Commit Graph
357 Commits
Author SHA1 Message Date
imposterandClaude Opus 4.8 7e9bd97379 feat(social): per-section link-preview cards for chokepoints, attack-chains, trends
A shared link now signals what it is — a new chokepoint, attack chain, or trends
entry — instead of the generic site card. Home and generic pages keep og.png.

- templates/og-card.html: HTML card template (build tool, excluded from site),
  rendered at 1200x630 with Press Start 2P / VT323 + the section pixel icon.
- assets/img/social/og-{chokepoints,attack-chains,trends}.png: the three cards.
- assets/img/pixel/trends.png: stripped the baked-in U-frame so the wave icon
  floats like the other nav icons.
- _config.yml: scoped jekyll-seo-tag defaults (chokepoints collection /
  attack-chains / trends); site-wide default unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-07-01 10:13:15 -06:00
iimp0ster b04b752382 Merge pull request #152 from iimp0ster/feat/attack-chain-convergence-viz
feat(attack-chains): convergence highlight + matrix row-mirror on actor select
2026-06-29 12:46:53 -06:00
iimp0ster 468988f597 Merge pull request #151 from iimp0ster/data/clickgrab-auto
chore: update clickgrab trends data [2026-06-29]
2026-06-29 12:44:26 -06:00
imposterandClaude Opus 4.8 fd3dae2a02 feat(attack-chains): convergence highlight + matrix row-mirror on actor select
Selecting 2+ actors on any attack-chain page now highlights the techniques they
all share in cyan (.state-converge) and fades single-actor cells (.state-partial),
so the convergence reads without inspecting per-actor dots. The same selection
mirrors onto the convergence matrix: selected actors' rows light in their own
colour, the rest dim, and the chokepoint (tfoot) invariant row stays fixed.
Legend hint updated to describe the cyan glow.

Verified on the ransomware page (Akira+Play = 19 shared cyan cells) at 1440 and
375 breakpoints, 0 console errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrCkcgXrEpHAiJRUhU9mFm
2026-06-29 12:04:25 -06:00
github-actions[bot] b3d19ec21a chore: update clickgrab trends data [2026-06-29] 2026-06-29 10:24:57 +00:00
iimp0ster 8319ceee31 Merge pull request #150 from iimp0ster/claude/clickgrab-conflicts-gh-actions-ytum2y
ci(clickgrab): weekly cadence + single rolling PR (stop the daily PR pileup)
2026-06-21 12:55:25 -06:00
iimp0ster 4017e54ead Merge pull request #149 from iimp0ster/data/clickgrab-2026-06-21
chore: update clickgrab trends data [2026-06-21]
2026-06-21 12:54:46 -06:00
github-actions[bot] 974ec6accd chore: update clickgrab trends data [2026-06-21] 2026-06-21 09:43:37 +00:00
Claude a0bb7bdddb ci(clickgrab): weekly cadence + single rolling PR
The daily cron cut a fresh dated branch (data/clickgrab-${DATE}) and opened
a new PR every run. Since each PR edits the tail + meta of the same growing
_data/clickgrab_trends.yml, they mutually conflict the moment one merges,
leaving a pileup of stuck PRs (#146/#147/#148).

Fixes the structure rather than the symptom:
- Publish to a fixed rolling branch (data/clickgrab-auto), force-pushed each
  run and refreshed via `gh pr edit`, so at most one ClickGrab PR is ever
  open and it always shows a clean append-only diff vs main.
- Drop cadence from daily to weekly (Mondays 06:00 UTC). The generator's
  14-day lookback + watermark dedup backfills every daily bucket regardless,
  so weekly captures the same data with far less churn.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YQzGNdzZK4svMZPTK9BikA
2026-06-21 04:20:55 +00:00
iimp0ster 5ec3a0d076 Merge pull request #145 from iimp0ster/data/clickgrab-2026-06-17
chore: update clickgrab trends data [2026-06-17]
2026-06-18 21:06:08 -06:00
github-actions[bot] 12fd998c56 chore: update clickgrab trends data [2026-06-17] 2026-06-17 10:47:50 +00:00
iimp0ster 39d56051b6 Merge pull request #144 from iimp0ster/feat/clickgrab-consolidated-source
ClickFix trends: re-source ingest + clean Carson three-feed model + classifier fix
2026-06-16 13:34:18 -06:00
iimp0ster a1ddcb7c78 Merge pull request #143 from iimp0ster/feat/edge-exploits-provenance
feat(trends): hosting-provenance section for edge-exploits
2026-06-16 13:34:01 -06:00
imposterandClaude Opus 4.8 6e4cd4bf93 docs(clickgrab): note build_domain_monthly + build_lure_keywords are manual-only
Both rebuild from the full local dataset (Carson XLSX / full MHaggis crawl history) that a fresh CI checkout cannot hold, so running them in the daily workflow would shrink the committed full-history files. Document them as manual/local refresh steps and correct the MHaggis feed label (volume, not behavioural — DECISIONS #012).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:58:28 -06:00
imposterandClaude Opus 4.8 a2f4d32bc8 fix(clickgrab): correct classifier regexes + refresh to 2026-06-16 export
Resolve the two classifier defects deferred in DECISIONS #013 and refresh the behavioural data to the current Carson export.

Classifier (build_domain_monthly.py): no_url now means 'no remote fetch' via REMOTE_FETCH_RE, catching single-slash http:/, ftp, UNC/WebDAV (\host, \IP@port\DavWWWRoot), and scheme-less bare-IPv4 fetches; base64 matches -e..-encodedcommand abbreviations via a base64-blob lookahead that excludes -ExecutionPolicy. Validated against the prior XLSX: reproduced the judge's predicted deltas exactly (May inline 93.9%, Feb 6.2%, +31 base64).

Data: regenerated from clickfix-domains-all-2026-06-16.xlsx (3321 domains, Aug 2025-Jun 2026). Trends prose re-derived - May base64 67% (354/528, 352/354 one token), May inline 92.4%, msiexec total 1054. June (partial) shows hex-XOR reclaiming 84% as the May base64 spike collapsed to 1%, framing May as a single campaign rather than a re-tooling.

Validated: scripts/validate_schema.py passes; render-checked.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:40:32 -06:00
imposterandClaude Opus 4.8 66034135c3 feat(clickgrab): re-source ingest + clean Carson three-feed trend model
Re-source ClickGrab ingest off the dead Git-LFS path onto raw GitHub blobs and re-architect the ClickFix trends page around three feeds, each used only for what it is reliable for (DECISIONS #010-012).

Ingest (#010-011): fetch MHaggis ClickGrab as raw blobs (upstream LFS quota exhausted); append-only idempotent volume generator + daily GHA for volume and Carson gist landscape count.

Behaviour (#012): rebuild the per-domain command classification from Carson's ClickFix Hunter export (build_domain_monthly.py) and re-plumb charts/cards to it, separating hex-XOR from base64 (the prior site-crawl source conflated them and measured ~93-99% noise). Trends prose corrected to the honest figures: May base64 69% (316/458), inline 95.2%, Nov msiexec 87% (669/767).

Workstream B: rank MHaggis lure-page HTML keywords (build_lure_keywords.py) into data-driven URLScan OSINT pivots on the clickfix chokepoint and enrich the multilingual IOK matcher.

Validated: scripts/validate_schema.py passes (13 chokepoints, 3 trends files). Deferred: two classifier regex bugs distort Dec-Apr months only; headline figures robust (DECISIONS #013).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:59:48 -06:00
imposterandClaude Opus 4.8 32260237fe chore: gitignore internal M3 provenance plan
Keep docs/M3-PROVENANCE-PLAN.md out of the public repo, matching the internal-material convention (DECISIONS.md, ATTEMPTS.md, .planning/). It is internal research synthesis for a separate workstream (DECISIONS #007), not site content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:58:44 -06:00
imposterandClaude Fable 5 123aedf7ed feat(trends): hosting-provenance section for edge-exploits
Publishes the ASN/hosting provenance the local enrichment produces -- a stacked
per-month chart + top-ASN table on the page, so abuse-tolerant hosting rotation
becomes visible over time. Aggregates only; no IPs in the repo (decision #009).

- transform_provenance.py: cache/edge_exploits_asn.json (local enrichment output)
  -> _data/edge_exploits_provenance.yml. Deterministic, IP-free, no external calls.
- index.html: "Hosting Provenance" section -- stacked ASN-by-month chart + top-ASN
  table with bulletproof flags + nav entry.
- validate_schema.py: structural spec for the new provenance data file.
- refresh_edge_exploits.py: weekly job now regenerates volume + provenance
  (runs the local enrichment when present; volume-only otherwise).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-15 00:09:20 -06:00
iimp0ster 35e5159e3f Merge pull request #142 from iimp0ster/chore/gitignore-enrichment
chore: keep ASN enrichment tooling local (gitignore)
2026-06-14 23:39:43 -06:00
iimp0ster ee17d6a0b0 Merge pull request #140 from iimp0ster/feat/validate-trends-data
feat(ci): extend data validator to trends _data files
2026-06-14 23:39:01 -06:00
iimp0ster 2f0720c964 Merge pull request #139 from iimp0ster/feat/edge-exploits-recon-leadtime
feat(trends): recon-vs-exploitation split + recon->exploit lead-time
2026-06-14 23:38:19 -06:00
imposterandClaude Fable 5 d88a7cd365 chore: keep ASN enrichment tooling local (gitignore)
Enrichment touches IPs/keys/external lookups and must not live in the repo --
the repo holds only published site data (decision #009). Mirrors the existing
scripts/enrich_staging_domains.py entry. The scripts run locally and write only
IP-free aggregates to cache/, which the page publishes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 21:11:52 -06:00
imposterandClaude Fable 5 2abf933982 feat(ci): extend data validator to trends _data files
validate_schema.py now also checks the generated trends data files
(edge_exploits, clickgrab_trends, masq_infra_hunts) against the structure
their page templates depend on: required meta keys, list sections, and the
field types the templates do date/number work on. Catches a transform bug or
hand-edit that would render a page blank or break the build.

- declarative TRENDS_SPECS per file; each validated only once it goes data-driven
- validate-data.yml now also triggers on _data/** changes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 16:50:22 -06:00
imposterandClaude Fable 5 7a1a748c4a feat(trends): add recon-vs-exploitation split + lead-time to edge-exploits
Classify each Defused alert by its Alert verb -- weaponized exploitation
("Vulnerability Exploited") vs targeted recon (probing / vuln-check /
exposure) -- and surface two views on the edge-exploits page:

- daily stacked exploitation-vs-recon chart (live window; 67% / 33%)
- per-CVE recon->exploit lead-time table, where probing preceded the first
  weaponized hit (e.g. CVE-2025-55182 led by 6 days)

No export change -- pure classification of the existing high/critical data.
Live window only (the baseline kept no per-alert verbs). Aggregates only; no IPs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-14 12:59:25 -06:00
iimp0ster ff20a9864f Merge pull request #136 from iimp0ster/feat/data-validation
feat(ci): chokepoint schema validator + link audit
2026-06-14 12:28:20 -06:00
iimp0ster a7ba507d59 Merge pull request #137 from iimp0ster/feat/masq-infra-publish
feat(trends): publish masq-infra hunts + weekly refresher
2026-06-14 12:28:04 -06:00
iimp0ster 821eea1a64 Merge pull request #138 from iimp0ster/feat/edge-exploits-automation
feat(trends): automate edge-exploits page from Defused exports
2026-06-14 12:27:29 -06:00
imposterandClaude Fable 5 6c242433db feat(trends): automate edge-exploits page from Defused exports
Render trends/edge-exploits/ from _data/edge_exploits.yml instead of
hand-typed numbers, accumulating history across exports.

- transform_defused_csv.py merges export(s) by day onto a frozen first-
  export baseline (combined = baseline + live); aggregates only, no IPs
- edge_exploits_baseline.yml freezes the un-retained Mar 14-Apr 13 window
- index.html renders stats, meta, daily/CitrixBleed charts, target bars
  from site.data (SRI hashes preserved; inline data jsonify-escaped)
- refresh_edge_exploits.py: weekly detect-only / --open-pr refresher
- adds the high/critical severity scope note, corrects the 2,653->2,683
  Next.js stat, and fixes export-cutoff artifact greying (data flag)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-13 23:33:15 -06:00
imposterandClaude Opus 4.8 f8a6004df5 feat(trends): publish masq-infra hunts + weekly refresher
The infra-malware-delivery-hunter skill writes hunt intel to the local
de-intel-pipeline; transform_intel_hunts.py aggregates it into
_data/masq_infra_hunts.yml. That data file was gitignored from when the
workflow was being tested, so the trends page guard
(`{% if site.data.masq_infra_hunts %}`) silently hid the section on the
live site. Un-ignore it (and its producer) so the section publishes.

- un-ignore _data/masq_infra_hunts.yml + scripts/transform_intel_hunts.py
- commit the current aggregated data (5 hunts, 5 brands)
- add scripts/refresh_masq_infra.py: local weekly refresher that
  regenerates from the hunts folder and opens a review PR only when real
  hunt data changed (ignores the generated: timestamp); preserves the
  working tree when run unattended

enrich_staging_domains.py stays ignored (belongs to the clickgrab trend).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 13:29:03 -06:00
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00
iimp0ster 5386944603 Merge pull request #132 from iimp0ster/chore/tame-dependabot
chore(deps): tame Dependabot (group + monthly)
2026-06-12 21:00:45 -06:00
imposterandClaude Opus 4.8 93655c550d chore(deps): tame Dependabot — group updates, monthly cadence
First-run Dependabot opened one PR per outdated dependency across 4
ecosystems (a dozen+ at once). Group all bumps per ecosystem into a
single PR and switch weekly -> monthly so a scan yields at most ~4 PRs.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:49:11 -06:00
iimp0ster cdcaad05d2 Merge pull request #119 from iimp0ster/security/hardening
security: harden supply chain, escaping, Actions, and governance
2026-06-12 20:43:15 -06:00
imposterandClaude Opus 4.8 0c3709aa7e security: harden site supply chain, escaping, Actions, and governance
XSS:
- Escape `</` in all 5 jsonify-into-<script> data blobs so contributed
  YAML cannot break out of the script context (verified: JSON still
  parses, no </script breakout)
- Add `| escape` to contributor-controlled fields in chokepoint-card.html
  and ~71 value outputs in the chokepoint detail layout

Supply chain (SRI):
- Pin highlight.js, d3, and Chart.js CDN includes with sha384 integrity +
  crossorigin (hashes computed from the immutable versioned URLs)
- Document why cdn.tailwindcss.com cannot take SRI + the real fix

GitHub Actions:
- SHA-pin all 7 third-party actions to commit SHAs (version in comment)

Governance:
- SECURITY.md (private disclosure policy + scope: detection content is
  intentional, not a vuln)
- CODEOWNERS routing review to @iimp0ster
- Dependabot for github-actions / bundler / npm / pip

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 20:24:30 -06:00
iimp0ster 14d42ef5b5 Merge pull request #118 from iimp0ster/feat/social-preview
feat(seo): add social preview card for link shares
2026-06-12 15:30:48 -06:00
imposterandClaude Opus 4.8 4b21a96965 fix(seo): kicker line matches site nav headings
SIGMA -> CHOKEPOINTS in the social card kicker.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:26:39 -06:00
imposterandClaude Opus 4.8 8094344d9f feat(seo): add social preview card for link shares
1200x630 og:image in the playingwithpackets card style: navy field,
Press Start 2P title, tagline, framed arcade artwork strip, site URL.
Wired site-wide via jekyll-seo-tag front matter defaults with
twitter:card summary_large_image; pages can override with their own
image front matter.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 15:24:23 -06:00
iimp0ster 3089493ec8 Merge pull request #117 from iimp0ster/docs/readme-refresh
docs(readme): sync README with live site content
2026-06-12 07:47:43 -06:00
imposterandClaude Opus 4.8 fc34754138 docs(readme): sync README with live site content
- Chokepoint index: 9 -> 13 entries (adds AiTM WebSocket Kit Relay,
  OAuth Device Code Phishing, Graph API Recon Burst, Device PRT
  Enrollment); names and tactic columns now match the canonical YAML
- Why This Exists: replace misattributed dwell-time stat with verified
  figures (M-Trends 2025 median dwell 11 days; Unit 42 GIRR 2026
  first-quartile time-to-exfiltration 72 minutes)
- Attack chains: fill in ransomware coverage (260 procedures, 36 reports)
- Trends: add missing Software Impersonation Infrastructure entry;
  refresh ClickFix and Edge Exploit figures to current dashboards
- Framework: question list now verbatim with the site; mention the
  interactive relationship map
- New Prevention Layer section (per-chokepoint prevention opportunities
  + MagicSword application-control mapping)

Audited against the live site and chokepoint YAMLs as of 2026-06-12.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 07:37:56 -06:00
iimp0ster 141dfa4b82 Merge pull request #116 from iimp0ster/feat/readme-pixel-logo
docs(readme): add arcade pixel-art repo logo
2026-06-12 06:58:21 -06:00
imposterandClaude Opus 4.8 2b7e3d3328 docs(readme): add arcade pixel-art repo logo
RNC-with-body-triangle artwork in a versus-game frame with the Press
Start 2P title band and tagline, matching the Tacklebox README lockup.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 06:55:45 -06:00
iimp0ster e349c48119 Merge pull request #115 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
fix(nav): full-screen mobile menu with Trends accordion
2026-06-11 10:27:48 -06:00
imposterandClaude Opus 4.8 0d0c14d7c3 fix(nav): full-screen mobile menu with Trends accordion
Replace the overflowing right-column mobile menu with a full-screen overlay: decluttered top bar (brand + hamburger), one item per row with large tap targets, a collapsible Trends accordion (no longer dumped inline), and theme/GitHub/MagicSword in a footer row. Move the overlay outside .site-nav so position:fixed isn't trapped by the nav's backdrop-filter containing block, and bind the theme toggle to all .js-theme-toggle buttons. Desktop nav unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 10:23:34 -06:00
iimp0ster 04c0e3005a Merge pull request #114 from iimp0ster/iimp0ster/aitm-chokepoints-2026-05
Site: MagicSword integration, TTP graph, redesign + logo fix
2026-06-11 09:20:19 -06:00
imposterandClaude Opus 4.8 a8728bb20b fix(nav): prevent brand/toolbar overlap on mobile
On <=900px the Press Start 2P brand (~240px) collided with the nav toolbar. Pare the toolbar to theme + hamburger (GitHub stays in the menu's Contribute, MagicSword on the homepage card), shrink the brand to .6rem, and cap its width with ellipsis so the full title fits at 375px and truncates cleanly on narrower screens. Desktop unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:31:51 -06:00
imposterandClaude Opus 4.8 d3d3538f17 content: chokepoint, trends, and framework updates
Refresh chokepoint YAML entries, trends pages (incl. masq-infra rewrite), framework page, search index script, build aggregation, and pixel nav/section icons.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 5982b5e468 style: arcade theme layer + chokepoint page redesign
Arcade theme stylesheet, premium chokepoint hero/sidebar styling, trends submenu, and hero treatments.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 f93cd02398 feat(magicsword): prevention integration + transparent logo
Homepage-only nav CTA, homepage prevention card, and per-chokepoint Prevention Opportunities with MagicSword affiliate callouts. Replace the opaque-background logo with a transparent emerald PNG and drop the colour-inverting filter so it renders correctly in nav/card/chip on both themes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:50 -06:00
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00
imposterandClaude Opus 4.8 e80dea6bd9 chore: gitignore internal planning and intel material
Keep GSD planning, draft detections, mockups, local intel hunt data, and intel-pipeline scripts out of the public repo.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00