Commit Graph
100 Commits
Author SHA1 Message Date
imposterandClaude Opus 4.8 66034135c3 feat(clickgrab): re-source ingest + clean Carson three-feed trend model
Re-source ClickGrab ingest off the dead Git-LFS path onto raw GitHub blobs and re-architect the ClickFix trends page around three feeds, each used only for what it is reliable for (DECISIONS #010-012).

Ingest (#010-011): fetch MHaggis ClickGrab as raw blobs (upstream LFS quota exhausted); append-only idempotent volume generator + daily GHA for volume and Carson gist landscape count.

Behaviour (#012): rebuild the per-domain command classification from Carson's ClickFix Hunter export (build_domain_monthly.py) and re-plumb charts/cards to it, separating hex-XOR from base64 (the prior site-crawl source conflated them and measured ~93-99% noise). Trends prose corrected to the honest figures: May base64 69% (316/458), inline 95.2%, Nov msiexec 87% (669/767).

Workstream B: rank MHaggis lure-page HTML keywords (build_lure_keywords.py) into data-driven URLScan OSINT pivots on the clickfix chokepoint and enrich the multilingual IOK matcher.

Validated: scripts/validate_schema.py passes (13 chokepoints, 3 trends files). Deferred: two classifier regex bugs distort Dec-Apr months only; headline figures robust (DECISIONS #013).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:59:48 -06:00
imposterandClaude Opus 4.8 32260237fe chore: gitignore internal M3 provenance plan
Keep docs/M3-PROVENANCE-PLAN.md out of the public repo, matching the internal-material convention (DECISIONS.md, ATTEMPTS.md, .planning/). It is internal research synthesis for a separate workstream (DECISIONS #007), not site content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:58:44 -06:00
iimp0ster 35e5159e3f Merge pull request #142 from iimp0ster/chore/gitignore-enrichment
chore: keep ASN enrichment tooling local (gitignore)
2026-06-14 23:39:43 -06:00
iimp0ster ee17d6a0b0 Merge pull request #140 from iimp0ster/feat/validate-trends-data
feat(ci): extend data validator to trends _data files
2026-06-14 23:39:01 -06:00
iimp0ster 2f0720c964 Merge pull request #139 from iimp0ster/feat/edge-exploits-recon-leadtime
feat(trends): recon-vs-exploitation split + recon->exploit lead-time
2026-06-14 23:38:19 -06:00
imposterandClaude Fable 5 d88a7cd365 chore: keep ASN enrichment tooling local (gitignore)
Enrichment touches IPs/keys/external lookups and must not live in the repo --
the repo holds only published site data (decision #009). Mirrors the existing
scripts/enrich_staging_domains.py entry. The scripts run locally and write only
IP-free aggregates to cache/, which the page publishes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 21:11:52 -06:00
imposterandClaude Fable 5 2abf933982 feat(ci): extend data validator to trends _data files
validate_schema.py now also checks the generated trends data files
(edge_exploits, clickgrab_trends, masq_infra_hunts) against the structure
their page templates depend on: required meta keys, list sections, and the
field types the templates do date/number work on. Catches a transform bug or
hand-edit that would render a page blank or break the build.

- declarative TRENDS_SPECS per file; each validated only once it goes data-driven
- validate-data.yml now also triggers on _data/** changes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 16:50:22 -06:00
imposterandClaude Fable 5 7a1a748c4a feat(trends): add recon-vs-exploitation split + lead-time to edge-exploits
Classify each Defused alert by its Alert verb -- weaponized exploitation
("Vulnerability Exploited") vs targeted recon (probing / vuln-check /
exposure) -- and surface two views on the edge-exploits page:

- daily stacked exploitation-vs-recon chart (live window; 67% / 33%)
- per-CVE recon->exploit lead-time table, where probing preceded the first
  weaponized hit (e.g. CVE-2025-55182 led by 6 days)

No export change -- pure classification of the existing high/critical data.
Live window only (the baseline kept no per-alert verbs). Aggregates only; no IPs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 12:59:25 -06:00
iimp0ster ff20a9864f Merge pull request #136 from iimp0ster/feat/data-validation
feat(ci): chokepoint schema validator + link audit
2026-06-14 12:28:20 -06:00
iimp0ster a7ba507d59 Merge pull request #137 from iimp0ster/feat/masq-infra-publish
feat(trends): publish masq-infra hunts + weekly refresher
2026-06-14 12:28:04 -06:00
iimp0ster 821eea1a64 Merge pull request #138 from iimp0ster/feat/edge-exploits-automation
feat(trends): automate edge-exploits page from Defused exports
2026-06-14 12:27:29 -06:00
imposterandClaude Fable 5 6c242433db feat(trends): automate edge-exploits page from Defused exports
Render trends/edge-exploits/ from _data/edge_exploits.yml instead of
hand-typed numbers, accumulating history across exports.

- transform_defused_csv.py merges export(s) by day onto a frozen first-
  export baseline (combined = baseline + live); aggregates only, no IPs
- edge_exploits_baseline.yml freezes the un-retained Mar 14-Apr 13 window
- index.html renders stats, meta, daily/CitrixBleed charts, target bars
  from site.data (SRI hashes preserved; inline data jsonify-escaped)
- refresh_edge_exploits.py: weekly detect-only / --open-pr refresher
- adds the high/critical severity scope note, corrects the 2,653->2,683
  Next.js stat, and fixes export-cutoff artifact greying (data flag)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-13 23:33:15 -06:00
imposterandClaude Opus 4.8 f8a6004df5 feat(trends): publish masq-infra hunts + weekly refresher
The infra-malware-delivery-hunter skill writes hunt intel to the local
de-intel-pipeline; transform_intel_hunts.py aggregates it into
_data/masq_infra_hunts.yml. That data file was gitignored from when the
workflow was being tested, so the trends page guard
(`{% if site.data.masq_infra_hunts %}`) silently hid the section on the
live site. Un-ignore it (and its producer) so the section publishes.

- un-ignore _data/masq_infra_hunts.yml + scripts/transform_intel_hunts.py
- commit the current aggregated data (5 hunts, 5 brands)
- add scripts/refresh_masq_infra.py: local weekly refresher that
  regenerates from the hunts folder and opens a review PR only when real
  hunt data changed (ignores the generated: timestamp); preserves the
  working tree when run unattended

enrich_staging_domains.py stays ignored (belongs to the clickgrab trend).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 13:29:03 -06:00
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00
iimp0ster 5386944603 Merge pull request #132 from iimp0ster/chore/tame-dependabot
chore(deps): tame Dependabot (group + monthly)
2026-06-12 21:00:45 -06:00
imposterandClaude Opus 4.8 93655c550d chore(deps): tame Dependabot — group updates, monthly cadence
First-run Dependabot opened one PR per outdated dependency across 4
ecosystems (a dozen+ at once). Group all bumps per ecosystem into a
single PR and switch weekly -> monthly so a scan yields at most ~4 PRs.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:49:11 -06:00
iimp0ster cdcaad05d2 Merge pull request #119 from iimp0ster/security/hardening
security: harden supply chain, escaping, Actions, and governance
2026-06-12 20:43:15 -06:00
imposterandClaude Opus 4.8 0c3709aa7e security: harden site supply chain, escaping, Actions, and governance
XSS:
- Escape `</` in all 5 jsonify-into-<script> data blobs so contributed
  YAML cannot break out of the script context (verified: JSON still
  parses, no </script breakout)
- Add `| escape` to contributor-controlled fields in chokepoint-card.html
  and ~71 value outputs in the chokepoint detail layout

Supply chain (SRI):
- Pin highlight.js, d3, and Chart.js CDN includes with sha384 integrity +
  crossorigin (hashes computed from the immutable versioned URLs)
- Document why cdn.tailwindcss.com cannot take SRI + the real fix

GitHub Actions:
- SHA-pin all 7 third-party actions to commit SHAs (version in comment)

Governance:
- SECURITY.md (private disclosure policy + scope: detection content is
  intentional, not a vuln)
- CODEOWNERS routing review to @iimp0ster
- Dependabot for github-actions / bundler / npm / pip

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:24:30 -06:00
iimp0ster 14d42ef5b5 Merge pull request #118 from iimp0ster/feat/social-preview
feat(seo): add social preview card for link shares
2026-06-12 15:30:48 -06:00
imposterandClaude Opus 4.8 4b21a96965 fix(seo): kicker line matches site nav headings
SIGMA -> CHOKEPOINTS in the social card kicker.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:26:39 -06:00
imposterandClaude Opus 4.8 8094344d9f feat(seo): add social preview card for link shares
1200x630 og:image in the playingwithpackets card style: navy field,
Press Start 2P title, tagline, framed arcade artwork strip, site URL.
Wired site-wide via jekyll-seo-tag front matter defaults with
twitter:card summary_large_image; pages can override with their own
image front matter.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:24:23 -06:00
iimp0ster 3089493ec8 Merge pull request #117 from iimp0ster/docs/readme-refresh
docs(readme): sync README with live site content
2026-06-12 07:47:43 -06:00
imposterandClaude Opus 4.8 fc34754138 docs(readme): sync README with live site content
- Chokepoint index: 9 -> 13 entries (adds AiTM WebSocket Kit Relay,
  OAuth Device Code Phishing, Graph API Recon Burst, Device PRT
  Enrollment); names and tactic columns now match the canonical YAML
- Why This Exists: replace misattributed dwell-time stat with verified
  figures (M-Trends 2025 median dwell 11 days; Unit 42 GIRR 2026
  first-quartile time-to-exfiltration 72 minutes)
- Attack chains: fill in ransomware coverage (260 procedures, 36 reports)
- Trends: add missing Software Impersonation Infrastructure entry;
  refresh ClickFix and Edge Exploit figures to current dashboards
- Framework: question list now verbatim with the site; mention the
  interactive relationship map
- New Prevention Layer section (per-chokepoint prevention opportunities
  + MagicSword application-control mapping)

Audited against the live site and chokepoint YAMLs as of 2026-06-12.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 07:37:56 -06:00
iimp0ster 141dfa4b82 Merge pull request #116 from iimp0ster/feat/readme-pixel-logo
docs(readme): add arcade pixel-art repo logo
2026-06-12 06:58:21 -06:00
imposterandClaude Opus 4.8 2b7e3d3328 docs(readme): add arcade pixel-art repo logo
RNC-with-body-triangle artwork in a versus-game frame with the Press
Start 2P title band and tagline, matching the Tacklebox README lockup.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 06:55:45 -06:00
iimp0ster e349c48119 Merge pull request #115 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
fix(nav): full-screen mobile menu with Trends accordion
2026-06-11 10:27:48 -06:00
imposterandClaude Opus 4.8 0d0c14d7c3 fix(nav): full-screen mobile menu with Trends accordion
Replace the overflowing right-column mobile menu with a full-screen overlay: decluttered top bar (brand + hamburger), one item per row with large tap targets, a collapsible Trends accordion (no longer dumped inline), and theme/GitHub/MagicSword in a footer row. Move the overlay outside .site-nav so position:fixed isn't trapped by the nav's backdrop-filter containing block, and bind the theme toggle to all .js-theme-toggle buttons. Desktop nav unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 10:23:34 -06:00
iimp0ster 04c0e3005a Merge pull request #114 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
Site: MagicSword integration, TTP graph, redesign + logo fix
2026-06-11 09:20:19 -06:00
imposterandClaude Opus 4.8 a8728bb20b fix(nav): prevent brand/toolbar overlap on mobile
On <=900px the Press Start 2P brand (~240px) collided with the nav toolbar. Pare the toolbar to theme + hamburger (GitHub stays in the menu's Contribute, MagicSword on the homepage card), shrink the brand to .6rem, and cap its width with ellipsis so the full title fits at 375px and truncates cleanly on narrower screens. Desktop unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:31:51 -06:00
imposterandClaude Opus 4.8 d3d3538f17 content: chokepoint, trends, and framework updates
Refresh chokepoint YAML entries, trends pages (incl. masq-infra rewrite), framework page, search index script, build aggregation, and pixel nav/section icons.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 5982b5e468 style: arcade theme layer + chokepoint page redesign
Arcade theme stylesheet, premium chokepoint hero/sidebar styling, trends submenu, and hero treatments.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 f93cd02398 feat(magicsword): prevention integration + transparent logo
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00
imposterandClaude Opus 4.8 e80dea6bd9 chore: gitignore internal planning and intel material
Keep GSD planning, draft detections, mockups, local intel hunt data, and intel-pipeline scripts out of the public repo.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00
iimp0ster 2588b2ee36 Merge pull request #111 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
fix(styles): add missing cp-section-icon/card/heading CSS inline
2026-05-29 21:32:37 -06:00
imposterandClaude Sonnet 4.6 2054e7c709 fix(styles): add missing cp-section-icon/card/heading CSS inline
Section icon HTML was committed without its companion CSS, leaving
SVGs unconstrained and rendering full-page on all chokepoint pages.
Inlines the four missing rules directly in chokepoint.html until
assets/css/style.css is committed as part of the MagicSword rollout.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 21:27:44 -06:00
iimp0ster 03c59a30fa Merge pull request #110 from iimp0ster/clean/public-site
Clean/public site
2026-05-29 21:14:31 -06:00
iimp0ster d88a45a53b Merge pull request #109 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
feat(chokepoints): add 4 AiTM / Tycoon 2FA chokepoints + site updates
2026-05-29 21:03:43 -06:00
imposterandClaude Sonnet 4.6 ccd74299b0 fix(template): xml_escape note/description fields to prevent bare HTML tags
Payload Note and variant Notes fields output unescaped, so literal HTML
tags in YAML prose (e.g. "<a> element" in DownloadFix variant note) were
parsed by htmlproofer as real anchor tags with missing href.

Add xml_escape to p.Note, v.Notes/NotesShort, and src.Notes outputs.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 21:00:00 -06:00
imposterandClaude Sonnet 4.6 57a8b751de fix(ci): strip baseurl prefix so htmlproofer resolves _site paths correctly
Jekyll builds with --baseurl "/detection-chokepoints", so all absolute
links in the HTML carry that prefix. htmlproofer checks these against
_site/ directly, so without --swap-urls it looks for
_site/detection-chokepoints/... instead of _site/... and fails on
every internal link — CSS, nav, chokepoint cross-refs, everything.

--swap-urls "^/detection-chokepoints:" strips the prefix before each
path lookup, making the checker match the actual _site/ layout.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:39:17 -06:00
imposterandClaude Sonnet 4.6 25c5f836e0 fix(ci): exclude assets/lures/ from htmlproofer link checks
Lure files use bare <a> elements intentionally (defanged phishing samples).
Add --ignore-files regex to skip the entire lures directory.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:24:48 -06:00
imposterandClaude Sonnet 4.6 a9dd68778b fix(ci): fix all html-proofer 5.x flag incompatibilities
- Pin gem to ~> 5.2 to prevent future silent upgrades
- Drop OpenGraph from --checks (not valid in 5.x; valid: Links,Images,Scripts)
- Add explicit .html argument to --assume-extension (required in 5.x)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:12:19 -06:00
imposterandClaude Sonnet 4.6 fbe79e5c0d fix(ci): drop --ignore-urls flag (changed in html-proofer 5.x)
Flag format changed between 4.x and 5.x; pattern was being treated as a
directory path. Redundant anyway since --disable-external skips all
external URLs including github.com links.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:04:01 -06:00
imposterandClaude Sonnet 4.6 04298039e8 fix(ci): update htmlproofer flags for html-proofer 5.x
--check-html and --typhoeus-config were removed in html-proofer 5.x.
Replace with --checks Links,Images,Scripts,OpenGraph (explicit defaults).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 20:00:22 -06:00
imposterandClaude Sonnet 4.6 2a4d06baef fix(yaml): fix mapping-values-not-allowed parse errors in 3 chokepoints
Plain scalars with "key: value" patterns (authenticationProtocol: deviceCode,
incomingTokenType: primaryRefreshToken, Account Discovery/Manipulation colons)
rejected by PyYAML. Fixed with > block scalar indicators and quoted Name/TheConstant
values.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 19:57:01 -06:00
imposterandClaude Sonnet 4.6 424a81212a feat(chokepoints): add 4 AiTM Tycoon 2FA chokepoints from Elastic research (2026-05-27)
Promotes intel-pipeline drafts to canonical chokepoints/. All entries sourced
from Elastic Security Labs Tycoon 2FA AiTM detection engineering article.

New entries:
- credential-access/aitm-websocket-relay (T1539, T1078.004) -- CRITICAL
  Node.js UA on Entra sign-in + two-tier ASN correlation. Covers Tycoon 2FA
  and EvilProxy variants.
- defense-evasion/oauth-device-code-phishing (T1550.001) -- HIGH
  MAB app ID + deviceCode + isInteractive = high-confidence victim redemption.
  CA policy "Block device code flow" documented as prevention.
- discovery/graph-api-recon-burst (T1087.004, T1069.003, T1526) -- HIGH
  4+ Graph API endpoint categories in 60s = automated operator console.
  Requires Graph Activity Logs. c_sid pivot mistake documented.
- persistence/aitm-device-prt-enrollment (T1098.005) -- HIGH
  axios UA on DRS enrollment generates audit event; device PRT survives
  revokeSignInSessions. IR playbook fix: delete devices BEFORE revoking.

12 Sigma rules (research/hunt/analyst per chokepoint). KQL implementations
documented inline for graph-api-recon-burst and aitm-device-prt-enrollment
analyst rules that require multi-table correlation.

Pending lab validation (documented inline):
- RawLogs samples not yet attached
- filter_legit_automation placeholders need tenant-specific UPNs
- AuditLogs UserAgent field name to verify for prt-enrollment
- graph-api-recon-burst: KQL required (Sigma cannot express category-count)

Closes: intel/aitm-drafts-2026-05 (drafts branch; this promotes to canonical)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:53 -06:00
imposterandClaude Sonnet 4.6 04e84dbab8 feat(site): weekly chokepoint updates and site improvements
Update 9 published chokepoints with accuracy fixes and variant additions.
Update layouts, attack chains, trends pages, and framework content.

Note: _config.yml, _includes/nav.html, assets/css/style.css, and index.html
contain in-progress MagicSword affiliate integration -- held back from this PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 15:07:33 -06:00
iimp0ster e8a2b5af43 Merge pull request #103 from iimp0ster/clean/public-site
Clean/public site
2026-04-22 14:47:57 -06:00
imposter febf1edb32 feat(site): add nav hamburger script, link-check workflow, and gitignore for local/tooling
Made-with: Cursor
2026-04-22 14:39:22 -06:00
imposter 859c5ace3c chore: drop local/planning artifacts from public branch
Made-with: Cursor
2026-04-22 13:04:35 -06:00
imposter d9caddcea8 feat(nav): enhance navigation with responsive design and new elements
- Added a hamburger menu for mobile view, improving accessibility and usability on smaller screens.
- Updated navigation links to be more flexible and responsive, adjusting layout based on screen size.
- Introduced styles to prevent horizontal overflow for images and other media.
- Enhanced the overall structure of the navigation bar for better alignment and spacing.

This update aims to create a more user-friendly navigation experience across different devices.
2026-04-22 13:02:46 -06:00
iimp0ster 871f8ea7ba Merge pull request #101 from iimp0ster/feat/kitsune-attack-chains-readme
Attack chain rebuild via Kitsune + ORKL, trend payload examples, README refresh
2026-04-14 14:08:20 -06:00
imposterandClaude Opus 4.6 479d465c44 docs(readme): rewrite in project voice, remove em dashes, reflect current state
The previous README was outdated (chokepoint count off by 2, no mention of 3 of the 5 attack chains, no trends section, framework section referenced only FRAMEWORK.md instead of the live framework page) and written in a tone that didn't match the rest of the site's voice.

This rewrite:
- Opens with the value prop in two sentences instead of the Thermopylae/Fulda Gap analogy (moved to framework page where it belongs)
- Leads Why This Exists with the Kaspersky 8/8 finding and the broader 5-chain convergence result from the Kitsune + ORKL rebuild, ties dwell time compression (Mandiant M-Trends 2025) to why chokepoints matter now
- Corrects chokepoint index from 7 to 9 entries (adds LSASS Credential Dumping and BYOSI Scripting Interpreters which were missing)
- Adds Attack Chains section listing all 5 chains with shared-technique counts
- Adds Trends section (ClickFix ClickGrab + Defused Cyber edge-exploit telemetry)
- Framework section now points at the interactive page, not the markdown file
- Contributing section aligns with the partial-contributions tone used on CONTRIBUTING.md
- Resources table adds Kitsune, ORKL, and Defused Cyber as first-class sources
- 0 em dashes (was 18). Peer-to-peer voice throughout.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 14:00:29 -06:00
imposterandClaude Opus 4.6 bf61a0c8fc style(templates): remove em dashes from shared attack-chain templates
- ttp-vertical-diagram.html: TTP card legend (applies to all attack chain pages via shared include)
- attack-chain.html: Chokepoint Convergence Principle callout and Actor Convergence Matrix description (applies to all attack chain pages via shared layout)

Replaces em dashes with periods or commas per project style. No content changes.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 13:59:59 -06:00
imposterandClaude Opus 4.6 17a8f877ad feat(trends): defang payloads, add detection logic + observed payload examples
Both trend pages now include paired collapsible blocks on each detection recommendation: one for real observed payloads (IOCs from the source dataset) and one for example Sigma-style detection logic. Formats match across the two pages.

clickgrab.md
- Add Example detection logic to all 7 detection recommendations (T1059 unusual parent->PS, cradle-agnostic network fetch, T1027 Base64 decode+execute, T1070 self-delete, INFRA CDN staging, T1218 MSIExec, T1059 inline decode-and-execute)
- Add Observed payloads collapsibles for T1218 MSIExec (3 examples) and T1059 inline decode (3 examples)
- Defang all malicious IOCs: shift-art.com, verifyhumanbot.com, port-5506 staging IPs
- Align h1 with colon separator instead of em dash

edge-exploits/index.html
- Add Observed payloads collapsibles to all 6 detection recommendations populated with real honeypot data (SD-WAN DCA bypass, Wildfly webshell upload, CitrixBleed 2, Bearer-token SQLi, pipe-to-shell, DCA credential access)
- Defang all malicious IOCs: CitrixBleed 2 operator IPs, pipe-to-shell staging (kernel.sh, moneroocean, 83.142, miso88, apache.selfrep), Ivanti reverse shell target, FortiWeb CIDR ranges, multi-device operator IPs, staging infrastructure entries
- Align h1 with colon separator matching clickgrab style; convert inline-styled meta div to .ep-meta class

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 13:59:44 -06:00
imposterandClaude Opus 4.6 40a10df78d feat(attack-chains): rebuild AiTM, hypervisor, and identity TTP overlap from Kitsune + ORKL
Apply the same Kitsune pipeline + ORKL corpus workflow previously used for the ransomware and infostealer attack chains to the remaining three chains. All three now use research-backed convergence data filtered to techniques observed in 2+ actors.

AiTM / Phishing Kits (11 reports, 5 kits, 12 shared techniques across 7 phases)
- Tycoon 2FA, Evilginx, EvilProxy, Sneaky 2FA, Device Code Phishing
- Sources: Microsoft Threat Intelligence, Sekoia, Proofpoint, Volexity, ANY.RUN, Resecurity, Silent Push
- T1557 AiTM and T1566.002 Spearphishing Link converge across all 4 proxy kits; T1078 Valid Accounts across 4 of 5

Hypervisor Compromise (12 reports, 5 actors, 22 shared techniques across 9 phases)
- BRICKSTORM/UNC5221, UNC3886, UNC3944/Scattered Spider, Play, Alphv/BlackCat
- Sources: CISA, Mandiant/Google Threat Intelligence, Trend Micro, Varonis, Sygnia
- T1190 Exploit Public-Facing App + T1078 Valid Accounts hit 4 of 5; T1486 Data Encrypted for Impact across all 3 ransomware actors

AD / Identity Domination (12 reports, 5 actors, 23 shared techniques across 8 phases)
- APT29/Midnight Blizzard, Storm-0501, Storm-2372, Scattered Spider, Ransomware Operators
- Sources: Microsoft Threat Intelligence, CrowdStrike, Mandiant/Google Threat Intelligence, CISA, ReliaQuest, The DFIR Report
- T1078 Valid Accounts hit by all 5; T1078.004 Cloud Accounts + T1110.003 Password Spraying hit by 4 of 5; T1550.001 Application Access Token converges across the 3 identity-centric actors

Each page now follows the consistent pattern: redundant mitre_techniques blocks removed (TTP diagram renders these from _data/), em dashes replaced, static References section replaced with Research Methodology crediting Kitsune + ORKL. Last-updated stamps bumped to 2026-04-14.

Reproducibility artifacts kept: scripts/build_{aitm,hypervisor,identity}_overlap.py regenerate the YAML from actor-TTP pair input.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 13:58:13 -06:00
iimp0ster 93e3137b06 Merge pull request #100 from iimp0ster/feat/osint-pipeline-fix-and-site-quality
Feat/osint pipeline fix and site quality
2026-04-13 19:57:34 -06:00
imposterandClaude Opus 4.6 6c61955380 refactor(chokepoints): tighten Detection Logic prose and layout cleanup
- Condense Logic fields across 8 chokepoint pages (22 blocks total) from pseudocode-style WHERE/AND/OR constructs into plain-language 1-3 sentence descriptions matching the clickfix reference pattern. Technical specificity preserved (event IDs, access masks, paths, thresholds).
- LSASS page: align structure with clickfix template (remove redundant AttackerControls/AttackerCannotControl blocks, reformat RawLogs samples to match clickfix style with Key signal comments, add URL fields to OSINT pivots so queries are clickable)
- Layout: remove tier badges from chokepoint stage headers and raw log sample cards so badges only appear on Sigma rule examples where they add context. Switch detection logic block from white-space:pre to pre-wrap with word-break so long rules wrap instead of hiding under the horizontal scrollbar.
- Remove remaining em dashes from chokepoint layout intro copy ("Each stage is an invariant condition...", "Tools and methods that exploit this chokepoint...")

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:56:12 -06:00
imposterandClaude Opus 4.6 82321099e6 style(landing): unified hero treatment, infosec iconography, voice alignment across landing pages
- Apply site-wide hero gradient (radial orange glow + diagonal bg) to framework, trends, and attack-chains landing pages so all four landing pages read as one system
- Replace emoji icons on trends pillars, framework testing cards, and attack-chains ecosystem flow boxes with inline SVG icons (shield, crosshair, cluster, radar, server rack, envelope, lock, pulse, arrows, chart) in accent-tinted tiles
- Rewrite attack-chains landing page copy in Tyler's peer-to-peer voice; shorten Kaspersky reference to a single hyperlinked title; remove "coming soon" footers from trends and attack-chains
- Tighten ac-prose top padding after the actor convergence matrix, reduce actor-matrix bottom margin
- Remove all em dashes from landing page prose (chokepoints index, framework, trends, attack-chains)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:55:48 -06:00
imposterandClaude Opus 4.6 568daa3293 feat(infostealers): rebuild TTP overlap from Kitsune + ORKL analysis
Replace hand-curated infostealer TTP data with research-backed convergence analysis extracted via Kitsune pipeline from 13 vendor and government reports sourced via ORKL. Now covers RedLine, LummaC2, Vidar, StealC, and Raccoon with 28 shared techniques across 8 MITRE tactics, filtered to techniques observed in 2+ families.

Also removes redundant mitre_techniques blocks from infostealer page stages (TTP overlap diagram already renders these) and adds a Research Methodology section crediting Kitsune and ORKL for data provenance.

scripts/build_infostealer_overlap.py is kept as a reproducibility artifact for regenerating the YAML when new reports are analyzed.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:55:23 -06:00
imposterandClaude Opus 4.6 ac92e4fff8 feat(framework): polish interactive framework page and restore trends/ransomware content
- Framework page: D3 graph zoom controls (in/out/reset + scroll/pan), fix chokepoint URLs to include baseurl, uniform-height step cards with shared detail panel replacing in-place expansion, infosec SVG icons replacing emojis
- Landing page: strip redundant 6-step framework section in favor of "Learn the framework" link to /framework/
- Ransomware page: restore filtered TTP layout (remove re-added mitre_techniques blocks from stages), remove VSS table and per-actor report lists, keep concise Research Methodology note crediting Kitsune + ORKL
- Edge-exploits page: restore Apr 13 honeypot data window (15,001 attempts, 25 decoy types, 40+ CVEs, SAP burst section)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:54:57 -06:00
imposter 990c608f91 docs(05-01): complete framework page plan summary 2026-04-13 14:49:18 -06:00
imposter 67e3857fb7 feat(05-01): update nav Framework link to local /framework/ page with active state
- Replace external GitHub FRAMEWORK.md link with local /framework/ href
- Remove target=_blank and rel=noopener (no longer external)
- Add active state conditional matching other nav items pattern
2026-04-13 14:46:37 -06:00
imposter 32ccd965e5 feat(05-01): create interactive framework page with all content sections and Liquid graph data
- Hero section with subtitle and Red Canary attribution
- 6 step cards with click-to-expand examples (SMB lateral movement worked example)
- Step 4 highlighted as THE CHOKEPOINT with critical red styling
- Detection maturity model (research/hunt/analyst) with pseudocode
- Chokepoint vs tool detection comparison
- Relationship graph container with tactic filter buttons
- Liquid-generated __GRAPH_DATA from site.data.chokepoints
- D3 v7 CDN load + framework-graph.js reference
- Testing section with 4 validation questions
- CTA section linking to chokepoints, attack chains, contribute
- All colors via CSS custom properties (--accent, --critical, etc.), no hardcoded hex
- No em dashes in prose
2026-04-13 14:46:30 -06:00
imposter 4ea07ce3e1 docs(05-02): complete framework-graph.js plan summary
- D3 force-directed graph visualization script created (288 lines)
- All 17 acceptance criteria verified
- SUMMARY.md documents implementation, decisions, and self-check
2026-04-13 14:09:45 -06:00
imposter a7a15ccc93 feat(05-02): create D3 force-directed graph for framework page
- Reads window.__GRAPH_DATA (set by Liquid in framework/index.html)
- D3 v7 force simulation with link, charge, center, and collision forces
- Tactic/chokepoint/technique node sizing, coloring, and labeling
- Tactic filter buttons via .graph-btn[data-filter] elements
- Hover tooltip with connection highlighting (dims unrelated nodes)
- Chokepoint click navigates to detail page via window.location.href
- Colors read from CSS custom properties at runtime (no hardcoded hex)
- Variation count badge on chokepoint nodes with vars > 0
- Link deduplication for Liquid output
- Responsive resize handler with 250ms debounce
2026-04-13 14:09:05 -06:00
imposterandClaude Opus 4.6 9287eda665 docs(05): create phase plan for interactive framework page
Two plans covering the full framework page: content/layout/nav (Plan 01)
and D3 relationship graph visualization (Plan 02). Both Wave 1, parallel.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 11:27:59 -06:00
imposterandClaude Sonnet 4.6 39df565389 refactor: filter single-actor techniques from TTP diagram and streamline ransomware page
TTP diagram now only shows techniques shared by 2+ actors, focusing on
convergence signals rather than actor-specific procedures. Ransomware
attack chain page removes inline MITRE technique lists (now driven by
data layer), drops VSS deletion table (covered by chokepoint page),
and condenses report bibliography into summary format.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-13 10:39:15 -06:00
imposterandClaude Sonnet 4.6 2061709d40 feat(trends): update edge-exploits page with Apr 13 honeypot data
- Period: Mar 14 – Apr 13, 2026 (was Mar 4 – Apr 3)
- Total: 15,001 attempts across 25 decoy types (was 12,420 / 22)
- CitrixBleed 2 (CVE-2025-5777): 8,112 hits, 54% of all traffic; Apr 6 new peak (1,726)
- Added SAP section: CVE-2022-22536 burst Apr 9–11, 1,024 hits, 176 unique IPs in 72h
- SAP rises to #3 target (1,179 decoy hits); CVE-2025-31324 also present
- SonicWall: 478 hits, 284 unique IPs — most distributed campaign in dataset
- SD-WAN: 1,260 hits this window; FortiWeb up to 1,027
- Updated daily chart, CB2 chart, stats strip, bar chart, and all callouts
- Added SAP nav entry to sidebar

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-13 10:29:02 -06:00
imposterandClaude Sonnet 4.6 721d292fe6 docs: rewrite README with full contributor guide and partial contribution paths
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-13 09:52:38 -06:00
iimp0ster b280f61b7f Merge pull request #99 from iimp0ster/feat/osint-pipeline-fix-and-site-quality
Feat/osint pipeline fix and site quality
2026-04-12 19:22:41 -06:00
imposterandClaude Sonnet 4.6 7361783dea chore: add planning artifacts, CLAUDE.md, docs, and pipeline dependencies
- .planning/: GSD project roadmap, phase plans, research, and verification
  docs for all 4 phases (baseline cleanup, writing, visual design, pipeline fix)
- CLAUDE.md: AI assistance guidelines for this repo
- docs/: LEARNED.md, CHALLENGES.md, and project-knowledge.md for session context
- attack-chains/webdav.json: WebDAV attack chain data
- package.json / package-lock.json: js-yaml dependency for build tooling
- _data/ransomware_ttp_overlap.yml, attack-chains/ransomware.md: upstream merge updates

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-12 19:18:36 -06:00
imposterandClaude Sonnet 4.6 61b9151dc5 merge: integrate upstream lsass credential dumping chokepoint (PR #92)
Merges remote changes: new lsass-credential-dumping chokepoint YAML,
emulation script, and three-tier Sigma rules (research/hunt/analyst).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-12 19:17:52 -06:00
imposter b779cb356d feat(04-02): add MIN_RECORD_FLOOR guard to build_data.py (PIPE-03)
- Add MIN_RECORD_FLOOR = 5 constant next to CONFIDENCE_THRESHOLD
- Add --min-records CLI argument (default: MIN_RECORD_FLOOR, set 0 to disable)
- Add floor guard block: exits sys.exit(1) without writing output when filtered
  record count is below floor
- Guard fires after filtering, before output dict assembly
2026-04-12 19:00:26 -06:00
imposter 3e6743880a refactor(04-02): replace inline confidence_label/rescore_record with pipeline_utils imports
- fetch_payload_chains.py: imports confidence_label, rescore_record from pipeline_utils; removes both inline definitions
- claude_triage.py: imports confidence_label from pipeline_utils; removes inline definition
- cluster_campaigns.py: imports confidence_label from pipeline_utils; removes inline definition
- build_data.py: imports confidence_label from pipeline_utils; removes inline definition
2026-04-12 11:01:13 -06:00
imposter 1a7f526c54 feat(04-01): create merge_records.py for three-source cache merge
- Merges ioc_records.json, infra_records.json, enriched_infra.json into enriched_records.json
- Deduplicates by domain (case-insensitive), first occurrence wins
- Two-pass approach: first build domain->sources map, then dedup and flag multi_source
- Sets multi_source=True on records whose domain appears in 2+ source files
- Imports rescore_record from pipeline_utils for behavioral scoring
- Handles missing source files gracefully (WARN, not crash)
- No API calls — pure I/O merge
2026-04-12 10:47:45 -06:00
imposter 4bbb840ef4 feat(04-01): create pipeline_utils.py with behavioral confidence scoring
- confidence_label maps 0-100 score to confirmed/high/medium/low
- rescore_record uses behavioral signals (chain_observed 40pts, multi_source 20pts)
- SHA-256 presence drops from 30pts to 5pts (structural, not behavioral)
- Feed membership scores 0pts (not behavioral per PIPE-02)
- Single source of truth for scoring logic across all pipeline scripts
2026-04-12 10:47:12 -06:00
imposter d3b7c418a6 fix(03-gap): restore Phase 1 Liquid fix and Phase 2 _config.yml em dash lost in merge 2026-04-12 10:18:58 -06:00
imposter 5b79b4139b merge(03-01): copy button feedback, tier accents, mobile table wrappers 2026-04-12 10:06:12 -06:00
imposter a878545825 feat(03-01): wrap all 5 cg-table elements in masq-infra.md with table-wrapper
- Table-wrapper div applied to Top Families, Lure Type, Confirmed Delivery Domains,
  Favicon Clusters, and Samples tables (UX-03)
- Prevents horizontal overflow bleed on 390px viewports
- .table-wrapper { overflow-x: auto } already defined in style.css
2026-04-12 09:40:44 -06:00
imposter 5c5a39cb6b feat(03-01): wire tier modifier classes into sigma-block Liquid template locations
- Accordion detection rules: extract sigma_tier from sigma_key, apply sigma-block--{{ sigma_tier }} (UX-02)
- Hunt-network hard-coded block: add sigma-block--hunt (UX-02)
- Research/Hunt/Analyst tabs loop: apply sigma-block--{{ level_lower }} (UX-02)
- Three non-tiered locations (EarlyDetections x2, Emulation) left unchanged
2026-04-12 09:22:59 -06:00
imposter ce0c0b8311 feat(03-01): add copy-button .copied CSS state and tier accent left-border CSS
- Add .sigma-block--research/hunt/analyst with 4px left border accent (UX-02)
- Add .sigma-btn.copied rule with green color and border feedback (UX-01)
- Update copyCode() to toggle .copied class on click and remove after 1.8s (UX-01)
2026-04-12 08:33:32 -06:00
imposter 5756319e51 fix(02-gap): voice-tighten edr-bypass and remote-execution descriptions; fix _config.yml em dash 2026-04-11 22:33:46 -06:00
imposter 8b6a951e8c docs(02-02): complete TheConstant header render and template em dash removal plan summary 2026-04-11 20:02:12 -06:00
imposter 244dbd6f20 fix(02-02): remove em dash from footer tagline in default layout
- Replace &mdash; with pipe separator in footer tagline
- Tagline text preserved; jekyll build --strict passes clean
2026-04-11 19:59:04 -06:00
imposter cfee2234a5 feat(02-02): add TheConstant invariant block to chokepoint detail-page header
- Insert cp.TheConstant aside with .cp-invariant/.cp-invariant-label CSS classes after description paragraph
- Replace all &mdash; entities in sigma-label and det-meta-label UI chrome with colons
- Fix inline prose em dashes: satisfy comma fix, Lure label, list-grows sentence, Goal label
- All em dashes removed from rendered HTML output; Liquid/CSS/HTML comments untouched
- jekyll build --strict passes clean; THE CONSTANT renders above first <details> block
2026-04-11 19:56:32 -06:00
iimp0ster 232d90ecb2 Merge pull request #92 from NovaSky0x1/NovaSky0x1/lsass-credential-dumping
feat(chokepoint): add LSASS Credential Dumping (T1003.001)
2026-04-11 19:48:29 -06:00
imposter c365cdbae0 docs(02-01): complete em dash removal and voice tightening plan summary 2026-04-11 19:46:40 -06:00
imposter 7f76a6895c refactor(02-01): voice tighten Description fields and remove remaining em dashes
- browser-credential-theft.yml: rewrite Description to lead with invariant (target paths), break stat dump into short sentences; fix em dashes in Invocation and References Name fields
- web-shells.yml: rewrite Description to open with mechanism ("A script lives in the web root"); fix em dashes in Invocation code comments, detection logic, and References Name fields
- renamed-rmm-tools.yml: rewrite Description to drop passive opener, state 4-step invariant concisely; fix em dashes in Invocation code comments, Sources list items, and References Name fields
- byosi-scripting-interpreters.yml: rewrite Description to drop "Adversaries bring" opener, lead with vendor-signed interpreter pattern; fix em dashes in References Name fields
- ransomware-service-manipulation.yml: rewrite Description to drop "This service manipulation phase" opener, tighten to five short sentences; fix em dash in Invocation code comment; preserve Windows Event Log quoted strings (Service State Change, Service Start Type Changed)
2026-04-11 19:40:06 -06:00
imposter 02d545e7f2 refactor(02-01): remove prose em dashes from YAML and Markdown files
- clickfix-techniques.yml: fix 10 em dashes in Notes, Detections, and References Name fields; cut weak closer from Description; quote YAML Name values with colons
- edr-bypass-techniques.yml: fix 7 em dashes in Context and References/Variation Name fields; quote YAML Name values with colons
- remote-execution-tools.yml: fix 5 em dashes in References Name fields; quote YAML Name values
- trends/clickgrab.md: fix 15 em dashes in titles, prose paragraphs, and callouts; preserve Liquid empty-cell placeholders
- trends/index.md: fix 5 em dashes in hero text, pillar descriptions, and front matter description
- trends/masq-infra.md: fix 5 em dashes in front matter, methodology, and chokepoints prose; preserve 7 Liquid table placeholder instances
2026-04-11 18:58:02 -06:00
imposter c74517b111 merge(01-01): integrate baseline cleanup fixes 2026-04-11 18:13:43 -06:00
imposter 7edd1dd37c fix(01-01): fix invalid Liquid parentheses syntax in emu_lang assignment
- Split single-line append with parenthesized filter chain into two-step assign
- emu_lang_raw computes the language string, emu_lang appends the prefix
- Resolves Jekyll warning emitted for every chokepoint with an emulation block
- jekyll build --strict now exits 0 with zero warnings
2026-04-11 18:12:25 -06:00
imposter a1b9b4c1f4 fix(01-01): replace positional forloop.parentloop.index with field-based tier matching
- Remove forloop.parentloop.index == 2 and == 3 conditions from detection rule display logic
- Replace with tier_lower field-based matching so any stage position renders correctly
- Hunt tier stages now show hunt and analyst detections regardless of array position
- Analyst tier stages now show research detection regardless of array position
2026-04-11 18:12:03 -06:00
imposterandClaude Opus 4.6 77b60bc52c fix: quote YAML value containing colon in remote-execution-tools
Unquoted colon in Invariant field caused yaml.scanner.ScannerError
in aggregate.py CI step.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 15:08:21 -06:00
imposterandClaude Opus 4.6 d54c031940 refactor: clean up writing style across all chokepoint pages
Remove em dashes from prose throughout all 7 remaining chokepoints,
replacing with periods, commas, or semicolons for tighter writing.
Remove AttackerControls/AttackerCannotControl bulleted lists (redundant
with chokepoint stage descriptions). Intel reference names preserved.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 14:57:48 -06:00
imposterandClaude Opus 4.6 8a3b14a987 refactor: clean up clickfix chokepoint writing style
Remove em dashes throughout, replace with periods/commas for cleaner
prose. Remove AttackerControls/AttackerCannotControl bulleted lists
since the chokepoint stages describe the same information. Tighten
description to match Tyler's writing style.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 14:52:02 -06:00
imposterandClaude Opus 4.6 b4c94d3081 fix: use .badge base class for actor status badges
Reuse the proven .badge class from style.css instead of custom
ac-actor-status styles. Eliminates border/alignment mismatch.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-07 15:15:48 -06:00
imposterandClaude Opus 4.6 caaab07ed3 fix: match actor status badges to .badge base style from chokepoint pages
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-07 14:53:01 -06:00
imposterandClaude Opus 4.6 815275ec35 fix: badge padding and line-height so border fully wraps text
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-07 14:47:34 -06:00
imposterandClaude Opus 4.6 17fb3e0620 fix: place actor status badges below name, widen actor column
Badges now render on their own line beneath the actor name to prevent
overflow into adjacent columns. Actor column widened to 180px.
Added espionage and legacy badge color variants.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-07 14:43:50 -06:00