Commit Graph
253 Commits
Author SHA1 Message Date
CyberSecurityUPandClaude Opus 4.8 8a3cb42c1f fix(repl/cli): /target re-derives scope; wildcard target tests subdomains; version banners
Two reported bugs:
1) A scope left over from a previous session persisted in the project session and
   kept denying every new target (DENY_TARGET_OUTSIDE_GRANT ... scope *.example.com
   even after /target zoom.us). With no verified capability, /target now re-derives
   the authorized scope from the new target (preserving excludes + guardrails), so
   the target you pick is the target you test — same model as `neurosploit run <url>`.
2) A wildcard target (`*.zoom.us`) now authorizes the apex AND all subdomains and
   seeds recon with the apex (a literal `*.zoom.us` has no DNS record to probe), so
   subdomain enumeration happens inside the wildcard scope. Applied in both the REPL
   /target and the one-shot `run` path.

Also: the run banner and clap about showed v4.1.0 — now use CARGO_PKG_VERSION / 4.2.1.
421 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:16:25 -03:00
CyberSecurityUPandClaude Opus 4.8 9076d30c59 feat: vulnerability-research mode — hand it a repo, it hunts a novel CVE
New --research mode for whitebox/greybox (REPL /research, web 🔬 checkbox, or
auto-detected from natural-language focus/objective in PT/EN). Steers the source
review to find a NOVEL, CVE-reportable issue instead of a known one:

- WHITEBOX_RESEARCH_DOCTRINE: pin version/commit; research known CVEs/advisories
  (SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate; patch-diff /
  n-day->0-day variant analysis (incomplete fixes, bypasses of a new check,
  sibling sinks, reintroductions); strict novelty gate (each finding states
  novel-why + checked-against); benign PoC + dynamic confirm on greybox.
- RunConfig.research + is_research_intent(); injected in run_whitebox and the
  greybox code-review half.
- 6 research skills (code/): known_cve_dedup, patch_diff_variant,
  attack_surface_map, source_to_sink_taint, logic_authz_flaw,
  dependency_nday_reachability.
- Methodology modeled on a real AppSec-research workflow (no specifics copied).

479 agents, 421 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 ed4105999e fix: version strings showed 4.2.0; use CARGO_PKG_VERSION so they never go stale
The REPL banner and HTML-report footer hardcoded v4.2.0 while the crate is 4.2.1.
Both now interpolate env!("CARGO_PKG_VERSION"); web title/sidebar/comments set to
4.2.1. --version already read the crate version.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 7741290193 feat(agents): deep Active Directory suite — 25 host/infra skills + 7 AD chains
Adds robust AD pentest coverage spanning the full kill chain (initial access →
enumeration → exploitation → lateral movement → privilege escalation →
persistence → pivoting), with concrete tooling, per-technique decision points,
benign-proof-only guidance, lockout/state awareness, and chaining hooks. All
GENERIC — no lab-specific hosts/IPs/creds/flags; works in any AD environment.

New infra/ skills: ad_recon_enum, ad_bloodhound_paths, ad_llmnr_poisoning,
ad_ntlm_relay, ad_password_spray, ad_kerberos_delegation, ad_adcs_esc,
ad_pth_ptt, ad_coerce_auth, ad_critical_cve (Zerologon/noPac), ad_smb_share_hunt,
ad_laps_gmsa_read, ad_gpo_abuse, ad_dpapi_looting, ad_trust_abuse,
ad_persistence_review, ad_mssql_abuse. Enriched: ad_kerberoasting, ad_asreproasting,
ad_dcsync, ad_acl_privesc, ad_default_creds, windows_priv_esc.

New chains/: chain_ad_web_to_forest_root, chain_ad_rbcd_s4u_to_adcs,
chain_ad_coerce_relay_adcs, chain_ad_kerberoast_to_domain,
chain_ad_mssql_linked_pivot, chain_ad_trust_cross_forest, chain_ad_local_to_domain.

attack_graph: map CWE-294/295/1392/269 to OWASP/MITRE/stage + CVSS bands so AD
findings grade and place in the kill chain correctly. 473 agents, 421 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 8051464a84 feat(web): live 'what's being tested' agent panel
Parse per-agent activity from the stream (launching agent / exploit·analyze·test
<name> via <model> -> N candidate(s) / failed) into a status map, surfaced in the
live view as a grid of chips coloured by state (pending/running/found/done/failed)
with a per-agent finding count and a running/done tally. Answers 'what is it
testing right now' at a glance; resets per engagement.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 e1350c0c4a fix(web): REPL spawn passed run-only flags as globals, breaking every run
The REPL-backed path (run/whitebox/greybox) spawns `neurosploit` with NO
subcommand, so only global flags are valid in argv — but authArgs() emitted
run-subcommand flags there (--environment, --policy, --in-scope, --budget,
--compliance, --revalidate-poc, --token-limit, --deep-test-limit, --order,
--sample-per-route, --scope-file). clap aborted on the first one
("unexpected argument '--environment'"), so the engagement died at launch and
the live view sat empty. authArgs now emits only the real global flags with
their global names (--session-environment / --session-in-scope / --session-policy,
plus --capability-token/--transport/--oob-*/--sms/--typesafe/--decision-backend/
--intercept/--sandbox); run-only knobs ride the REPL script or defaults.

Also:
- sidebar: a disk run whose status says "running" but has no live job is shown
  as "interrupted", not "running" (no more stale RUNNING entries); brand-new
  in-memory jobs are injected so an engagement appears the moment it starts;
  new "Interrupted" group; clicking a running/interrupted row attaches the live
  stream or offers resume.
- stop: robust now — graceful /stop then SIGTERM/SIGKILL fallback, a second
  press escalates, a job whose child already exited is marked done so the UI
  stops showing it as running.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 999d9c2209 fix(pipeline): synthesize pocs/ and evidence/ from recorded evidence (#44)
The runs/evidence and pocs folders were always empty on the API-key path: there
the model only returns findings JSON and never executes a tool to write files,
so nothing populated them (they were only ever written by the subscription
agentic CLIs). The harness already holds the structured evidence (evidence_data:
baseline/attack/identity exchanges, marker) and the payload/endpoint.

synthesize_pocs_and_evidence() now writes, per finding and without overwriting
anything an agent already produced:
- evidence/<slug>.md  — the request/response proof (baseline/attack/identity
  pairs, marker, callback/browser flags, notes), or the prose receipt as fallback
- pocs/<slug>.md      — a runnable curl repro from the recorded request(s),
  incl. the cross-identity pair for BOLA/IDOR; falls back to endpoint+payload
and cites the PoC path back into the finding's evidence. Runs in the main
pipeline after evidence collection; idempotent. 421 tests passing.

Closes #44

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
CyberSecurityUPandClaude Opus 4.8 d0219f65f5 fix(cli): make a parked one-shot run resumable — accept /continue on stdin
The one-shot `neurosploit run|whitebox|greybox <target>` path dropped the
pause/resume handles and never read stdin, so when the pool parked on quota/auth
exhaustion it printed "type /continue …" into a void — nothing accepted it and
the process hung forever on the parked task; only Ctrl-C worked. This is exactly
the "can't /continue, it's stuck" a run that exhausts during recon hits.

run_mode now, at a real terminal, reads stdin and accepts:
  /continue [provider:model]   resume (optionally switching model)
  /model provider:model        switch provider/model, then resume
Ctrl-C still stops and offers a partial report; it also clears the pause so a
parked task can't swallow the interrupt. Over a pipe (CI/web) stdin is skipped.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
v4.2.1
2026-10-02 19:07:24 -03:00
CyberSecurityUPandClaude Opus 4.8 1bfaf1837c fix(pool): emit the quota/auth PAUSE notice once, not once per parallel agent
A single out-of-credit event (Anthropic's 400 "credit balance too low", which
is_exhaustion correctly classifies) made every in-flight parallel agent print
its own "PAUSED — /continue" line, flooding the console with identical notices.
Now only the agent that wins the paused false->true transition emits the notice;
the rest park quietly. Resume clears the flag so the next episode notices again.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-02 19:01:32 -03:00
CyberSecurityUPandClaude Opus 4.8 efc687c1e4 feat: --quick economy preset for short, low-cost tests (CLI + REPL + web)
Billing concern: a full run with 2-3 voters, deep chaining and exhaustive recon
burns a lot of tokens. --quick is one switch for a fast, cheap pass:
one voter, one chain round, light recon (intensity 1), ≤6 agents, eco budget.
Dropping voting from 3 models to 1 is the biggest saver.

- CLI: --quick on run/whitebox/greybox (apply_quick, applied last so it wins)
- REPL: /quick (aliases /economy /eco), listed in help + completion
- web: ⚡ Quick-mode checkbox in the wizard -> /quick in the REPL script
- README: documented in the flags table
- 420 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-02 18:54:37 -03:00
CyberSecurityUPandClaude Opus 4.8 a916abaf75 feat(web): persist jobs + resume an interrupted run where it left off
The web server's job state was in-memory only, so a node restart/crash lost the
live run (the harness still checkpointed to .neurosploit/active_run.json, but
the console couldn't see or re-attach it).

- persist each job to .neurosploit/web-jobs/<id>.json (snapshot + feed tail +
  sanitized launch params; NO api keys or creds contents), throttled, on
  findings/phase/done
- loadPersistedJobs() on boot: a job that was live becomes `interrupted`, and
  `resumable` when it was a REPL-backed run/whitebox/greybox
- POST /api/exploit/:id/resume: relaunch the REPL (NEUROSPLOIT_AUTO_RESUME=1),
  which recovers the on-disk checkpoint and /continue's it, carrying findings
  forward; reuses the same job id so the live view resumes streaming
- API-key jobs need the provider key re-entered after a full restart (kept only
  in memory) — resume returns a clear 409 saying which; subscription resumes clean
- frontend: boot offers a dismissible "N interrupted run(s) — Resume" banner

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-02 18:49:10 -03:00
Corentin GoetghebeurandClaude Opus 4.8 01eac8f0c3 fix: robust LLM response handling & JSON extraction (#46)
* fix(pipeline): robust LLM JSON extraction (json5 + truncation repair)

Model replies that did not exactly match the expected JSON syntax were
either dropped silently or surfaced as "[extract_findings] ... JSON parse
failed" / "... no JSON array/object found". Both came from the same two
weak stages in extract_findings: a greedy first-'['-to-last-']' span that
captured prose, and a salvage pass that only stripped trailing commas.

Add a shared, string/escape-aware extractor (crates/harness/src/json_extract.rs):
- locate balanced [..]/{..} regions, ignoring brackets inside prose/strings,
  preferring fenced blocks (last wins);
- parse leniently: serde_json first, then json5 (trailing commas, comments,
  single quotes, unquoted keys);
- repair token-limit truncation by closing the open structure, keeping the
  complete findings instead of discarding the whole batch.

Route extract_findings, reported_nothing, extract_chain, parse_string_array
and prosecutor::parse_verdict through it. Make the diagnostic tail()
char-boundary-safe (the old slice could panic on UTF-8). Add regression
tests for single quotes/comments, capitalised ```JSON fences, truncated
arrays and pure prose.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(models): robust LLM response handling + higher token/timeout limits

Harden the OpenAI-compatible chat client against the empty-content and
parse failures hit with reasoning models (GLM/DeepSeek via OpenRouter)
during whitebox runs:

- Accept message `content` as a string, an array of content parts, or a
  `reasoning_content` fallback; surface `finish_reason` and empty-choices
  errors instead of an opaque "no content in response".
- Stop masking mid-stream body-read failures as a bogus "EOF while
  parsing"; report read timeouts and empty bodies explicitly, and
  reassemble SSE-framed responses some gateways return unrequested.
- Raise reasoning-model max_tokens to 32768 and the HTTP timeout to 300s;
  both overridable via NEUROSPLOIT_MAX_TOKENS / NEUROSPLOIT_HTTP_TIMEOUT.

Adds unit tests for content extraction, token sizing, and SSE reassembly.
Cargo.lock syncs the json5 entry from the prior extraction commit.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(pipeline): unwrap findings/selection replies wrapped in an object

The json5 + truncation work made JSON *parsing* robust, but the *shape*
handling after it still dropped data when a model wrapped its answer in an
object instead of returning the bare array we asked for. Most visible on
black-box runs, where a long tool-use turn ends with the model narrating
into a report object.

extract_findings treated any object as ONE finding, so a real batch returned
as `{"findings":[…]}` (or `{"vulnerabilities":[…]}`, …) became a single
title-less "finding", was filtered out, and surfaced to the operator as
"returned text but 0 parseable findings" while the findings were lost. Add
findings_items() to normalise the shape: an array is the list; an object with
a title is one bare finding; otherwise an object wrapping a known findings key
unwraps to that array. reported_nothing() now recognises the same wrapper keys
so an empty `{"vulnerabilities":[]}` reads as an honest negative.

Two more consumers of the same class:
- parse_string_array (agent selection) accepted only a bare array of strings,
  so a wrapped `{"agents":[…]}` or elements-as-objects `[{"name":"sqli"}]`
  silently fell back to RL ranking. Now unwraps the wrapper and pulls the
  string from object elements.
- extract_chain hard-coded the "findings" key for its object branch, dropping
  the sibling `loot` under any other wrapper key. Now checks all wrapper keys.

Add regression tests for each shape.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-02 18:48:50 -03:00
CyberSecurityUPandClaude Opus 4.8 5d4e7e0347 feat(models): add September 2026 models + Z.ai (GLM) provider
- Anthropic: claude-opus-5-5 (default), claude-fable-5-1
- OpenAI: gpt-6-astra / gpt-6-sol / gpt-6-luna
- Google: gemini-3.8-flash
- Qwen: qwen3.8-max, qwen3.8-omni-flash
- new provider zai (Z.ai / GLM): glm-5.3, glm-5.3-flashx, glm-4.6
- refresh opencode + openrouter curated lists (glm-5.3, deepseek-v4.1, qwen3.8-max, opus-5-5)
- web console PROVIDERS mirror synced; also fixes stale xai list (adds grok-4.7)
- routing is by provider, not model id, so new ids pass through unchanged
- README badge 18 -> 19 providers; 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-27 17:48:01 -03:00
CyberSecurityUPandClaude Opus 4.8 7c25958827 feat(web): make FAIR top-contributor rows clickable to their finding
Each dashboard "Top contributors" row is now a button: clicking it opens the
run it belongs to and pops that finding's detail modal (evidence/impact/PoC).
Matches the finding by title, falling back to CWE; if it was recalibrated or
merged, opens the run and says so. Fetches the run detail directly to avoid
racing loadDetail's async fill.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-27 17:26:05 -03:00
CyberSecurityUPandClaude Opus 4.8 f82e3fe265 feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-26 16:25:58 -03:00
CyberSecurityUPandClaude Opus 4.8 5ab6451c15 feat(report): SARIF 2.1.0 export + stronger cross-object reference mining (v4.2.1)
- new sarif module: projects findings to SARIF 2.1.0 (rules deduped by CWE,
  security-severity from graded CVSS, endpoint locations, OWASP/MITRE tags)
- report::write_all/rebuild now emit report.sarif alongside md/json/html/pdf
- `neurosploit sarif <run> [--out]` re-emits on demand; exposed over MCP
- assurance: report.sarif added to the known-artifacts manifest
- chaining doctrine: harvest every object identifier (ids/UUIDs/tokens/emails)
  into a reference pool and substitute across identities/endpoints — the core
  of reliable BOLA/IDOR/mass-assignment discovery
- version 4.2.1; 389 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-24 12:14:49 -03:00
CyberSecurityUPandClaude Opus 5 e49595b8bf feat(container,coverage): Strix-1.6.2-inspired capabilities
- Container image scanning: new `container` mode + 4 skills (vuln, secret,
  misconfig, SBOM) driving trivy/grype/syft headless, read-only. Scans an OCI
  ref / tar / Dockerfile for vulnerable packages (CVE/fixed-in/KEV), exposed
  secrets in any layer, Dockerfile+runtime misconfig, and writes an SBOM in
  both SPDX and CycloneDX to the run's sbom/. Also exposed as an MCP tool
  (neurosploit_container).
- Coverage report: every run writes coverage.md — which agents ran (tested
  surface), findings per agent, and the high-value classes NOT covered — so the
  reader sees the engagement's reach. Added to the assurance bundle.
- Login-verification evidence: doctrine now requires capturing the login
  request/response + a Playwright screenshot and recording success/failure
  before authenticated testing.
- HTTP traffic export: `neurosploit traffic <run>` turns the intercepted
  flows.jsonl into a traffic.http archive for external tools.

Not ported: Asset Discovery (enterprise-only, skipped per request).

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v4.2.0
2026-09-23 01:27:26 -03:00
CyberSecurityUPandClaude Opus 5 1adc882f6d feat(decision): wire 3 high-value System One decisions (backend = TypeSafe or Laya)
The three fragile heuristics now get a calibrated second opinion when a decision
backend is configured. All go through TypeSafe::from_env(), so they work
identically with hosted TypeSafe or local Laya (--decision-backend), and the run
banner names the active backend. Deterministic behaviour is unchanged when no
backend is set or --typesafe off.

- typesafe.rs: three helpers — same_finding (Noul), response_origin (Choice) and
  is_prompt_injection (Noul).
- Dedup grey zone (pipeline finish): a fixed 0.4 Jaccard cannot settle
  near-duplicates; merge_grey_zone_dupes asks a calibrated Noul on every
  same-endpoint/CWE pair scoring in the 0.25..0.40 band and merges the ones it
  calls the same bug.
- WAF origin (poc.rs): header signatures are ambiguous; before dropping a PoC as
  edge-answered, the backend gets the deciding vote — only bail if it also judges
  p(application) < 0.5, so a real finding is not discarded on a false edge.
- Prompt-injection (pipeline probe): the keyword matcher over-flags legit pages
  that merely mention "ignore instructions"; a calibrated Noul confirms real
  manipulation before raising the neutralised-injection notice.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 01:18:14 -03:00
CyberSecurityUPandClaude Opus 5 bc00fa61eb feat(models,pocs): Grok 4.7 support; save every exploit/Frida script to the run's pocs/
Models: xai:grok-4.7 added as the preferred xAI model (API via XAI_API_KEY at
api.x.ai/v1, and subscription via the local `grok` CLI) and to the OpenCode Zen
list. `--model xai:grok-4.7` or `--subscription --model xai:grok-4.7`.

PoC persistence hardened so exploitation artifacts are retrievable after a run:
the POCS doctrine now explicitly requires saving repro scripts, Frida hook
scripts (<slug>.frida.js), custom exploit code/source, compiled PoCs, request
collections and adapted public PoCs into the run's pocs/ folder with a run
command in the header — and the mobile mode now carries that directive too, so
Frida bypass/hook scripts written during APK/IPA analysis are kept and re-runnable.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 16:35:49 -03:00
CyberSecurityUPandClaude Opus 5 4b71ac63a0 feat(mobile): binary/APK/IPA testing mode + 12 RE skills — v4.2.0
New `mobile` engagement mode: `neurosploit mobile <app.apk|app.ipa|binary>`
reverse-engineers a local artifact with a dedicated `mobile` agent set, all
headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker,
Frida, apktool/jadx, radare2).

Twelve original, generic skills (agents_md/mobile/, English): static binary
triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping,
root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug
detection + bypass, obfuscation analysis & deobfuscation, code-integrity /
tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and
mobile network traffic analysis. Findings are proven from the artifact
(decompilation or Frida trace), non-destructively.

- agents.rs: new `mobile` Library category (loaded, counted).
- pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and
  headless tooling doctrine; exported from the crate.
- CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI.
- README + TUTORIAL document the new test type; engagement-modes badge + table
  updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 21:08:14 -03:00
CyberSecurityUPandClaude Opus 5 a4afd784c7 feat(mcp,tooling): NeuroSploit as an MCP server; tool-discovery + CVE-PoC + headless doctrine
MCP server (app/src/mcp.rs): `neurosploit mcp` speaks Model Context Protocol
over stdio (JSON-RPC 2.0), exposing run / list_runs / findings / report /
rebuild / internal / compliance as tools. Each shells out to the same binary,
so scope, safety and authorization match the CLI. Install with
`claude mcp add neurosploit -- neurosploit mcp`. Handshake, tools/list and a
live call verified. TUTORIAL section 8 + README document setup for Claude Code,
Codex and Cursor.

Tooling doctrine expanded so the agent researches and provisions the BEST tool
for the context instead of being limited to a fixed list:
- context toolboxes (AD: netexec/impacket/bloodhound-python/certipy/kerbrute/
  responder/evil-winrm; web recon; cloud; exploitation frameworks incl.
  metasploit/msfvenom; cracking) — provision on demand.
- CVE -> PoC sourcing as a core capability: on a fingerprinted version
  (WordPress/plugin/CMS/OS package/service) go to searchsploit, Exploit-DB,
  GitHub, PacketStorm/Vulners, wpscan; clone/fetch, compile (gcc/go/cargo) and
  run the PoC non-destructively, vetted and time-boxed.
- headless-only rule for GUI tools: mobsf (REST/Docker), ghidra analyzeHeadless,
  jadx/apktool/frida, radare2 — never require an X display.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v4.1.0
2026-09-20 20:55:49 -03:00
CyberSecurityUPandClaude Opus 5 56b2c80ae4 feat(decision): pluggable System One backend — TypeSafe (hosted) or Laya (local)
Laya (github.com/NandhaKishorM/laya) is the same System One abstraction as
TypeSafe — identical choice/score/noul primitives — but local, open-source
(Apache 2.0) and free. Added it as a swappable backend, entirely additively:
the hosted TypeSafe path is byte-for-byte unchanged (key alone → same endpoint,
model, bearer as before).

- typesafe.rs: endpoint/model/bearer are now instance fields with env overrides
  (NEUROSPLOIT_DECISION_ENDPOINT / _MODEL). Defaults are the hosted TypeSafe API.
  from_env() now also activates when a local endpoint is configured (no key).
  backend_label() names the active backend in the run banner.
- tools/laya_shim.py: a stdlib HTTP shim that loads Laya and exposes the exact
  POST /systemone contract the client already speaks. Model downloads on first
  use (HF cache); no key; evidence stays on the box.
- CLI: --decision-backend typesafe|laya. `laya` installs laya if missing, starts
  the shim, waits for readiness, and points the client at it — all optional,
  only when the operator selects it.

383 tests; the hosted TypeSafe behaviour is untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 19:27:14 -03:00
CyberSecurityUPandClaude Opus 5 d752e252e6 docs: drop links to the internal benchmark folder
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 19:11:17 -03:00
CyberSecurityUPandClaude Opus 5 d5d136ef34 chore: stop tracking benchmarks/ (internal only, not for the public repo)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 19:10:40 -03:00
CyberSecurityUPandClaude Opus 5 651b2bfc81 bench: A vs B·TS gap re-test — both close the gaps, TypeSafe calibrates severity
Re-ran the previously-missed scenarios on the current build without TypeSafe (A)
and with (B). Both arms now confirm CRLF-on-Location, second-order SQLi, UNION
SQLi, blind-time, IDOR and BOLA — the chaining/skill fixes are prompt-level, not
TypeSafe-gated. TypeSafe's contribution is the severity shape: it consolidates
A's long Low tail (10) into fewer, better-justified High findings (8 vs 3) and
keeps the credential-dump BOLA at Critical via data-type grading. Artifact grid
restored to A vs B·TS columns; both run arms stored.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 19:04:08 -03:00
CyberSecurityUPandClaude Opus 5 d334946915 bench: refresh the TypeSafe benchmark — 13/13 coverage, data-type-aware severity
Current-build run against the 13-scenario target with TypeSafe on: every seeded
class confirmed with a live receipt, chained beyond the set into full admin
takeover, GraphQL authz bypass, a config secret leak and an authenticated RCE.
The credential-dump BOLA holds Critical because severity is graded on the kind
of data exposed, not the class. report.html + run artifacts + README refreshed;
no secrets committed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 14:06:39 -03:00
CyberSecurityUPandClaude Opus 5 fce86522ca feat(chain,skills): close benchmark misses — CRLF-on-Location, second-order precondition; condense BENCHMARK
The 13-target benchmark left 3 misses. Root-caused and fixed the two that were
coverage gaps (the third was single-run variance, already handled by the
session-limit fix):

- CRLF header injection (web_crlf_header_go): the agent confirmed the open
  redirect on /go?url= and stopped; the CRLF payload was never generated. The
  open_redirect skill now tests %0d%0a header injection on the SAME param, and
  CHAIN_DOCTRINE says a param landing in a Location header must also be tested
  for response splitting. chain.rs: CWE-113/93/644 now provide capabilities;
  attack_graph maps their kill-chain stage.
- Second-order SQLi (web_sqli_second_order): the sink was behind /admin, which
  the customer account could not reach. CHAIN_DOCTRINE now teaches the
  precondition pattern (store the payload, trigger from every identity, escalate
  first if the trigger page needs a role you lack, else report as a chained
  lead). chain.rs: CWE-564 requires PrivilegedContext so it chains after privesc.

BENCHMARK.md: added the TypeSafe calibrated-adjudication row; dropped the
"genuinely ahead" prose (the table is the summary); condensed the rest
188 -> 89 lines; refreshed scale (27 validators, 47 modules, 383 tests).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 12:42:36 -03:00
CyberSecurityUPandClaude Opus 5 dff2e3c0f0 chore: stop tracking articles/ (local-only, not for the public repo)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 12:35:39 -03:00
CyberSecurityUPandClaude Opus 5 c9e1f74e23 feat(cvss,typesafe): data-type-aware impact + evidence back-fill; LinkedIn article
Addresses the benchmark's honest edge (a genuine BOLA credential dump graded
Low because evidence_data was null). Two fixes so criticals like it are not
recalibrated away:

- attack_graph::backfill_evidence — when evidence_data is null but the agent
  recorded a proof in prose, copy that text into the structured slot the grader
  reads (no fabrication, just relocation). Called first in enrich().
- attack_graph::data_class — classifies the demonstrated data (none/data/
  sensitive) by scanning every evidence slot for credential/key/PII/payment
  signatures. cvss_graded now grants the confidentiality receipt when sensitive
  data was shown, even on a thin structured receipt — the KIND of data is itself
  the impact.
- TypeSafe adjudication adds a `data_sensitivity` Score (public → PII → secrets),
  carried on Adjudication. The pipeline regrade only strips impact when the
  model was unconvinced AND no sensitive data was shown AND data_sensitivity is
  low; a demonstrated credential/PII exposure keeps its severity.

articles/ — LinkedIn article (PT, no em-dashes) in Markdown + DOCX: explains
TypeSafe/System One/Jev, NeuroSploit, how to configure TypeSafe, the step-by-step
benchmark, results, the refinements this forced, and offensive-security use cases.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 12:34:34 -03:00
CyberSecurityUPandClaude Opus 5 088d133c80 release: v4.1.0 — assurance layer, TypeSafe, hardening + benchmark
Version bumped to 4.1.0 across the workspace, binaries, web console and Typst
template.

README: new "New in v4.1.0" summary; trimmed the verbose highlight bullets and
the TypeSafe section; removed the anti-plagiarism/provenance section (provenance
stays in the code, just not front-and-centre in the README); TypeSafe promoted
to its own top-level section; agent count 446.

TUTORIAL: new section 17 "Assurance & authorization" covering the target gate,
--scope-file, evidence-graded CVSS, audit anchoring + assurance bundle, sandbox,
intercept proxy, PoC re-validation, compliance mapping, TypeSafe, and the
internal/AD graph + budget governor.

benchmarks/typesafe-2026-09-20/: the with/without TypeSafe measurement —
report.html, scorer, both runs' findings/assurance/meta/logs, and a README.
No secrets committed (env-only during the runs, verified clean).

381 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-20 12:25:23 -03:00
CyberSecurityUPandClaude Opus 5 d2ec0a112d fix(models): treat subscription session/usage-limit stdout as exhaustion
Subscription CLIs (claude) report a hit session limit as ordinary stdout with a
ZERO exit code — 'You've hit your session limit · resets …'. Left as Ok it
became a 'response' each agent then failed to parse, and the run burned every
remaining agent against a dead session instead of pausing. Now the sentinel is
caught (length-guarded so a real finding mentioning 'rate limit' is not misread)
and surfaced as exhaustion, so the pool parks the run for /continue — the
pause-on-quota path that already existed but this case never reached.

Found during a live benchmark when run B collapsed to 0 findings mid-run.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 23:16:56 -03:00
CyberSecurityUPandClaude Opus 5 b23fae7318 fix(transport): exempt loopback from the fail-closed gate (unambiguous host)
127.0.0.1/localhost/::1 always mean this host regardless of any VPN, so the
network-position ambiguity the gate guards against does not apply. Needed to
run against a local benchmark target.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 18:24:34 -03:00
CyberSecurityUPandClaude Opus 5 7661b5eb4e fix(wiring): resolve the last two placebos — pomdp belief gate + harness-owned inbox
pomdp.rs was dead (belief.rs was on the path, pomdp wasn't). Now
pomdp::may_assert runs as an anti-hallucination gate over the belief WorldModel:
a finding asserted confirmed while the belief about it is diffuse or weak is
held for review. Advisory — never deletes.

inbox.rs was unused (mail.tm happened via agent prompt instructions). Now when
temp-email is enabled the HARNESS creates the mail.tm inbox via crate::inbox and
hands the agent that exact address, so the inbox is one we own and record rather
than an unrecorded one the agent conjures. Best-effort; falls back to the old
prompt path on failure.

Every module is now on a real runtime path. 381 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 18:20:14 -03:00
CyberSecurityUPandClaude Opus 5 8e84656f4f feat(typesafe): confirmation-loop agent + --typesafe flag (on/off/auto) for A/B
TypeSafe cannot BE an LLM agent — System One does not generate text or call
tools. But it can be the decision brain of a code-owned confirmation loop, and
that is what typesafe_agent.rs is: an ADDITIONAL confirmation strategy.

typesafe_agent.rs — for enumerable classes (XSS, SQLi, open-redirect, path
traversal, SSRF, IDOR): code lists candidate payloads, a TypeSafe Choice picks
the next one given what's been tried, the replay engine sends it for real, a
TypeSafe Noul judges the response, loop until confirmed or exhausted. Edge/WAF
answers are refused. Pure parts (class table, payload templating, id-swap, OAST
substitution, query encoding) are unit-tested; the networked loop is integration.

Wired as a pipeline pass that runs ONLY on findings the LLM path left
unconfirmed or in needs-review (the recall lever) — it can raise a finding to
confirmed with a calibrated probability, never downgrades (the deterministic
layer owns that).

--typesafe on|off|auto (global flag) resolves into the env the pipeline reads,
governing adjudication, CVSS re-grade, agent pruning and this loop together.
`off` runs the identical pipeline without TypeSafe; meta.json records
"typesafe": true|false so a with/without pair is a clean A/B measurement. Web
console gets the same toggle.

381 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 18:15:10 -03:00
CyberSecurityUPandClaude Opus 5 48c38d4798 fix(wiring): activate cvss.rs + waf.rs (were shelf-ware); TypeSafe into CVSS + agent selection
Honesty audit found four modules written but not on the runtime path. Two mattered
and are now wired; two are noted.

cvss.rs — was NOT called; finding.cvss came from the old attack_graph ladder.
Now attack_graph::cvss_graded() bridges the class shape + demonstrated rung into
crate::cvss::grade (the FIRST-verbatim v3.1 equation), and enrich() sets
finding.cvss from the demonstrated vector, recording the potential ceiling in
the impact text. The class ladder remains only as a fallback for findings with
no evidence to grade.

waf.rs — the deterministic classifier was NOT run on any real exchange (only
WAF_OPS prompt text reached the agent). Now poc.rs classifies each re-run: a PoC
answered by a WAF/CDN is Unverifiable, not "gone" — closing a false-demotion
where an edge block looked like a fix.

TypeSafe (System One) extended per the build-with docs:
- CVSS via System One: when impact_demonstrated < 0.5, the finding's CVSS is
  re-graded with impact receipts stripped — the calibrated judgment, not just
  the rung, decides the demonstrated number.
- Agent selection: typesafe_prune_agents() asks one batched request (the
  fan-out pattern), a Noul per chosen agent, and drops only those it calibrates
  as clearly irrelevant (p < 0.25), never prunes to empty. Additive over the
  LLM selection; skipped without a key.

Still shelf-ware, flagged honestly (not wired): inbox.rs (mail.tm/SMS happens
via agent prompt instructions, the Rust client is unused) and pomdp.rs
(redundant — belief.rs is the one on the path).

374 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 18:06:50 -03:00
CyberSecurityUPandClaude Opus 5 c3de51d508 feat(typesafe): System One calibrated adjudication (RLCD tier)
Integrates TypeSafe's System One model (Jev) as an optional, calibrated
adjudicator — the RLCD (Reinforcement Learning for Calibrated Decisions) tier:
typed judgments with probabilities where the harness needs a number, not prose.

- typesafe.rs: HTTP client for POST /v1/systemone (Bearer TYPESAFE_API_KEY,
  model jev-latest), with Choice/Noul/Score primitives, retry on 429/529, and
  parsed answers exposing the probability distribution + confidence.
  adjudicate() asks a Choice {confirmed/needs-review/rejected} plus an
  impact-demonstrated Noul over a finding; calibrated_confidence() folds
  demonstrated impact into the number, wants_review() gates a split distribution.
- pipeline: an optional pass (runs when TYPESAFE_API_KEY is set, off with
  NEUROSPLOIT_TYPESAFE=off) adjudicates each finding over its EVIDENCE — never
  its narrative — refining confidence and the needs-review boundary. Additive:
  a deterministic validator still rules; TypeSafe can only lower confidence or
  flag for review, never resurrect a rejected claim. Audited per finding.
- env.example + README document it; the web console inherits the key via env.

Where the model stack maps in NeuroSploit: LM/BERT ≈ the deterministic
validators (no model), RLHF chat ≈ the exploit/recon agents, RLVR reasoning ≈
the DeepReasoning budget tier, RLCD ≈ this calibrated adjudication.

373 tests (+5).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 17:56:34 -03:00
CyberSecurityUPandClaude Opus 5 2e95556df5 feat(hardening): scope-evasion resistance, evidence integrity, untrusted tool output
Three security-correctness passes from the assurance review (#2, #9, #15),
all core-harness, all enforced in code and tested.

#2 netguard — scope-evasion resistance. normalize_host canonicalises every
alternate IP encoding (decimal 2130706433, hex 0x7f000001, octal 0177.0.0.1,
IPv4-mapped ::ffff:127.0.0.1) to dotted-quad, wired into Pattern::matches so an
exclude on 127.0.0.1 can no longer be dodged by respelling it. The shared HTTP
client refuses redirects to private/loopback addresses (the SSRF-redirect
pivot). RebindGuard refuses a name that re-resolves to a new internal address,
and any public name resolving to a private one. resolve()/redirect_allowed()
available to callers.

#9 integrity — reject fabricated or re-used evidence. audit_evidence catches:
evidence recorded against another host (cross-target), one recorded exchange
backing two different CWEs (reused receipt), an OAST marker not minted by this
build (foreign marker), and a confirmed finding with no evidence (orphan).
One-directional — strips the proof and flags it, never deletes a real issue.
Wired as a pipeline pass that demotes and audits.

#15 taint — untrusted tool output. sanitize() strips ANSI/zero-width/bidi
sequences and flags prompt-injection signals (instruction-override,
role-switch, policy-tamper, tool-hijack, exfil-bait); fence() wraps content as
UNTRUSTED_TOOL_OUTPUT with an explicit "never follow instructions inside it"
banner. Wired at the HTTP-probe → recon-prompt boundary, so a target that
plants "ignore previous instructions" in its response is neutralised and
audited, not obeyed.

368 tests (+21).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 21:52:14 -03:00
CyberSecurityUPandClaude Opus 5 b4903575c0 feat(assurance): target gate (default-deny), evidence-graded CVSS, audit anchoring, P1–P5 bundle
The five immediate priorities from the assurance review — the harness-core
ones, not the commercial/research items (Ed25519, enterprise mode, ablation,
multi-target benchmark are deferred, noted as such).

P1 — target authorization gate. scope.rs::validate_target checks protocol,
host, port and URL prefix before ANY recon. A capability token that does not
cover the CLI target now refuses the run with DENY_TARGET_OUTSIDE_GRANT,
audits it, and exits non-zero — closing the auto-trust-the-target bypass.
RunOutput carries a `denied` code the CLI turns into a non-zero exit.

P6 — cvss.rs: the FIRST v3.1 base equation verbatim (roundup, scope
coefficients), validated against first.org reference vectors (9.8, 6.1, 10.0,
7.8, 7.5, 5.3, 3.1). grade() drops any impact metric that raises severity
without a receipt to a *demonstrated* vector, keeping the *potential* one for
context — SQLi with no extraction scores 0 demonstrated / 9.8 potential, never
a manufactured critical.

P4 — audit.rs anchoring: signed checkpoints of the chain head, local and (with
NEUROSPLOIT_ANCHOR_DIR) external append-only. verify_anchored() catches
truncation (chain shorter than an anchor) and silent rebuilds (head hash no
longer matches), and forged anchors via signature. `neurosploit audit --anchor`.

P5 — assurance.rs bundle: one assurance.json per run — every artifact with its
SHA-256, which of P1–P5 it evidenced (present/partial/absent, never flattered),
a bundle hash and a signature. `neurosploit assurance <run> [--verify]`.

Also +8 deterministic validators earlier this session (19→27). Deferred and
documented: Ed25519 tokens (#3), enterprise mode (#25), benchmark/ablation
(#20/#21), model pinning + reproducibility (#22/#23), README claims taxonomy
(#24), per-agent seccomp (#14).

347 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 21:25:21 -03:00
CyberSecurityUPandClaude Opus 5 8894649ccb feat(scope): --scope-file YAML loader + web Scoping/Guardrails UI
Hard scoping was already enforced in code (every request passes
ScopePolicy::check_request; exclude beats allowlist; capability token caps
it; out-of-scope findings withheld + audited). What was missing was a way to
author that boundary from a file or the web form instead of only CLI flags.

- scope.rs: ScopePolicy::from_yaml / from_file — a dependency-free parser for
  the friendly string format (app.example.com, *.wildcard, CIDR, url-prefix),
  the same strings Pattern::parse already takes, NOT the raw serde {kind,value}
  shape. Strict in one direction: an unreadable file errors, an empty hard list
  authorizes nothing (a safe failure, but the operator's choice, not a typo).
- CLI: --scope-file <yaml>. Loaded before authorization so --in-scope adds to
  it and the capability grant still caps it.
- Web: a full Scoping & Guardrails section in the Authorization tab — hard
  scope, exclusions, observe-only, destructive-method + account-creation
  toggles, max accounts, rate limit, forbidden payloads, notes. The server
  materializes a scope YAML and passes --scope-file; notes stay labelled
  "guidance, NOT enforced" so prose is never mistaken for a control.
- examples/scope.example.yaml documents the format.

End-to-end verified: web form -> YAML -> Rust loader -> enforced boundary.
332 tests (+4).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 19:20:29 -03:00
CyberSecurityUPandClaude Opus 5 f1fb6b8bc7 feat: PoC validator, Kali sandbox, intercept proxy, compliance, +8 validators
Closes the three benchmark gaps and adds the two the user asked for.

poc.rs — re-runs each finding's recorded proof and sorts it into reproduced /
changed / gone / unverifiable. The last two are kept apart deliberately: a PoC
that could not be tested (out of scope now, state-changing, nothing recorded)
is never reported as one that failed. Never re-runs a mutating request to
"confirm" it. Can only lower a finding's standing, never raise it. Wired as a
run pass (--revalidate-poc) and a subcommand (neurosploit poc <run> --apply).

proxy.rs — own recording forward proxy (HTTP in full; HTTPS tunnelled with
honest metadata, no fake CA) that chains upstream to Burp / Caido / ZAP /
mitmproxy. A bare tool routes straight through it; own+tool records here and
forwards for full TLS interception. Flows -> flows.jsonl, distinct hosts become
passive-discovery leads. Harness and agent child commands share one route.

sandbox.rs — Kali docker/podman container: no host network, no mounted socket,
no-new-privileges, workdir mounted, proxy/transport env inherited. A missing
runtime is an explicit error, never a silent fallback to host execution — the
whole point being to keep attack payloads off the operator's host. Subcommands
sandbox up|exec|install|down.

compliance.rs — maps confirmed findings onto PCI-DSS v4.0, HIPAA Security Rule
and SOC 2 controls. Phrased as "bears on control X", never "compliant/non-
compliant"; the disclaimer is rendered on top and absence of a finding is never
presented as compliance. Report section + `neurosploit compliance <run>`.

validation.rs — 8 new deterministic validators (19 -> 27 classes): verbose
errors/stack traces (CWE-209), cleartext/HSTS (319), CRLF response splitting
(113), dangerous HTTP methods (650), GraphQL introspection, exposed backup
files (530), Host header injection (644), cacheable private responses (525).
Each names exactly what it saw and rejects the classic false positives (a
block page echoing a payload, the SPA served under a bogus path, a copyright
year mistaken for a code).

All wired through RunConfig, the CLI (global --intercept/--sandbox; run-level
--revalidate-poc/--compliance) and the web console's Tooling & assurance block.
328 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 10:26:06 -03:00
CyberSecurityUPandClaude Opus 5 64d6efa8c3 feat(waf): tell the edge apart from the application
A WAF breaks inference in both directions and agents make both mistakes:
a 403 from Cloudflare read as "tested, not vulnerable" (the expensive one —
the app may be wide open and simply never reached), and a block page that
echoes the payload read as reflection (the embarrassing one).

classify() answers one question: did the application see this request?
Proxy markers and enforcement markers are separate lists, because cf-ray is
on every response Cloudflare proxies — treating that as a block would
discard every finding on every CDN-fronted site, including the ordinary
authorization 403s that are often the finding itself.

Coverage::summary() says how many probes actually reached the application,
so a clean result on a WAF-fronted target cannot be read as a clean app.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:39:20 -03:00
CyberSecurityUPandClaude Opus 5 8aa776665a feat(net): fail-closed egress, self-hosted OOB channel, inbound SMS
transport.rs — internal engagements happen through a VPN, a bastion or a
tunnel, and the dangerous failure is silent: with the VPN down, 10.20.0.15
is a machine on the operator's own network and the scan succeeds against
the wrong host. So an internal target with no transport is refused before
any traffic leaves, and a transport that is up must prove it (the apparent
source address has to change) rather than be assumed. Supports SOCKS, HTTP
proxy, OpenVPN, SSH bastion (dynamic or single-host forward) and cloudflared.

oob.rs — our own Collaborator, self-hosted by default because callbacks are
engagement data (internal hostnames, resolver addresses, sometimes the
exfiltrated value). HTTP and DNS listeners written on tokio directly, no new
dependency. The two levels of proof are separated in code: an HTTP callback
proves egress, a DNS query proves only that a resolver saw the name — the
overclaim this channel otherwise invites.

inbox.rs — mail.tm and inbound SMS (Twilio or webhook). extract_code() scores
candidates by surrounding text and returns nothing rather than a guess, so a
copyright year never gets submitted as an OTP. A throttling claim requires
delivered messages carrying DISTINCT codes, not HTTP 200s.

Wired through RunConfig, the CLI (global flags, so a session cannot re-route
itself mid-engagement), the REPL and the web console's Authorization tab.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:35:36 -03:00
CyberSecurityUPandClaude Opus 5 90b4614d94 docs: benchmark vs Strix/Shannon/Penligent, README for budget, provenance, AD graph
BENCHMARK.md is a capability comparison, not a scored result — and it says
so. It names the three places NeuroSploit is genuinely behind (no container
isolation, no intercepting proxy, no benchmark anyone has actually run) as
plainly as the places it is ahead.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:21:49 -03:00
CyberSecurityUPandClaude Opus 5 8d44e4cf4a feat(internal): internal network / AD attack graph with choke-point analysis
An internal engagement's result is a path, not a list of findings. This
models it as one: Asset → Exposure → Weakness → Credential → Privilege →
Movement → Crown Jewel, with business impact, detection and remediation
hanging off the edges — because what a client fixes is a relationship,
not a host.

- the credential → identity → permission → machine → new credential loop,
  distance-bounded so a real chain turns it and an assumption-chain does
  not run forever
- paths() separates what was walked from what is believed; one assumed
  hop caps the chain at informational instead of laundering it to critical
- choke_points(): the single edge whose removal cuts the most value to
  crown jewels — the question a CVSS-sorted finding list cannot answer
- detection_gaps(): unchecked reported as unchecked, never as unmonitored
- dangling edges refused; re-adding a node upgrades rather than duplicates
- `neurosploit internal --graph g.json --scaffold corp.local --from <node>`

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:19:15 -03:00
CyberSecurityUPandClaude Opus 5 408350539f feat(budget,provenance): reasoning budget modes and JOASNSCOPE provenance
Budget (opt-in, unlimited by default so an un-budgeted run is unchanged):
- crates/harness/src/budget.rs — modes, phase shares, Token Governor
- CLI: --budget/--token-limit/--deep-test-limit/--coverage-first/
  --depth-first/--sample-per-route; same controls in the web wizard
- pipeline honours it: vote_n narrows, evidence rounds are capped

Run control parity in the web console:
- /pause in the REPL, backed by a pause gate in the model pool: in-flight
  agents finish, then the run holds with every finding kept
- POST /api/exploit/:id/{pause,continue,report} + GET .../log

Provenance (crates/harness/src/provenance.rs):
- JOASNSCOPE sigil leads every canary, so a marker found in a response,
  a log or someone else's report extracts whole and names its build
- per-build fingerprint, per-run id, optional per-customer build id
- findings.json stamped with _engine; signed provenance.json manifest
- structural signature survives rewording but not a changed result set
- prompts watermarked at the single pool chokepoint
- `neurosploit provenance show|scan|verify`

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:14:03 -03:00
CyberSecurityUPandClaude Opus 5 40b047b9e7 feat(agents): 10 skills for techniques the catalogue was missing
Written against what disclosed bug-bounty reports and public write-ups actually
turn up, and chosen by diffing the existing 245 skills rather than restating
them. Each one is built around the same discipline the harness now enforces:
the client-side discovery is a lead, and the finding is what the SERVER did.

Browser instrumentation and client trust:
- browser_runtime_hooking — hook fetch/XHR/postMessage/storage/WebCrypto at
  document_start to find what the client is trusted to decide, then prove the
  server accepts the tampered value with an independent read-back.
- prototype_pollution_gadget_hunt — pollution is a precondition, not a finding.
  Hunt the gadget with a getter on Object.prototype that breaks into the
  debugger, quote it as file:line from the bundle, and prove the end effect.
- js_source_deep_analysis — recover original sources from source maps, extract
  the API surface the UI never shows, and pair every client-side discovery with
  the server request that confirms or refutes it.
- client_side_path_traversal — the evidence is which URL left the browser, and
  it is Low until chained to something otherwise unreachable.

Authentication:
- webauthn_passkey_downgrade — passkeys as a system: the usual finding is a
  weaker factor nobody removed, or enrollment needing only a session.
- email_verification_bypass — the gate is normally on the login screen, not the
  API; address normalisation is where pre-account-takeover lives.
- jwt_jku_x5u_injection — whether the token gets to choose its own verifier.

Server-side reach and money:
- ssrf_render_pipeline — PDF/screenshot/unfurl renderers browse on the server's
  behalf, usually with no egress restrictions and often with JS enabled; the
  returned document is the exfiltration channel.
- payment_webhook_forgery — prove the ORDER changed state, not that the
  endpoint returned 200; idempotency failures are their own finding.
- presigned_url_abuse — the bug is what the API is willing to SIGN, which is an
  IDOR with a cloud signature on top.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:57:45 -03:00
CyberSecurityUPandClaude Opus 5 36c9e05ea7 feat(uncertainty): collect more evidence instead of handing a human a thin verdict
Everything upstream produced a verdict and stopped. When the evidence was thin
the answer was needs-review — which hands a reviewer the same thin evidence and
asks them to do the collecting. That is the wrong party: the harness still has
the target, the session and the tooling; the reviewer has a paragraph.

The uncertainty engine scores how undecided each candidate is by counting what
its class needs against what it has, which makes "how sure are we?" a
measurement rather than another model's opinion. A finding that is undecided
AND whose gap is obtainable gets one more collection round before judgement.

Two rules keep the loop from becoming a treadmill:
- Only obtainable gaps trigger a round. A missing baseline is one request away;
  a confirmed account behind an email gate is not, and retrying it forever
  burns budget while nothing changes. Unreachable gaps are recorded, never
  retried.
- Rounds are bounded per finding (two by default) and the remaining gap is
  written into the review reason, so a needs-review says exactly what was
  missing instead of sending a human looking from scratch.

Actions are ordered by cost: a baseline is one request, a browser run costs
seconds and a process. Spending the expensive step before the cheap one has had
a chance to decide it is how a budget goes without buying anything.

Merging is monotonic — a later run that did not see the marker does not unsee
an earlier one that did.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:54:01 -03:00
CyberSecurityUPandClaude Opus 5 170ed3808e fix(pool): a voting panel of distinct providers, not one model asked n times
Every finding in the Arena engagement carried votes reading 1/1 while the run
was configured for a 3-model vote. The panel was candidates.take(n), so a run
with one configured model produced a "multi-model adversarial validation" that
was one model agreeing with itself — the single most important thing the
engagement revealed about the harness.

Filling the panel by repeating that model would not fix it: its errors are
correlated with themselves, and three confident repetitions of one mistake are
indistinguishable from a consensus. Anthropic checking Anthropic is not
independent; a second vendor is.

build_panel() now takes at most one model per provider from the configured
candidates, then fills any shortfall from backends this machine can actually
reach (an installed subscription CLI, or a provider whose API key is in the
environment). When nothing else is available the panel stays small and the
yes/total the caller prints tells the truth about it, rather than being padded
to look like a quorum.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:51:29 -03:00
CyberSecurityUPandClaude Opus 5 fb65074cab feat(chain): attack paths derived per vulnerability, after every agent has reported
The Arena engagement produced 24 findings, a graph with 83 edges, and exactly
one chain edge. Two defects, both a step nobody was doing rather than a model
reasoning badly.

chains_from came back empty on every finding. An agent works one vulnerability
and has no view of what the other twelve found, so asking it to link its result
to findings it never saw was asking for something it cannot know. Chaining now
happens after the whole set is visible, on rules about ENABLEMENT: what one
weakness yields that another needs. Account enumeration yields valid
identities; absent throttling turns them into unlimited guesses; a permissive
password policy makes the guessing land. None is severe alone, and that
sequence is how accounts get taken over — on the real data it now reads
CWE-307 <- CWE-204, CWE-208 and CWE-614 <- CWE-319.

The CWE->stage fallback sent 23 of 24 findings to initial-access, so the kill
chain had one populated column and drew a star. Enumeration and side channels
are discovery; missing throttling, password policy, cookie flags and session
fixation are credential-access; hardening headers are recon. The same run now
spreads across credential-access 13, discovery 6, initial-access 5.

Two bugs the tests and the real data caught:
- CWE-614 both yields session material and needs it, so a class chained to
  itself: duplicates formed a circular "attack path" from a cookie flag to the
  same cookie flag. A weakness class no longer enables itself.
- apply_links only fills an empty chains_from, which is right for asserted
  chains and wrong for links written by an older version of these rules — a
  report kept the circular link through two rebuilds because nothing was
  allowed to touch it. repair() now drops links that cannot be true whoever
  wrote them: self-references, same-class links, dangling ids, cross-host
  links.

enrich() still only fills empty fields during a run (an agent's judgement
should survive), but a rebuild applies the current mappings via remap_stages —
otherwise a finished run is frozen with whatever taxonomy existed that day.

path_for() gives the per-vulnerability view: what precedes this finding, what
it enables, and the narrative to print beside it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:49:52 -03:00
CyberSecurityUPandClaude Opus 5 0422b8dc41 feat(cvss): grade by the impact actually demonstrated, not by the class name
"SQLi = Critical" was the shortcut. The same weakness is a different finding
depending on how far the evidence took it, and the report has to be able to
defend the difference.

A ladder is read off the recorded observations:
  reached the component  → the mechanic is proven, impact is not
  read data              → confidentiality impact is real
  read SENSITIVE data    → and it is high
  wrote (read-back)      → integrity impact is real
  executed code          → the system is compromised
  crossed to a second system → scope changes
The class now sets the CEILING and the evidence sets the score, so an injection
that reached the interpreter and extracted nothing no longer scores like one
that returned credentials.

Only observations climb it. "Could lead to remote code execution" stays at the
bottom rung — a test asserts exactly that, because prose is where inflation
enters.

Temporal metrics come from facts the engagement owns: E from whether a runnable
PoC exists, RC from the validation verdict (needs-review is Reasonable, never
Confirmed). They only ever lower the score.

A bug the tests caught: the first rung kept the class's availability impact, so
"reached" scored ABOVE "read data" — the ladder inverted at its first step.

Two older tests encoded the behaviour this replaces ("a bare CWE-89 must be
critical"). They now assert the new contract instead: a class name alone earns
no critical, and command execution scores like command execution only when
execution was observed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:39:35 -03:00