L1ghtn1ng
86c2c5f979
fix: enforce discovery security boundaries
...
Keep proxy identities stable across provider conversations, preserve exact target scope, canonicalize evidence, secure first-run config creation, and retain legacy source-name compatibility.
2026-08-25 01:29:05 +01:00
NotoriousRebel
ea9dab4b87
feat: replace takeover fingerprints with typed evidence
2026-08-15 03:30:33 -04:00
Matt and GitHub
b8a8f7c7ca
fix: move Shodan discovery into adapter ( #2535 )
...
* fix: move Shodan discovery into adapter (#283 )
* docs: clarify Shodan transport and persistence
* fix: query every Shodan-resolved IPv4
* fix: call Shodan Host API directly
* fix: serve HarvestView assets locally
* Revert "fix: serve HarvestView assets locally"
This reverts commit 413e8b25ab .
* docs: clarify Shodan proxy transport
* docs: clarify Shodan changelog entry
* feat: persist structured Shodan host evidence
* feat: expand Shodan discovery with TLS search
2026-08-14 21:11:12 -04:00
Matt and GitHub
624066a3e8
Add RouteViews enrichment and sourced ASN organization attribution ( #2528 )
...
* Add RouteViews network enrichment
* Add authenticated RouteViews API access
* Restrict RouteViews to explicit network pivots
* Restore discovered ASN RouteViews enrichment
* Retain sourced ASN organization attribution
* Avoid dangling and repeated ASN attributions
* Keep automatic RouteViews evidence target-relevant
* Complete target-relevant RouteViews enrichment
* Clarify automatic RouteViews IP pivots
2026-08-13 10:46:54 -04:00
Matt and GitHub
f13280ddad
Add typed ASN-prefix routing evidence ( #2527 )
...
* Add typed network evidence foundation
* Deepen network evidence accumulation
* Bound network evidence accumulator limits
* Make nested JSON rejection test version tolerant
* Keep network evidence in unreleased schema v8
* Clarify structured result persistence dispatch
2026-08-12 10:49:16 -04:00
Matt and GitHub
fa8afa5e46
Add bounded virtual-host discovery ( #2517 )
...
* Add bounded virtual-host discovery
* Document virtual host probe boundary
2026-08-11 00:43:04 -04:00
Matt and GitHub
1fd5749e52
Add an authenticated durable run API v1 ( #2511 )
...
* Model active evidence in result persistence
* Expose active action diagnostics
* Persist truthful DNS action evidence
* Persist direct action evidence
* feat: add authenticated durable run API v1
* Make API file interchange JSONL-only
* Harden API evidence boundaries
* Remove API rate limiter
* Unify API runs with result persistence
* Support target action runs
* Keep DNS resolver selection action-neutral
* Add action-neutral CLI resolver selection
* Preserve API evidence across JSONL round trips
* Complete HarvestView API run parity
* Harden HarvestView run API contracts
* Remove obsolete bundled network snapshots
Delete the unused bundled AWS IP-range and resolver snapshots while preserving operator-supplied resolver file input.
* refactor: canonicalize URL results
* docs: define a bounded test budget
* Standardize hostname and IP result names
* fix(api): avoid duplicate evidence conflicts
2026-08-10 00:08:04 -04:00
Matt and GitHub
e4d37b05a8
Persist per-source run provenance ( #2516 )
...
* Persist per-source run provenance
* Keep the first JSONL contract unversioned
* Explain source yield counts
2026-08-09 11:50:08 -04:00
Matt and GitHub
6b02dbddc9
Share safe enumeration execution across transports ( #2507 )
...
* feat: share safe enumeration execution across transports
* fix: clarify safe scan contracts
* fix: preserve public screenshot redirects
* fix: restore operator-controlled active requests
* fix: allow operator-selected API scan targets
2026-08-07 16:02:16 -04:00
NotoriousRebel
708405c882
feat: add completed-result JSONL reports
2026-08-05 01:59:08 -04:00