docs: partial serialized recon reads headers, parameters and form names; 19-slide Jev deck
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: serialized-object Jev ranking; the complete AI in Pipeline hook list
TypeSafe Jev gains its serialized-object ranking section and the five
Jev-only hooks everywhere the count appears. Serialized Object Detection
covers form fields, one candidate per format per value, the honest ceiling
of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI
in Pipeline panel with every hook card, the Jev token card, and the
Serialized Object Scan card. MCP API reference and settings registry
regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: serialized object detection + insecure deserialization skill
New Serialized-Object-Detection operator guide (detect->confirm model,
families, safety, candidate lifecycle, settings, graph query). Adds the
Insecure Deserialization built-in skill to Agent-Skills, the
serialized_scan source + deser_* props to Attack-Surface-Graph, and nav
wiring in Home + _Sidebar.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
docs(jev): the four Jev-only hooks in shadow mode
- TypeSafe-Jev: page-type labels, FFuf base-path ranking, Hakrawler seed
order and tool health (what Jev is asked, the result, cache, on failure),
a Shadow mode section, the two-level switch, the data each sends to
TypeSafe, cost and limits, the preflight kinds, log tags and
troubleshooting; the refusal text and the preset rule corrected
- AI-in-the-Recon-Pipeline, Recon-Pipeline-Workflow, AI-Model-Providers,
Global-Settings and Home name the Jev-only hooks where they list Jev's
- screenshots retaken: the AI in Pipeline panel with the Jev-only cards,
and the TypeSafe AI (Jev) section with its new intro
- Project-Settings-Reference counts (726 stored, 659 settable);
Project-Settings-Registry and MCP-API-Reference regenerated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: a TypeSafe Jev page and the Jev Meets the Recon Pipeline walkthrough
- TypeSafe-Jev: what Jev is, the four hooks it can answer and what each may
decide, the call flow, setup, the per-hook switches, token ownership,
containment (closed answer sets, floors, static fallbacks), failure
behaviour, the data sent to TypeSafe, cost, MCP, logs and troubleshooting
- links to the animated walkthrough on redamon.org from the top of the page,
Home and the sidebar
- AI-in-the-Recon-Pipeline, AI-Model-Providers, Global-Settings,
Recon-Pipeline-Workflow, Data-Export-and-Import and
Subdomain-Takeover-Detection point at the new page where they mention Jev
- new screenshots of the Jev settings section and the Target AI panel
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(home): align positioning with the repo description
Drop "zero human intervention", which contradicted the human approval
gates; use the canonical sentence from the GitHub About box plus the
two-way MCP line.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: sync the wiki with Multi mute and Models by feature
New screenshots of the Multi mute dialog and the Models by feature grid;
refreshed CypherFix settings (the two account-wide model pickers), RoE tab
(its model line) and node drawer (Multi mute beside Mute). Home and the
sidebar link both sections, the drawer's action table follows the
on-screen order, and Muted Nodes and Global Settings note the re-run
after a muted seed and the grid waiting for a save.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(red-zone): document the node drawer actions and node-scoped agent sessions
Node Drawer: the Basic Info action row (copy context, ask agent, mute,
delete), what the copied brief contains and its limits, the smaller title
with a hover for clipped names, and the corrected delete scope. AI Agent
Guide: a second way in, a "Starting a Session from a Graph Node" section and
the node-chat title. Refreshes the node drawer screenshot, which also drops a
real hostname and IP the old image showed, and adds two new ones.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
docs: document the MCP Server surface, incl. kali_exec
Rename MCP-Access-Tokens to MCP-Server and cover the whole inbound
surface rather than just the token screen.
- MCP-Server: thirteen tools, the four switches guarding kali_exec, the
per-tool flag allowlist and what it refuses, rate limits and audit rows.
- MCP-API-Reference: generated by `npm run docs:mcp` from the server's own
tools/list. Never hand-edit; a unit test compares it byte for byte.
- Sidebar, Home and Global-Settings point at the new page name.
docs: add the MCP Access Tokens page (inbound MCP server)
docs: where the authenticated session is actually used
Documents the Authenticated Session Recording feature end to end, with two
real screenshots of the UI rather than placeholders.
The new depth is the consumer map: which recon modules and tools attach the
session (http_probe, resource_enum's six crawlers and fuzzers, vuln_scan,
ai_surface_recon, graphql_scan), the partial-recon equivalents, and the three
agent paths, plus what deliberately never gets it and why (GAU and ParamSpider
query third-party archives, so a session would go to the archive provider).
Also explains the two scope-enforcement models and why they differ: CLI tools
take one -H set for a whole targets file with no per-host syntax, so they fail
closed across every host, while the per-request consumers can be judged one
host at a time.
Corrects the page against the shipped product: the /traffic Record button no
longer exists, the two consumer switches were undocumented, the default scope
covers subdomains, and an anchor collided with its own parent heading. Adds
the OAST and same-host-redirect behaviour an attached session now triggers.
The diagram is greyscale with per-node text colours so it holds up on both the
light and dark themes; mermaid's defaults assume a white page.
Rename Finding Triage & Mute wiki page to Noise Gate
Rename the page file to Noise-Gate.md, retitle it, update the canonical
docs URL slug, and rework the branded terms in the body from "Triage" /
"Finding Triage" to "Noise Gate" (the per-finding Mute action keeps its
name). Update the Home page table row and the sidebar nav entry to the new
name and link.
Home.md and _Sidebar.md also carry the co-mingled Origin Discovery nav
entry, which could not be separated from this change; the XBOW/XBEN session
and patch files in this repo are intentionally left uncommitted.
docs: add redamon.org/docs canonical banners + XBEN 8/16-20 walkthrough videos
Prepend a canonical banner to each curated wiki page linking to its version on
the official docs site (redamon.org/docs), so search engines consolidate
authority onto the owned domain instead of ranking the GitHub wiki. Also adds
the walkthrough video links to XBEN-008/016/017/018/019/020 in the benchmark table.
docs: Domain batch across the targeting-mode wiki pages
The project form's targeting mode is now three modes, not a domain/IP boolean.
Updated every page that described the two-mode selector:
- Creating-a-Project: the Targeting Mode section now lists Single Domain / IP /
CIDR / Domain batch, plus a full Domain Batch Mode subsection (the grouping
rule with the worked example, one-scan-not-many, progressive graph writes and
single version, the size limits).
- Running-Reconnaissance: the "Domain Mode vs IP Mode" table gains a Domain batch
column and a note that it runs the Single-Domain pipeline once per group.
- Project-Settings-Reference: target-config table renamed to a three-mode
Targeting Mode row plus the Domain Batch Hostnames field.
- Pentest-Reports and Home: scan-mode / overview wording.
First target mode renamed "Domain / Hostname" -> "Single Domain" to match the UI.
docs: repoint remaining reorganization paths (blob URLs, deploy, scanners, kb, internal)
Absolute github blob/tree URLs and inline path references that still pointed at
the pre-6.9 top-level layout: readmes/ -> docs/readmes/, deploy/single-host ->
tooling/deploy/single-host, guinea_pigs -> testing/guinea_pigs, knowledge_base ->
services/knowledge_base, the scanner dirs -> scanners/<name>, and internal/ +
validation-benchmarks -> _local/.
docs(scans): rename Scan Scheduler to Scans, add scan queue + org batch