Skip to content

History / Project Settings Reference

Revisions

  • docs: deserialization skill switches (OOB/timing/scope/runtimes/exec/PHAR) Document the seven project switches for the Insecure Deserialization skill, the three confirmation channels they gate, and the regenerated settings + MCP pages. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 7, 2026
  • docs: serialized-object Jev ranking; the complete AI in Pipeline hook list TypeSafe Jev gains its serialized-object ranking section and the five Jev-only hooks everywhere the count appears. Serialized Object Detection covers form fields, one candidate per format per value, the honest ceiling of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI in Pipeline panel with every hook card, the Jev token card, and the Serialized Object Scan card. MCP API reference and settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
  • docs(wiki): refresh settings registry for serializedScanEnabled Regenerate Project-Settings-Registry.md (npm run docs:settings) and update the narrative counts in Project-Settings-Reference.md for the new serializedScanEnabled recon parameter (726 -> 727 stored, 659 -> 660 settable). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
  • docs(jev): the four Jev-only hooks in shadow mode - TypeSafe-Jev: page-type labels, FFuf base-path ranking, Hakrawler seed order and tool health (what Jev is asked, the result, cache, on failure), a Shadow mode section, the two-level switch, the data each sends to TypeSafe, cost and limits, the preflight kinds, log tags and troubleshooting; the refusal text and the preset rule corrected - AI-in-the-Recon-Pipeline, Recon-Pipeline-Workflow, AI-Model-Providers, Global-Settings and Home name the Jev-only hooks where they list Jev's - screenshots retaken: the AI in Pipeline panel with the Jev-only cards, and the TypeSafe AI (Jev) section with its new intro - Project-Settings-Reference counts (726 stored, 659 settable); Project-Settings-Registry and MCP-API-Reference regenerated Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 2, 2026
  • docs: TypeSafe AI (Jev) provider, the LLM | Jev engine on four recon AI hooks - AI-in-the-Recon-Pipeline: engine choice, the four hooks and what each may do, why the false-positive filter has no Jev option, the three-level model, how a bad answer is contained, failure behaviour, and the third-party data note - AI-Model-Providers: the TypeSafe AI (Jev) section (one token, pinned model, not a chat model) - Global-Settings: the Jev check spends a trace of credit - generated: MCP API reference, settings registry and reference (4 new settable fields, preflight aiHooks)

    @samugit83 samugit83 committed Oct 1, 2026
  • docs(settings): ffufSmartFuzzMaxBasePaths caps smart-fuzz base paths Regenerated Project-Settings-Registry and MCP-API-Reference for the new settable field (651 settable, 718 stored), and described the cap and the random pick in the narrative Project-Settings-Reference FFuf section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 30, 2026
  • docs: Multi mute, Models by feature and the three-layer Priority Board Multi mute on Muted Nodes and the Red Zone, Models by feature in Global Settings and on every feature page that asks for a model, the settings that retire the per-project CypherFix model, and the Priority Board's rules, review and decision layers with the MCP review and run tools. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
  • docs(mcp): recon presets and project rescope over MCP Document the preset tools (list, create, update, delete, apply) and update_project_scope, their three permissions and profile ticks, the settings-surface counts and compare-and-swap, the stale-form 409, the agent-written preset badge and the presets no longer carrying the MCP sandbox switch. Regenerate the MCP API reference and the settings registry page from the committed code. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
  • docs: preset load confirms and saves, presets hold every setting, applied badge Recon-Presets and Creating-a-Project describe the new load flow (confirm, replace, save immediately), what a preset now captures and excludes, and the "Preset applied" badge. The settings registry page is regenerated and the stored-parameter count is 715 for the new loadedPreset column. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 23, 2026
  • docs: the UI the engagement split actually shipped A deep check of every hand-written page against the branch found six gaps. The two generated pages (Project Settings Registry, MCP API Reference) were already current; every gap was in prose nobody regenerates. Rules of Engagement - `roeForbiddenCategories` listed four tokens. There are five: `exploitation` was missing. - `roeForbiddenTools` read as free text. Both lists are now closed vocabularies ticked from the registry, and the page says why that is a safety property rather than tidiness: the gate matches these strings EXACTLY, so a near-miss is not partially enforced, it is not enforced at all. A live project held `execute_sqlmap`, which is not a tool, beside categories reading "Denial of Service" and "Brute Forcing", which the gate does not know. - The parse section did not mention that an oversized proposal is refused with 422 and writes nothing, nor that a policy's identification header now reaches `engagementIdentityHeader` - the single most common concrete instruction such documents carry, in 28 of 60 sampled. - The authorization history panel was undocumented: append-only, digest only, and a failed fetch is not the same as "no record". Project Settings Reference - The page told readers the agent's limits were in Agent Behaviour and then never listed them. All six are documented there now. - The "Advanced" block was undocumented. It is in seventeen module sections and exists because sixty-five columns were writable over the API with an input nowhere in the form. MCP Server - "The thirty tools" is thirty-four. `create_project`, `attach_engagement_authorization` and `list_engagement_authorizations` were missing from the table, and `project:create` and `engagement:authorize` from the permissions. - "Not exposed, deliberately" still listed the scope fields. Scope is now a create-only exception with a stricter rule, and the page states it. - "Only about 126 tuning fields are settable" is 648 of 714. Screenshots retaken (the old ones predate the split by six months) and two added: the engagement limits in Agent Behaviour showing the tool checkboxes, and the registry-generated Advanced block. Checked and clean: no stated default or numeric bound on any hand-written page disagrees with the registry; no page still names `tighten_engagement_roe` or `roeEnabled` as a switch.

    @samugit83 samugit83 committed Sep 17, 2026
  • docs: split Rules of Engagement into limits and record The engagement is two unrelated things, and the wiki described it as one. Rules-of-Engagement.md is rewritten around the split: the LIMITS are ordinary settings, reachable from the form and the API alike and enforced at scan start, and the RECORD is the contract a person writes and no token can touch. The "set once at creation, read-only afterwards" claim is gone; only the record is creation-time. Also updated: - Recon-Presets: a preset never carries the engagement, at capture or at apply, and the exclusion is a registry query rather than a name-prefix match - MCP-Server: update_recon_settings reaches the limits in either direction, and what keeps that safe is enforcement at scan start, not a write-time rule - Creating-a-Project: tab 1 is the Engagement Record; the limits live elsewhere and stay editable - Origin-Discovery: the mechanism is unchanged, the field classification is not - AI-Gauntlet: its RoE checkbox is a per-launch confirmation, distinct from the project's engagement limits - Project-Settings-Reference: an Engagement Limits section, and two checked counts instead of one wrong one. "714 configurable parameters" overstated the surface exactly as the "245+" it replaced understated it - Project-Settings-Registry and MCP-API-Reference: regenerated A test fails any page that still names tighten_engagement_roe, the tighten_only disposition, or a roe* field as MCP-settable.

    @samugit83 samugit83 committed Sep 17, 2026
  • docs: generate the settings registry, and fix a count that was off by two thirds Project-Settings-Reference.md opened by claiming "245+ configurable parameters" against a model of 714. That is the failure mode of a hand-written exhaustive reference: right on the day it is written, quietly wrong every day after, and nobody notices because nobody counts. The narrative page keeps its screenshots and its tour and now states the real number, which a test checks against the registry. Beside it, Project-Settings-Registry.md is generated from recon_settings/registry.yaml with every parameter, its enforced bound, its default, whether an external agent may write it, and what it means. The rows that carry a warning carry it in the row: a rate whose zero means unlimited, a value the engagement ceiling rewrites at scan start, a field fixed at creation, and a column withheld from every read. The MCP API reference picks up five new tools and the rewritten recon:settings blurb, whose old wording broke in the direction that made the permission sound safer than it was.

    @samugit83 samugit83 committed Sep 16, 2026
  • docs: add redamon.org/docs canonical banners + XBEN 8/16-20 walkthrough videos Prepend a canonical banner to each curated wiki page linking to its version on the official docs site (redamon.org/docs), so search engines consolidate authority onto the owned domain instead of ranking the GitHub wiki. Also adds the walkthrough video links to XBEN-008/016/017/018/019/020 in the benchmark table.

    @samugit83 samugit83 committed Aug 31, 2026
  • docs(settings): document the auto-detected LHOST suggestion + HOST_LAN_IP override (#180)

    @samugit83 samugit83 committed Aug 31, 2026
  • docs: Domain batch across the targeting-mode wiki pages The project form's targeting mode is now three modes, not a domain/IP boolean. Updated every page that described the two-mode selector: - Creating-a-Project: the Targeting Mode section now lists Single Domain / IP / CIDR / Domain batch, plus a full Domain Batch Mode subsection (the grouping rule with the worked example, one-scan-not-many, progressive graph writes and single version, the size limits). - Running-Reconnaissance: the "Domain Mode vs IP Mode" table gains a Domain batch column and a note that it runs the Single-Domain pipeline once per group. - Project-Settings-Reference: target-config table renamed to a three-mode Targeting Mode row plus the Domain Batch Hostnames field. - Pentest-Reports and Home: scan-mode / overview wording. First target mode renamed "Domain / Hostname" -> "Single Domain" to match the UI.

    @samugit83 samugit83 committed Aug 31, 2026
  • docs(wiki): remove Burp Suite references; document the proxy_brain browser capability

    @samugit83 samugit83 committed Aug 29, 2026
  • docs(wiki): replace the retired proxy_* tools with proxy_brain + add a dedicated page The ten proxy_* traffic tools were collapsed into one code-native tool, proxy_brain. Update the wiki to match: - New page Proxy-Brain.md: deep explanation — the one-tool idea, the end-to-end flow (Kali sandbox -> redamon SDK -> /traffic/exec + /traffic/replay broker -> capture proxy), the full redamon SDK, the on-demand manual, the Burp-capability map, the security model (host-pin, tenant tag, egress guard, phase gate, send budget), and worked prompts + the pbtarget practice target. - TrafficMind.md: the "agent's traffic tools" section rewritten around proxy_brain (was the ten-tool tables); intro, mermaid, routing and troubleshooting references updated; links to the new page. - AI-Agent-Guide.md: tool lists updated; the ten per-tool subsections replaced with a single proxy_brain section. - Project-Settings-Reference.md: Tool Matrix rows collapsed to one proxy_brain row. - _Sidebar.md: link the new page next to TrafficMind.

    @samugit83 samugit83 committed Aug 29, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Aug 19, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Aug 18, 2026
  • docs: supply-chain incident intel (6.10.0) - Supply-Chain-Scanning: new "The incident catalog (threat intel)" section (sync command, the six knobs, what it adds, the three things it deliberately does not do, and the honest scope note that this catches the browser-side class rather than supply-chain attacks in general). Adds the two new project toggles, the Incident column on the Verdicts sheet, and the ThreatPulse / CONTACTS_MALICIOUS_HOST half of the graph model. - Project-Settings-Reference: scaIntelCorrelationEnabled (default ON) and supplyChainTyposquatEnabled (default off, gates only the fuzzy check). - TrafficMind: the ioc flag chip and the per-user ignore list, including that clearing the box restores the shipped list rather than disabling suppression. - Red-Zone: Threat Intel now has a third kind of row (BaseURL / Contacted host) and why the edge type keeps it from reading as "your host is an indicator"; the SCA Verdicts sheet gains the Incident column. - Attack-Surface-Graph: the new relationship in the chain, typosquat as a source_tool, and the incident_* properties. - Recon-Pipeline-Workflow: what GROUP 5.5 now does beyond the OSV verdict.

    @samugit83 samugit83 committed Aug 15, 2026
  • docs: repoint remaining reorganization paths (blob URLs, deploy, scanners, kb, internal) Absolute github blob/tree URLs and inline path references that still pointed at the pre-6.9 top-level layout: readmes/ -> docs/readmes/, deploy/single-host -> tooling/deploy/single-host, guinea_pigs -> testing/guinea_pigs, knowledge_base -> services/knowledge_base, the scanner dirs -> scanners/<name>, and internal/ + validation-benchmarks -> _local/.

    @samugit83 samugit83 committed Aug 11, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Aug 7, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Jul 23, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Jul 19, 2026
  • docs: remove Tor/proxychains recon-routing references The "route reconnaissance traffic through Tor" feature was removed from the product. Scrub the wiki of the removed setting and its behaviour: - drop the "Use Tor for Recon" project-setting rows (Creating-a-Project, Project-Settings-Reference) - delete the naabu and puredns "Tor / proxychains" paragraphs - graphql-cop always runs --network host now (no -T / -x / HTTP_PROXY) - reword masscan raw-SYN notes and stealth/preset copy to drop Tor framing Kept: CriminalIP threat-intel "Tor/VPN/proxy" TARGET detection, PDCP anonymous-mode API access, and captured tool --help in session transcripts (all unrelated to the removed routing feature).

    @samugit83 samugit83 committed Jul 19, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Jun 30, 2026
  • docs: update wiki

    @samugit83 samugit83 committed Jun 5, 2026
  • docs: update wiki

    @samugit83 samugit83 committed May 29, 2026
  • docs: udpate wiki

    @samugit83 samugit83 committed May 27, 2026
  • docs: update wiki

    @samugit83 samugit83 committed May 24, 2026