Files
NeuroSploit/neurosploit-rs/app
CyberSecurityUPandClaude Opus 5 8d44e4cf4a feat(internal): internal network / AD attack graph with choke-point analysis
An internal engagement's result is a path, not a list of findings. This
models it as one: Asset → Exposure → Weakness → Credential → Privilege →
Movement → Crown Jewel, with business impact, detection and remediation
hanging off the edges — because what a client fixes is a relationship,
not a host.

- the credential → identity → permission → machine → new credential loop,
  distance-bounded so a real chain turns it and an assumption-chain does
  not run forever
- paths() separates what was walked from what is believed; one assumed
  hop caps the chain at informational instead of laundering it to critical
- choke_points(): the single edge whose removal cuts the most value to
  crown jewels — the question a CVSS-sorted finding list cannot answer
- detection_gaps(): unchecked reported as unchecked, never as unmonitored
- dangling edges refused; re-adding a node upgrades rather than duplicates
- `neurosploit internal --graph g.json --scaffold corp.local --from <node>`

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:19:15 -03:00
..