mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
Validators decide from recorded artifacts, and the weakest link was who recorded them: "the payload returned a 500" is still an agent's account of what happened. Replay produces the part that matters most in practice — reproducibility — by sending the request again through the harness's own client, with the scope guard in front of it. Three properties it is built around: - every request passes ScopePolicy::check_request before a socket is opened, so replay cannot be the thing that wanders off-scope while verifying a finding; - it never mutates: a finding proven with DELETE is not re-proven by deleting the record again, so non-idempotent verbs are refused and repeats of them are refused outright; - bodies are truncated at 96KB and SAY they were truncated — a silently clipped body makes a length differential meaningless. enrich() fills in repeats and re-measures a recorded baseline (comparing a fresh attack against an hour-old baseline attributes ordinary drift to the payload). It deliberately does NOT synthesize a baseline from an attack request: removing "the payload" from an arbitrary URL is guesswork, and a guessed baseline would silently decide the verdict. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>