant additions.
Update layouts, attack chains, trends pages, and framework content.

Note: _config.yml, _includes/nav.html, assets/css/style.css, and index.html
contain in-progress MagicSword affiliate integration -- held back from this PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:33 -06:00
iimp0ster e8a2b5af43 Merge pull request #103 from iimp0ster/clean/public-site
Clean/public site
2026-04-22 14:47:57 -06:00
imposter febf1edb32 feat(site): add nav hamburger script, link-check workflow, and gitignore for local/tooling
Made-with: Cursor
2026-04-22 14:39:22 -06:00
imposter 859c5ace3c chore: drop local/planning artifacts from public branch
Made-with: Cursor
2026-04-22 13:04:35 -06:00
imposter d9caddcea8 feat(nav): enhance navigation with responsive design and new elements
- Added a hamburger menu for mobile view, improving accessibility and usability on smaller screens.
- Updated navigation links to be more flexible and responsive, adjusting layout based on screen size.
- Introduced styles to prevent horizontal overflow for images and other media.
- Enhanced the overall structure of the navigation bar for better alignment and spacing.

This update aims to create a more user-friendly navigation experience across different devices.
2026-04-22 13:02:46 -06:00
iimp0ster 871f8ea7ba Merge pull request #101 from iimp0ster/feat/kitsune-attack-chains-readme
Attack chain rebuild via Kitsune + ORKL, trend payload examples, README refresh
2026-04-14 14:08:20 -06:00
imposterandClaude Opus 4.6 479d465c44 docs(readme): rewrite in project voice, remove em dashes, reflect current state
The previous README was outdated (chokepoint count off by 2, no mention of 3 of the 5 attack chains, no trends section, framework section referenced only FRAMEWORK.md instead of the live framework page) and written in a tone that didn't match the rest of the site's voice.

This rewrite:
- Opens with the value prop in two sentences instead of the Thermopylae/Fulda Gap analogy (moved to framework page where it belongs)
- Leads Why This Exists with the Kaspersky 8/8 finding and the broader 5-chain convergence result from the Kitsune + ORKL rebuild, ties dwell time compression (Mandiant M-Trends 2025) to why chokepoints matter now
- Corrects chokepoint index from 7 to 9 entries (adds LSASS Credential Dumping and BYOSI Scripting Interpreters which were missing)
- Adds Attack Chains section listing all 5 chains with shared-technique counts
- Adds Trends section (ClickFix ClickGrab + Defused Cyber edge-exploit telemetry)
- Framework section now points at the interactive page, not the markdown file
- Contributing section aligns with the partial-contributions tone used on CONTRIBUTING.md
- Resources table adds Kitsune, ORKL, and Defused Cyber as first-class sources
- 0 em dashes (was 18). Peer-to-peer voice throughout.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 14:00:29 -06:00
imposterandClaude Opus 4.6 bf61a0c8fc style(templates): remove em dashes from shared attack-chain templates
- ttp-vertical-diagram.html: TTP card legend (applies to all attack chain pages via shared include)
- attack-chain.html: Chokepoint Convergence Principle callout and Actor Convergence Matrix description (applies to all attack chain pages via shared layout)

Replaces em dashes with periods or commas per project style. No content changes.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 13:59:59 -06:00
imposterandClaude Opus 4.6 17a8f877ad feat(trends): defang payloads, add detection logic + observed payload examples
Both trend pages now include paired collapsible blocks on each detection recommendation: one for real observed payloads (IOCs from the source dataset) and one for example Sigma-style detection logic. Formats match across the two pages.

clickgrab.md
- Add Example detection logic to all 7 detection recommendations (T1059 unusual parent->PS, cradle-agnostic network fetch, T1027 Base64 decode+execute, T1070 self-delete, INFRA CDN staging, T1218 MSIExec, T1059 inline decode-and-execute)
- Add Observed payloads collapsibles for T1218 MSIExec (3 examples) and T1059 inline decode (3 examples)
- Defang all malicious IOCs: shift-art.com, verifyhumanbot.com, port-5506 staging IPs
- Align h1 with colon separator instead of em dash

edge-exploits/index.html
- Add Observed payloads collapsibles to all 6 detection recommendations populated with real honeypot data (SD-WAN DCA bypass, Wildfly webshell upload, CitrixBleed 2, Bearer-token SQLi, pipe-to-shell, DCA credential access)
- Defang all malicious IOCs: CitrixBleed 2 operator IPs, pipe-to-shell staging (kernel.sh, moneroocean, 83.142, miso88, apache.selfrep), Ivanti reverse shell target, FortiWeb CIDR ranges, multi-device operator IPs, staging infrastructure entries
- Align h1 with colon separator matching clickgrab style; convert inline-styled meta div to .ep-meta class

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 13:59:44 -06:00