Skip to content

History

Revisions

  • docs: drop the pointers to the removed TLS and AI-surface guinea pigs Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 8, 2026
    ffce08c
  • docs: the vhost custom wordlist is a hostname list Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 8, 2026
    84a8adb
  • docs: deserialization skill switches (OOB/timing/scope/runtimes/exec/PHAR) Document the seven project switches for the Insecure Deserialization skill, the three confirmation channels they gate, and the regenerated settings + MCP pages. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 7, 2026
    d283d8b
  • docs: the serialized-object Jev ranking acts Jev's format and reachability are written onto each candidate and the deserialization skill confirms the most reachable first; without Jev the candidates are the signatures' own. TypeSafe Jev, Serialized Object Detection, AI in the Recon Pipeline, Recon Pipeline Workflow, Agent Skills and Mute Rules updated; settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 7, 2026
    653b8b0
  • docs: list Insecure deserialization in the Mute Rules kinds table The node-filter engine already has the vuln.serialized_scan kind; the wiki "Kinds you can filter" table was missing its row. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 7, 2026
    3768eb8
  • docs: partial serialized recon reads headers, parameters and form names; 19-slide Jev deck Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    d93b757
  • docs: deserialization skill records confirmations through chain_findings The skill never had a report tool: a confirmation reaches the graph only as a chain_findings entry in output_analysis, filled in the same response that reads the proof. Serialized-Object-Detection (lifecycle and agent steps) and Agent-Skills (steps 5-6) now say so, plus a model note from the live test: deepseek-chat confirmed the sink but never filled the field, deepseek-v4-pro did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    49f167c
  • docs: Serialized Object Scan card screenshot with the corrected copy Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    0fa8458
  • docs: serialized-object review fixes The Jev ranking sends evidence only, never the format or the marker label that names it, and its act mode is described as the later change it is. One candidate per sink and format; deser_location is the cookie's, parameter's or header's own name; encoding_layers are the layers peeled to reach the match. The honest ceiling names httpxPaths; the data-sent and budget lines match the code; the scan card's control is listed; the shadow hooks are no longer said to use their answer. Settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    a87c5ee
  • docs: serialized-object Jev ranking; the complete AI in Pipeline hook list TypeSafe Jev gains its serialized-object ranking section and the five Jev-only hooks everywhere the count appears. Serialized Object Detection covers form fields, one candidate per format per value, the honest ceiling of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI in Pipeline panel with every hook card, the Jev token card, and the Serialized Object Scan card. MCP API reference and settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    34e7dc4
  • docs(agent-skills): kali ruby/viewgen in the deserialization skill; fix stale phpggc claim The Insecure Deserialization skill's Tools line now lists ruby + viewgen, and the RCE skill description no longer says phpggc is not preinstalled (it is). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    b61c9b5
  • docs: serialized object detection + insecure deserialization skill New Serialized-Object-Detection operator guide (detect->confirm model, families, safety, candidate lifecycle, settings, graph query). Adds the Insecure Deserialization built-in skill to Agent-Skills, the serialized_scan source + deser_* props to Attack-Surface-Graph, and nav wiring in Home + _Sidebar. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    0da08e1
  • docs(wiki): refresh settings registry for serializedScanEnabled Regenerate Project-Settings-Registry.md (npm run docs:settings) and update the narrative counts in Project-Settings-Reference.md for the new serializedScanEnabled recon parameter (726 -> 727 stored, 659 -> 660 settable). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 6, 2026
    423c73a
  • docs(mcp): 5,000 findings per mute or unmute call, no daily budget MCP Server and the generated MCP API Reference follow the new limits: one call names up to 5,000 findings, a token makes at most 200 mute or unmute calls a minute, and the daily mute budget is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 5, 2026
    df27b2b
  • docs(recon): crt.name answers when crt.sh gives no answer Running Reconnaissance and Origin Discovery say when the fallback is used, its quota of 100 requests a day per IP, the 50,000-name read limit, and that turning crt.sh off turns it off too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 5, 2026
    72c1a1a
  • wiki update

    @samugit83 samugit83 committed Oct 2, 2026
    5e402c1
  • docs(jev): page-type pre-filter needs HTML; tool-health redacts session headers Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 2, 2026
    48ac74d
  • docs(jev): the four Jev-only hooks in shadow mode - TypeSafe-Jev: page-type labels, FFuf base-path ranking, Hakrawler seed order and tool health (what Jev is asked, the result, cache, on failure), a Shadow mode section, the two-level switch, the data each sends to TypeSafe, cost and limits, the preflight kinds, log tags and troubleshooting; the refusal text and the preset rule corrected - AI-in-the-Recon-Pipeline, Recon-Pipeline-Workflow, AI-Model-Providers, Global-Settings and Home name the Jev-only hooks where they list Jev's - screenshots retaken: the AI in Pipeline panel with the Jev-only cards, and the TypeSafe AI (Jev) section with its new intro - Project-Settings-Reference counts (726 stored, 659 settable); Project-Settings-Registry and MCP-API-Reference regenerated Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 2, 2026
    b0284c4
  • docs: vhost noise bookkeeping, co-hosted names, the JS hostname cap - VHost-and-SNI-Enumeration: the IP node now records how many anomalies a permissive frontend's noise filter discarded and a sample of their names; a co-hosted third party's name stays in the graph but partial recon no longer scans it - Project-Settings-Registry (generated): tlsxMaxInjectedHostnames also caps the hostnames JS Recon finds Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 1, 2026
    a71371f
  • docs: a TypeSafe Jev page and the Jev Meets the Recon Pipeline walkthrough - TypeSafe-Jev: what Jev is, the four hooks it can answer and what each may decide, the call flow, setup, the per-hook switches, token ownership, containment (closed answer sets, floors, static fallbacks), failure behaviour, the data sent to TypeSafe, cost, MCP, logs and troubleshooting - links to the animated walkthrough on redamon.org from the top of the page, Home and the sidebar - AI-in-the-Recon-Pipeline, AI-Model-Providers, Global-Settings, Recon-Pipeline-Workflow, Data-Export-and-Import and Subdomain-Takeover-Detection point at the new page where they mention Jev - new screenshots of the Jev settings section and the Target AI panel Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 1, 2026
    7d92443
  • docs(settings): wafAiClassifier records jev_classifier on the Jev engine Regenerated with npm run docs:settings.

    @samugit83 samugit83 committed Oct 1, 2026
    0b5de42
  • docs: TypeSafe AI (Jev) provider, the LLM | Jev engine on four recon AI hooks - AI-in-the-Recon-Pipeline: engine choice, the four hooks and what each may do, why the false-positive filter has no Jev option, the three-level model, how a bad answer is contained, failure behaviour, and the third-party data note - AI-Model-Providers: the TypeSafe AI (Jev) section (one token, pinned model, not a chat model) - Global-Settings: the Jev check spends a trace of credit - generated: MCP API reference, settings registry and reference (4 new settable fields, preflight aiHooks)

    @samugit83 samugit83 committed Oct 1, 2026
    c9357d3
  • docs(home): align positioning with the repo description Drop "zero human intervention", which contradicted the human approval gates; use the canonical sentence from the GitHub About box plus the two-way MCP line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Oct 1, 2026
    0f59375
  • docs(settings): ffufSmartFuzzMaxBasePaths caps smart-fuzz base paths Regenerated Project-Settings-Registry and MCP-API-Reference for the new settable field (651 settable, 718 stored), and described the cap and the random pick in the narrative Project-Settings-Reference FFuf section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 30, 2026
    93f4e03
  • docs(wiki): restyle all Mermaid diagrams for light and dark mode Pin every diagram to theme:base with explicit themeVariables, and give every node a fill and text colour, so the diagrams render identically on GitHub light, GitHub dark, and the VS Code Markdown Preview (which draws Mermaid with the light theme on a dark page, leaving theme-coloured text invisible before this change). One shared palette carries meaning across all diagrams: blue = user, violet = agent/LLM, slate = infra/steps, teal = datastore, green = good, amber = warning/secret/output, red = danger/finding. Edge labels get padded slate chips; subgraphs get dashed grey borders. Also redraw the Tradecraft resource-lifecycle state diagram left-to-right (the auto-layout overlapped labels) and drop the now-obsolete greyscale rationale comment in Authenticated-Session-Recording. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 30, 2026
    fdd66cf
  • docs(triage): every open tab follows a triage run A second tab on the project (the Priority Board and CypherFix side by side) no longer takes the run over; both see its progress and its end. A tab that was already open when an agent started the run shows it after a reload. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 30, 2026
    365ec5f
  • docs(triage): hardening notes for reviews, verdicts, stops and Ask agent get_finding_triage returns review text (fix lever included) only with includeQuotes and separates host proof from finding proof; a proven finding takes a raising review; evidence redacts credential headers and shows the nuclei matcher and GVM port/solution type; an agent image older than the webapp refuses MCP verdicts (agent_outdated); an agent's stop reaches every open tab; Ask agent fences the node name as untrusted. MCP API reference regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
    37c73d1
  • docs: sync the wiki with Multi mute and Models by feature New screenshots of the Multi mute dialog and the Models by feature grid; refreshed CypherFix settings (the two account-wide model pickers), RoE tab (its model line) and node drawer (Multi mute beside Mute). Home and the sidebar link both sections, the drawer's action table follows the on-screen order, and Muted Nodes and Global Settings note the re-run after a muted seed and the grid waiting for a save. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
    d7e8e13
  • docs: Multi mute, Models by feature and the three-layer Priority Board Multi mute on Muted Nodes and the Red Zone, Models by feature in Global Settings and on every feature page that asks for a model, the settings that retire the per-project CypherFix model, and the Priority Board's rules, review and decision layers with the MCP review and run tools. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
    1cf6e0f
  • docs(scan-timeline): what blocks activation, the queued-scan agent wait, pauses that stick - Scan Timeline: every writer that blocks a version activation, including an agent session (counted only while the agent confirms it); a queued full recon waits for an agent session; a pause made while a run starts is not undone - Troubleshooting: "An agent session is running", but none is Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

    @samugit83 samugit83 committed Sep 29, 2026
    9d42145