Matt and GitHub
f44807a046
refactor: run discovery sources with TaskGroup ( #2544 )
...
* refactor: run discovery sources with TaskGroup
* fix: preserve source runner compatibility diagnostics
* feat: add configurable source workers
2026-08-15 01:48:33 -04:00
Matt and GitHub
4fef2c5e3b
refactor: bound screenshot lifecycle ownership ( #2543 )
...
* refactor: bound screenshot lifecycle ownership (#293 )
* fix: retain HTTP error screenshots (#293 )
2026-08-14 23:10:34 -04:00
Matt and GitHub
38e32de023
fix: complete API endpoint scans by default ( #2539 )
...
* fix: complete API endpoint scans by default
* refactor: reuse shared cancellation cleanup
2026-08-14 23:03:28 -04:00
Matt and GitHub
1a9b114a5d
fix: complete DNS enumeration by default ( #2542 )
...
* fix: complete DNS enumeration by default
* test: avoid URL substring sanitizer alert
2026-08-14 22:54:25 -04:00
Matt and GitHub
bb77613a05
fix: call Censys Platform API directly ( #2537 )
...
* fix: call Censys Platform API directly (#295 )
(cherry picked from commit 7ce361413ad35471ab0b6878382f3548b0918dbe)
* docs: clarify Censys global search entitlement
2026-08-14 22:44:45 -04:00
Matt and GitHub
b8a8f7c7ca
fix: move Shodan discovery into adapter ( #2535 )
...
* fix: move Shodan discovery into adapter (#283 )
* docs: clarify Shodan transport and persistence
* fix: query every Shodan-resolved IPv4
* fix: call Shodan Host API directly
* fix: serve HarvestView assets locally
* Revert "fix: serve HarvestView assets locally"
This reverts commit 413e8b25ab .
* docs: clarify Shodan proxy transport
* docs: clarify Shodan changelog entry
* feat: persist structured Shodan host evidence
* feat: expand Shodan discovery with TLS search
2026-08-14 21:11:12 -04:00
Matt and GitHub
259455f1c1
fix: remove Windvane DNS guessing fallback ( #2541 )
2026-08-14 15:14:53 -04:00
Matt and GitHub
7c4420150d
Add route-aware no-host result filtering ( #2534 )
2026-08-13 11:14:55 -04:00
Matt and GitHub
624066a3e8
Add RouteViews enrichment and sourced ASN organization attribution ( #2528 )
...
* Add RouteViews network enrichment
* Add authenticated RouteViews API access
* Restrict RouteViews to explicit network pivots
* Restore discovered ASN RouteViews enrichment
* Retain sourced ASN organization attribution
* Avoid dangling and repeated ASN attributions
* Keep automatic RouteViews evidence target-relevant
* Complete target-relevant RouteViews enrichment
* Clarify automatic RouteViews IP pivots
2026-08-13 10:46:54 -04:00
Matt and GitHub
1db27309dd
Remove duplicate Chaos discovery source ( #2533 )
2026-08-12 18:47:34 -04:00
Matt and GitHub
aed50e0b0d
Add crt.name composite hostname discovery ( #2531 )
2026-08-12 17:05:12 -04:00
Matt and GitHub
4643f6f0f9
fix: use explicit provider and browser user agents ( #2530 )
2026-08-12 17:01:57 -04:00
Matt and GitHub
38524ab674
Add Sourcegraph hostname candidates from indexed code ( #2524 )
...
* feat: add bounded Sourcegraph discovery
Use the documented anonymous streaming API with explicit keyword, result, timeout, and line-match bounds; retain only scoped hostname and email evidence with truthful source outcomes.
* Harden Sourcegraph hostname discovery
* Raise Sourcegraph recall budget to 5000
* docs: clarify Sourcegraph candidate semantics
* test: account for combined source catalog
2026-08-12 12:14:02 -04:00
Matt and GitHub
91ed6c1d9f
Add APIs.guru hostname, email, and URL discovery ( #2525 )
...
* feat: add bounded APIs.guru discovery
* docs: clarify APIs.guru result boundaries
2026-08-12 12:06:04 -04:00
Matt and GitHub
f13280ddad
Add typed ASN-prefix routing evidence ( #2527 )
...
* Add typed network evidence foundation
* Deepen network evidence accumulation
* Bound network evidence accumulator limits
* Make nested JSON rejection test version tolerant
* Keep network evidence in unreleased schema v8
* Clarify structured result persistence dispatch
2026-08-12 10:49:16 -04:00
Matt and GitHub
ac3c543768
Add bounded provider response streaming ( #2526 )
...
* Add bounded provider response streaming
* Add bounded provider JSON fetching
2026-08-12 09:41:13 -04:00
Matt and GitHub
fa8afa5e46
Add bounded virtual-host discovery ( #2517 )
...
* Add bounded virtual-host discovery
* Document virtual host probe boundary
2026-08-11 00:43:04 -04:00
Matt and GitHub
0d2ab5a0b3
Add the HarvestView web application ( #2512 )
...
* feat: add HarvestView operator UI
* Use JSONL-only HarvestView file flows
* Drive HarvestView activities from the API catalog
* Add result action controls
* Render shared DNS resolver defaults
* Clarify resolver cardinality in HarvestView
* Load Tabulator from CDNjs
* Fix HarvestView wiki link
* Align HarvestView with execution status contract
* Add HarvestView import and action controls
* Harden HarvestView browser assertions
* Simplify HarvestView run selection
* Show truthful HarvestView execution outcomes
* refactor: show canonical URL results in HarvestView
* Show canonical hostname results in HarvestView
* test(harvestview): remove browser error race
2026-08-10 00:08:05 -04:00
Matt and GitHub
1fd5749e52
Add an authenticated durable run API v1 ( #2511 )
...
* Model active evidence in result persistence
* Expose active action diagnostics
* Persist truthful DNS action evidence
* Persist direct action evidence
* feat: add authenticated durable run API v1
* Make API file interchange JSONL-only
* Harden API evidence boundaries
* Remove API rate limiter
* Unify API runs with result persistence
* Support target action runs
* Keep DNS resolver selection action-neutral
* Add action-neutral CLI resolver selection
* Preserve API evidence across JSONL round trips
* Complete HarvestView API run parity
* Harden HarvestView run API contracts
* Remove obsolete bundled network snapshots
Delete the unused bundled AWS IP-range and resolver snapshots while preserving operator-supplied resolver file input.
* refactor: canonicalize URL results
* docs: define a bounded test budget
* Standardize hostname and IP result names
* fix(api): avoid duplicate evidence conflicts
2026-08-10 00:08:04 -04:00
Matt and GitHub
e4d37b05a8
Persist per-source run provenance ( #2516 )
...
* Persist per-source run provenance
* Keep the first JSONL contract unversioned
* Explain source yield counts
2026-08-09 11:50:08 -04:00
Matt and GitHub
c4af833da0
Use SQLAlchemy for async result persistence ( #2515 )
...
* Use SQLAlchemy for async result persistence
* Explain persistence ORM records
* Clarify persisted run schema
* Clarify legacy schema migration
* Consolidate result persistence
* Preserve incomplete legacy observations
2026-08-09 00:50:39 -04:00
Matt and GitHub
6b02dbddc9
Share safe enumeration execution across transports ( #2507 )
...
* feat: share safe enumeration execution across transports
* fix: clarify safe scan contracts
* fix: preserve public screenshot redirects
* fix: restore operator-controlled active requests
* fix: allow operator-selected API scan targets
2026-08-07 16:02:16 -04:00
Matt and GitHub
7a854eda95
Contract DeHashed and LeakIX evidence ( #2506 )
...
* Contract DeHashed evidence handling
* Align LeakIX with its documented API
* Update provider capability selection
* Require REST auth for DeHashed results
2026-08-07 00:25:54 -04:00
Matt and GitHub
30ac342d9d
Remove unavailable Venacus source ( #2505 )
2026-08-07 00:04:47 -04:00
Matt and GitHub
ce791dcaca
Contract Leak-Lookup evidence handling ( #2504 )
...
* Contract Leak-Lookup evidence
* Preserve additional API compatibility
2026-08-07 00:01:26 -04:00
Matt and GitHub
d42322031c
Expose bounded recursive DNS discovery in the CLI ( #2501 )
...
* Integrate recursive DNS with CLI persistence
* Expose bounded PTR evidence in recursive DNS output
* Document the CLI hard query default
* Clarify recursive DNS query accounting
* Preserve dual-stack recursive DNS output
* Preserve recursive DNS CLI lifecycle contracts
* Deduplicate exact XML host address pairs
2026-08-06 22:40:30 -04:00
Matt and GitHub
2398bfd15b
Add bounded recursive DNS discovery engine ( #2500 )
...
* Add bounded recursive DNS engine
* Retain bounded PTR evidence in recursive DNS
* Count actual recursive DNS queries
* Type recursive DNS resolver capabilities
* Bound recursive DNS candidate generation
* Reject unbounded recursive DNS runtimes
2026-08-06 22:35:14 -04:00
Matt and GitHub
7baaf62874
Add exact DNS query budgets and PTR lookups ( #2499 )
...
* Add exact PTR queries to DNS resolver vantages
* Enforce DNS query budgets across CNAME chains
* Harden DNS query budget contracts
2026-08-06 22:27:17 -04:00
Matt and GitHub
8d8bbdc060
Preserve POST semantics through proxies ( #2498 )
2026-08-06 21:32:02 -04:00
Matt and GitHub
9ff9115dcf
Migrate Pentest-Tools discovery to API v2 ( #2497 )
...
* Migrate Pentest-Tools discovery to API v2
* Send Pentest scan payload as JSON
2026-08-06 21:27:30 -04:00
Matt and GitHub
b6bd951c74
Add DNS consensus classification ( #2495 )
...
* Add DNS consensus classification
* Document DNS consensus behavior
2026-08-06 20:17:11 -04:00
Matt and GitHub
4f76b93513
Preserve direct DNS source result contracts ( #2494 )
...
* Harden explicit DNS direct source contracts
* Reject mismatched Shodan InternetDB evidence
* Preserve valid direct-source IP evidence
* Avoid ambiguous hostname output assertions
* Reference current Pentest-Tools scan documentation
2026-08-06 20:16:23 -04:00
Matt and GitHub
d60afe12e1
Retain GitLab evidence URLs ( #2492 )
2026-08-06 15:39:26 -04:00
Matt and GitHub
16c4866b49
fix: drive all from passive source catalog ( #2489 )
2026-08-06 14:47:33 -04:00
Matt and GitHub
a7f883e45c
feat: add HIBP verified-domain source ( #2488 )
2026-08-06 14:47:33 -04:00
NotoriousRebel
35b368b705
fix: retain HIBP breach names in completed results
2026-08-05 23:02:36 -04:00
NotoriousRebel
e063c42a08
fix: remove invalid Bitbucket domain source ( #100 )
2026-08-05 21:45:08 -04:00
NotoriousRebel
7af23e4382
fix: remove nonfunctional ThreatCrowd source ( #98 )
2026-08-05 20:48:35 -04:00
NotoriousRebel
66e1beee7c
feat: preserve shared HTTP response metadata
2026-08-05 18:31:36 -04:00
NotoriousRebel
8d3876724e
fix: preserve generic people in completed results
2026-08-05 16:25:27 -04:00
NotoriousRebel
48d5df237d
feat: persist completed results
...
Store and load CompletedResult values transactionally without changing legacy rows or public output contracts.
2026-08-05 12:06:15 -04:00
Matt and GitHub
8d5a7cceea
Merge pull request #2461 from NotoriousRebel/codex/upstream-dev-completed-jsonl
...
feat: completed-result JSONL reports
2026-08-05 11:14:46 -04:00
NotoriousRebel
708405c882
feat: add completed-result JSONL reports
2026-08-05 01:59:08 -04:00
NotoriousRebel
24b36ba590
fix: retain typed DNS evidence
2026-08-05 01:29:18 -04:00
NotoriousRebel
59311ef7cc
test: isolate configuration copy logging
2026-08-04 19:54:57 -04:00
NotoriousRebel
fda00aeda3
fix: separate RapidDNS host and IP evidence
2026-08-04 19:34:32 -04:00
NotoriousRebel
c56c20a57d
refactor: model subdomain result routes explicitly
2026-08-01 13:33:54 -04:00
NotoriousRebel
3bc9cfb296
refactor: derive source capabilities from result routes
2026-07-30 19:47:52 -04:00
NotoriousRebel
4a69697451
feat: select sources by result capability
2026-07-30 19:47:51 -04:00
NotoriousRebel
77d7e46032
fix: preserve Brave credential accessor
2026-07-28 20:13:42 -04:00