mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 20:41:51 +02:00
The Arena engagement produced 24 findings, a graph with 83 edges, and exactly one chain edge. Two defects, both a step nobody was doing rather than a model reasoning badly. chains_from came back empty on every finding. An agent works one vulnerability and has no view of what the other twelve found, so asking it to link its result to findings it never saw was asking for something it cannot know. Chaining now happens after the whole set is visible, on rules about ENABLEMENT: what one weakness yields that another needs. Account enumeration yields valid identities; absent throttling turns them into unlimited guesses; a permissive password policy makes the guessing land. None is severe alone, and that sequence is how accounts get taken over — on the real data it now reads CWE-307 <- CWE-204, CWE-208 and CWE-614 <- CWE-319. The CWE->stage fallback sent 23 of 24 findings to initial-access, so the kill chain had one populated column and drew a star. Enumeration and side channels are discovery; missing throttling, password policy, cookie flags and session fixation are credential-access; hardening headers are recon. The same run now spreads across credential-access 13, discovery 6, initial-access 5. Two bugs the tests and the real data caught: - CWE-614 both yields session material and needs it, so a class chained to itself: duplicates formed a circular "attack path" from a cookie flag to the same cookie flag. A weakness class no longer enables itself. - apply_links only fills an empty chains_from, which is right for asserted chains and wrong for links written by an older version of these rules — a report kept the circular link through two rebuilds because nothing was allowed to touch it. repair() now drops links that cannot be true whoever wrote them: self-references, same-class links, dangling ids, cross-host links. enrich() still only fills empty fields during a run (an agent's judgement should survive), but a rebuild applies the current mappings via remap_stages — otherwise a finished run is frozen with whatever taxonomy existed that day. path_for() gives the per-vulnerability view: what precedes this finding, what it enables, and the narrative to print beside it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>