docs: drop the pointers to the removed TLS and AI-surface guinea pigs
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ffce08c
docs: the vhost custom wordlist is a hostname list
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
84a8adb
docs: deserialization skill switches (OOB/timing/scope/runtimes/exec/PHAR)
Document the seven project switches for the Insecure Deserialization skill, the
three confirmation channels they gate, and the regenerated settings + MCP pages.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
d283d8b
docs: the serialized-object Jev ranking acts
Jev's format and reachability are written onto each candidate and the
deserialization skill confirms the most reachable first; without Jev the
candidates are the signatures' own. TypeSafe Jev, Serialized Object Detection,
AI in the Recon Pipeline, Recon Pipeline Workflow, Agent Skills and Mute Rules
updated; settings registry regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
653b8b0
docs: list Insecure deserialization in the Mute Rules kinds table
The node-filter engine already has the vuln.serialized_scan kind; the wiki
"Kinds you can filter" table was missing its row.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
3768eb8
docs: partial serialized recon reads headers, parameters and form names; 19-slide Jev deck
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
d93b757
docs: deserialization skill records confirmations through chain_findings
The skill never had a report tool: a confirmation reaches the graph only as a
chain_findings entry in output_analysis, filled in the same response that reads
the proof. Serialized-Object-Detection (lifecycle and agent steps) and
Agent-Skills (steps 5-6) now say so, plus a model note from the live test:
deepseek-chat confirmed the sink but never filled the field, deepseek-v4-pro did.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
49f167c
docs: Serialized Object Scan card screenshot with the corrected copy
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
0fa8458
docs: serialized-object review fixes
The Jev ranking sends evidence only, never the format or the marker label that
names it, and its act mode is described as the later change it is. One
candidate per sink and format; deser_location is the cookie's, parameter's or
header's own name; encoding_layers are the layers peeled to reach the match. The
honest ceiling names httpxPaths; the data-sent and budget lines match the code;
the scan card's control is listed; the shadow hooks are no longer said to use
their answer. Settings registry regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
a87c5ee
docs: serialized-object Jev ranking; the complete AI in Pipeline hook list
TypeSafe Jev gains its serialized-object ranking section and the five
Jev-only hooks everywhere the count appears. Serialized Object Detection
covers form fields, one candidate per format per value, the honest ceiling
of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI
in Pipeline panel with every hook card, the Jev token card, and the
Serialized Object Scan card. MCP API reference and settings registry
regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
34e7dc4
docs(agent-skills): kali ruby/viewgen in the deserialization skill; fix stale phpggc claim
The Insecure Deserialization skill's Tools line now lists ruby + viewgen, and
the RCE skill description no longer says phpggc is not preinstalled (it is).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
b61c9b5
docs: serialized object detection + insecure deserialization skill
New Serialized-Object-Detection operator guide (detect->confirm model,
families, safety, candidate lifecycle, settings, graph query). Adds the
Insecure Deserialization built-in skill to Agent-Skills, the
serialized_scan source + deser_* props to Attack-Surface-Graph, and nav
wiring in Home + _Sidebar.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
0da08e1
docs(wiki): refresh settings registry for serializedScanEnabled
Regenerate Project-Settings-Registry.md (npm run docs:settings) and update the
narrative counts in Project-Settings-Reference.md for the new serializedScanEnabled
recon parameter (726 -> 727 stored, 659 -> 660 settable).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
423c73a
docs(mcp): 5,000 findings per mute or unmute call, no daily budget
MCP Server and the generated MCP API Reference follow the new limits: one
call names up to 5,000 findings, a token makes at most 200 mute or unmute
calls a minute, and the daily mute budget is gone.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
df27b2b
docs(recon): crt.name answers when crt.sh gives no answer
Running Reconnaissance and Origin Discovery say when the fallback is used,
its quota of 100 requests a day per IP, the 50,000-name read limit, and
that turning crt.sh off turns it off too.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
72c1a1a
docs(jev): page-type pre-filter needs HTML; tool-health redacts session headers
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
48ac74d
docs(jev): the four Jev-only hooks in shadow mode
- TypeSafe-Jev: page-type labels, FFuf base-path ranking, Hakrawler seed
order and tool health (what Jev is asked, the result, cache, on failure),
a Shadow mode section, the two-level switch, the data each sends to
TypeSafe, cost and limits, the preflight kinds, log tags and
troubleshooting; the refusal text and the preset rule corrected
- AI-in-the-Recon-Pipeline, Recon-Pipeline-Workflow, AI-Model-Providers,
Global-Settings and Home name the Jev-only hooks where they list Jev's
- screenshots retaken: the AI in Pipeline panel with the Jev-only cards,
and the TypeSafe AI (Jev) section with its new intro
- Project-Settings-Reference counts (726 stored, 659 settable);
Project-Settings-Registry and MCP-API-Reference regenerated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
b0284c4
docs: vhost noise bookkeeping, co-hosted names, the JS hostname cap
- VHost-and-SNI-Enumeration: the IP node now records how many anomalies a
permissive frontend's noise filter discarded and a sample of their names;
a co-hosted third party's name stays in the graph but partial recon no
longer scans it
- Project-Settings-Registry (generated): tlsxMaxInjectedHostnames also caps
the hostnames JS Recon finds
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
a71371f
docs: a TypeSafe Jev page and the Jev Meets the Recon Pipeline walkthrough
- TypeSafe-Jev: what Jev is, the four hooks it can answer and what each may
decide, the call flow, setup, the per-hook switches, token ownership,
containment (closed answer sets, floors, static fallbacks), failure
behaviour, the data sent to TypeSafe, cost, MCP, logs and troubleshooting
- links to the animated walkthrough on redamon.org from the top of the page,
Home and the sidebar
- AI-in-the-Recon-Pipeline, AI-Model-Providers, Global-Settings,
Recon-Pipeline-Workflow, Data-Export-and-Import and
Subdomain-Takeover-Detection point at the new page where they mention Jev
- new screenshots of the Jev settings section and the Target AI panel
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7d92443
docs(settings): wafAiClassifier records jev_classifier on the Jev engine
Regenerated with npm run docs:settings.
0b5de42
docs: TypeSafe AI (Jev) provider, the LLM | Jev engine on four recon AI hooks
- AI-in-the-Recon-Pipeline: engine choice, the four hooks and what each may do,
why the false-positive filter has no Jev option, the three-level model, how a
bad answer is contained, failure behaviour, and the third-party data note
- AI-Model-Providers: the TypeSafe AI (Jev) section (one token, pinned model,
not a chat model)
- Global-Settings: the Jev check spends a trace of credit
- generated: MCP API reference, settings registry and reference (4 new settable
fields, preflight aiHooks)
c9357d3
docs(home): align positioning with the repo description
Drop "zero human intervention", which contradicted the human approval
gates; use the canonical sentence from the GitHub About box plus the
two-way MCP line.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
0f59375
docs(settings): ffufSmartFuzzMaxBasePaths caps smart-fuzz base paths
Regenerated Project-Settings-Registry and MCP-API-Reference for the new
settable field (651 settable, 718 stored), and described the cap and the
random pick in the narrative Project-Settings-Reference FFuf section.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
93f4e03
docs(wiki): restyle all Mermaid diagrams for light and dark mode
Pin every diagram to theme:base with explicit themeVariables, and give
every node a fill and text colour, so the diagrams render identically on
GitHub light, GitHub dark, and the VS Code Markdown Preview (which draws
Mermaid with the light theme on a dark page, leaving theme-coloured text
invisible before this change).
One shared palette carries meaning across all diagrams: blue = user,
violet = agent/LLM, slate = infra/steps, teal = datastore, green = good,
amber = warning/secret/output, red = danger/finding. Edge labels get
padded slate chips; subgraphs get dashed grey borders.
Also redraw the Tradecraft resource-lifecycle state diagram left-to-right
(the auto-layout overlapped labels) and drop the now-obsolete greyscale
rationale comment in Authenticated-Session-Recording.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
fdd66cf
docs(triage): every open tab follows a triage run
A second tab on the project (the Priority Board and CypherFix side by side)
no longer takes the run over; both see its progress and its end. A tab that
was already open when an agent started the run shows it after a reload.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
365ec5f
docs(triage): hardening notes for reviews, verdicts, stops and Ask agent
get_finding_triage returns review text (fix lever included) only with
includeQuotes and separates host proof from finding proof; a proven finding
takes a raising review; evidence redacts credential headers and shows the
nuclei matcher and GVM port/solution type; an agent image older than the
webapp refuses MCP verdicts (agent_outdated); an agent's stop reaches every
open tab; Ask agent fences the node name as untrusted. MCP API reference
regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
37c73d1
docs: sync the wiki with Multi mute and Models by feature
New screenshots of the Multi mute dialog and the Models by feature grid;
refreshed CypherFix settings (the two account-wide model pickers), RoE tab
(its model line) and node drawer (Multi mute beside Mute). Home and the
sidebar link both sections, the drawer's action table follows the
on-screen order, and Muted Nodes and Global Settings note the re-run
after a muted seed and the grid waiting for a save.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
d7e8e13
docs: Multi mute, Models by feature and the three-layer Priority Board
Multi mute on Muted Nodes and the Red Zone, Models by feature in Global
Settings and on every feature page that asks for a model, the settings
that retire the per-project CypherFix model, and the Priority Board's
rules, review and decision layers with the MCP review and run tools.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1cf6e0f
docs(scan-timeline): what blocks activation, the queued-scan agent wait, pauses that stick
- Scan Timeline: every writer that blocks a version activation, including
an agent session (counted only while the agent confirms it); a queued
full recon waits for an agent session; a pause made while a run starts
is not undone
- Troubleshooting: "An agent session is running", but none is
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
9d42145