redacted results

Evidence

The artifacts below are sanitized excerpts shaped from working project output. They are here to show what the platforms produce without publishing targets, credentials, client data, infrastructure, or raw evidence.

view project

Pipeline run summary

redacted aggregate

End-to-end Juice Shop validation — scout agents, deterministic probes, and heavy-model exploitation with zero cloud calls.

sanitized-output
target: local lab (OWASP Juice Shop)
scout_model: LFM2.5-230M via Ollama
heavy_model: Ornith-1.0-35B (local endpoint)
stages_completed: passive_recon, web_recon, web_analysis, service_analysis, exploiter, persistence
findings_persisted: findings.json + logs/downloads/
cloud_calls: 0
raw_flags_published: false

Case trace excerpt

redacted trace

Luciv3 scope gate, skill routing, and append-only case artifacts — evidence that survives between pipeline stages and operator sessions.

sanitized-output
scope.init: demo — basis lab_only, mode lab_only
scope.approve: unrestricted_lab — operator-owned container
router.hint: "JWT verification weaknesses"
  primary: web-api-security
  confidence: 0.91
web_analysis.judge:
  priority: high
  type: auth_bypass
  path: /api/Users (401)
trace.append: evidence + finding + report under work/demo/
view project

Agent registration and system info

redacted agent log

A linux-x86_64 agent connects over WSS and answers GetSystemInfo on first command.

sanitized-output
[INF] Agent starting, registered 9 command handlers
[INF] Connection attempt #1 to https://relay.[REDACTED].workers.dev/agent
[INF] WebSocket connection established (attempt #1)
[INF] Message #1 received: command=GetSystemInfo (0x00), payload_length=0, ws_opcode=2
[INF] Handling GetSystemInfoCommand.
[INF] GetSystemInfo: hostname=[REDACTED], arch=x86_64, agent_platform=linux,
      os_version=Linux [REDACTED], build=318, commit=[REDACTED]
[INF] Command GetSystemInfo completed: status=0, response_length=481
[INF] Response sent successfully for command GetSystemInfo (481 bytes)

Remote shell session

redacted agent log

Interactive shell over the binary WebSocket protocol — write then read, no local path or command text published.

sanitized-output
[INF] Message #2 received: command=WriteShell (0x04), payload_length=8, ws_opcode=2
[INF] Handling WriteShellCommand.
[INF] Command written to shell successfully, bytes written: 7
[INF] Command WriteShell completed: status=0, response_length=4
[INF] Response sent successfully for command WriteShell (4 bytes)
[INF] Message #3 received: command=ReadShell (0x05), payload_length=0, ws_opcode=2
[INF] Handling ReadShellCommand.
[INF] Command ReadShell completed: status=0, response_length=57
[INF] Response sent successfully for command ReadShell (57 bytes)
view project

Advisory record

public CVE

The public record ties the issue to Qualcomm WLAN host and firmware behavior.

sanitized-output
cve: CVE-2023-33105
vendor: Qualcomm
class: transient denial-of-service
area: WLAN host and firmware
cvss_v3_1: 7.5 HIGH
vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
publication: Qualcomm March 2024 bulletin / NVD

Research artifact

public research artifact

Early Python proof-of-concept kept available for lab validation and traceability.

sanitized-output
language: Python
dependencies: scapy, termcolor, wireless injection tooling
scope: authorized lab validation only
target_data: not included
operational_status: archived public research

Redacted scan row

sanitized CSV

Representative scanner output from a public test target with volatile identifiers shortened.

sanitized-output
ts,ip,port,service,version,cves,risk,asn,egress
2026-06-02T10:48:37Z,45.33.32.[x],22,ssh,OpenSSH_6.6,23,low,AS63949,vpn-radar/us-west
2026-06-02T10:48:37Z,45.33.32.[x],80,http,Apache/2.4.7,0,medium,AS63949,vpn-radar/us-west

Pipeline completion event

redacted MQTT

Discovery, scanner, and writer events are correlated by scan id before landing in Postgres.

sanitized-output
topic: radar-x/scan/[scan-id]/complete
message:
  discovery_node: dk-us-west-[REDACTED]
  scanner_node: ds-us-west-[REDACTED]
  services: 5
  cves: 23
  duration_seconds: 38
  postgres_batch: writer-[REDACTED]
  checksum: sha256:2a7b...[REDACTED]

Redacted mobile collection export

redacted case bundle

A scoped Android assessment export with personal fields removed and integrity preserved.

sanitized-output
case_id: OPS-MOB-[REDACTED]
device: Pixel 7 / Android 14 / stock / non-root
approved_modules:
  - device_info
  - get_notifications.metadata_only
  - get_clipboard
  - get_sms.metadata_only
  - take_screenshot.operator_confirmed
collected:
  sessions: 1
  notifications: 184
  clipboard_events: 19
  sms_metadata_rows: 73
  screenshots: 3
export_sha256: 9f4c1b7e8a2d0c5f...[REDACTED]

Operator audit trail

redacted log excerpt

Sensitive actions are operator-confirmed and written to the server-side audit trail.

sanitized-output
2026-06-18T14:22:11Z operator=[REDACTED] module=device_info status=ok
2026-06-18T14:24:03Z operator=[REDACTED] module=get_notifications scope=metadata status=ok
2026-06-18T14:31:44Z operator=[REDACTED] module=take_screenshot confirm=true status=ok
2026-06-18T14:44:02Z operator=[REDACTED] action=export_evidence bundle=case-[REDACTED].zip

Forensic scan summary

redacted executive output

A redacted summary shaped from the v3 pipeline output and QA numbers.

sanitized-output
scan_id: MAM-[REDACTED]
files_processed: 1,278
pipeline_stages: 12
local_models_loaded: 14
entities_extracted: 4,912
identity_clusters:
  face: 37
  voice: 12
  cross_script_name: 18
cloud_apis_used: 0

QA matrix

redacted test run

Evidence-type tests validate audio, vision, document, and entity processing before a scan is trusted.

sanitized-output
mammon test --profile v3
audio multilingual: 19/20 pass
image vision/OCR/faces: 12/12 pass
document PDF/OCR/entities: 7/7 pass
hybrid search: pass
identity graph: pass
export manifest: pending court-packaging
view project

Credential campaign QA

redacted campaign flow

The QA path validates delivery, landing behavior, audit state, and live operator updates.

sanitized-output
campaign: PX-QA-[REDACTED]
mode: email + credential landing
preflight:
  spam_score: pass
  dns_auth: pass
  file_host: not_required
events:
  email_sent: ok
  click_tracked: ok
  credential_submit: ok
  audit_row: ok
  sse_update: ok

Host registration state

redacted dashboard

Campaign infrastructure is modeled as registered operator-owned hosts, not vendor services.

sanitized-output
admin      https://admin.[REDACTED]      healthy
landing    https://login.[REDACTED]      listener online / drain connected
files      https://dl.[REDACTED]         caddy online
smtp       smtp.[REDACTED]:587           dkim aligned / relay ready
telemetry  third_party                   disabled

DNS posture snapshot

redacted JSON

Wraith's read-only DNS recon captures MX, SPF, DMARC, and related records as structured evidence before any delivery attempt.

sanitized-output
domain: client-[REDACTED].com
mx:
  - priority: 10
    host: aspmx.l.google.com
spf: "v=spf1 include:_spf.google.com ~all"
dmarc: absent
ns: [cloudflare, cloudflare]
saved: ~/.wraith/evidence/dns_client_[REDACTED]_com.json

Console launch manifest

redacted dry-run record

The assessment console defaults to dry-run. Live delivery requires operator review and explicit confirmation.

sanitized-output
campaign: authorized-poc-[REDACTED]
mode: dry_run
from: security-test@client-[REDACTED].com
to: approved-recipient@client-[REDACTED].com
mx_target: aspmx.l.google.com
hunter_senders: 3
auth_notice: appended
evidence_dir: ~/.wraith/evidence/[REDACTED]/

Forensic report excerpt

generated report

The report excerpt uses sanitized case metadata from the report-generation path.

sanitized-output
REPORT ID: b8f6fdbb-[REDACTED]
CASE: CASE-2024-[REDACTED]
DEVICE: Samsung Galaxy S21 Ultra / Android 12 / encrypted
TOTAL ITEMS: 46
CATEGORIES:
  contacts: 2
  photos_media: 3
  wifi_networks: 38
  bluetooth_devices: 3
formats: pdf, html, markdown, json, csv

Integrity block

redacted hashes

Extraction and report hashes are generated so exports can be verified after handoff.

sanitized-output
extraction_sha256: 3656c197922701cf7d43...[REDACTED]
report_sha256:     8d2a5a550a0f3599a42...[REDACTED]
chain_of_custody:
  acquisition_ts: 2026-02-25T12:13:03Z
  examiner: [REDACTED]
  tool: ARCHON Forensics v0.1.0

Zeek alert excerpt

redacted JSON

Alerts point to the exact pcap and replay filter without publishing packet contents.

sanitized-output
{
  "event": "alert",
  "router": "router-[REDACTED]",
  "iface": "br0",
  "note": "RCAPNG::PlaintextHTTPLogin",
  "src": "10.0.0.[x]",
  "dst": "10.0.0.[y]",
  "pcap": "/captures/router-[REDACTED]/20260514-br0-[id].pcap",
  "replay": "tcpdump -nn -tttt -A -r [pcap] 'host 10.0.0.x and host 10.0.0.y and port 80'"
}

Collector status snapshot

redacted ops view

The collector exposes enough state for operators without requiring shell access to the box.

sanitized-output
active_sessions: 3
sessions_accepted_total: 118
bytes_written_total: 42.8GB
rotations_total: 31
zeek_pipe: enabled
metrics: /metrics
retention_days: 7
view project

Execution flow

redacted run log

The script backs up security settings, disables Defender services and policies, and uses a safe-mode reboot when Tamper Protection blocks in-session changes.

sanitized-output
version: 1.8.6
phase: initial_setup
backup_dir: FuckWinDefend Backup\[REDACTED]
registry_backup: MySecurityDefaults.reg
restore_point: created
phase: disable_services
targets:
  - WinDefend
  - SecurityHealthService
  - wscsvc
phase: policy
Set-MpPreference: applied
SmartScreen: disabled
phase: safe_mode_reboot
bcdedit: copy {current} -> Safe Mode
reboot_count: 2
status: in_progress

Persistence hook

redacted state

Registry markers and scheduled recovery survive reboot so Defender stays disabled across the lab window.

sanitized-output
script_key: HKLM\Software\FuckWinDefendScript
random_name: [REDACTED]
boot_cleanup: scheduled
gpupdate: forced
SecurityHealth: removed from startup
cloud_protection: disabled
realtime_protection: disabled
tamper_protection: bypassed (safe mode path)
view project

Origin candidate table

redacted report excerpt

Candidates are graded by confidence and source so weak Shodan correlations do not read the same as a TLS-cert match.

sanitized-output
target: client-[REDACTED].com
apex_https: 200 · server: cloudflare · cdn: cloudflare
candidates:
  - ip: 203.0.113.[x]
    confidence: high
    source: tls_san_match + body_hash
    notes: direct-IP HTTPS 200 with matching cert SAN
  - ip: 198.51.100.[y]
    confidence: medium
    source: urlscan.io passive DNS
    notes: HTTP responsive; verify manually
  - ip: 192.0.2.[z]
    confidence: low
    source: shodan:favicon
    notes: shared asset correlation — investigate manually

Rescan diff

redacted regression

JSON output supports `diff` between scans so grey-cloud regressions and new origin exposure show up as structured deltas.

sanitized-output
diff: reports/2026-06-[REDACTED].json → reports/2026-07-[REDACTED].json
new_origin_ips: [203.0.113.[x]]
removed_from_edge: []
confidence_upgrades: 1
grey_cloud_regressions: 0
sarif_findings_high: 1

WiFi sighting envelope

redacted MQTT payload

Nodes emit schema-versioned metadata only — no packet payloads, no decoded content.

sanitized-output
schema_v: "0.1"
ts: 2026-07-27T09:14:22Z
node_id: wifi-mote-office-[REDACTED]
tech: wifi
location: office-west
mac: aa:bb:cc:dd:ee:[xx]
ssid_probed: HomeNetwork-[REDACTED]
channel: 6
rssi: -67
ie_hash: 8f3a...[REDACTED]

Recurrence alert

redacted core output

The core fuses sightings into stable device identity and flags devices that reappear across time or locations.

sanitized-output
alert_id: ARG-[REDACTED]
device_id: dev-7c2f...[REDACTED]
signature: ie_hash + probed_ssid_set + timing
first_seen: 2026-07-20T08:02:11Z
sightings: 14
locations: [office-west, commute-route-[REDACTED]]
anomaly: recurring_unknown_device
mac_observed: [aa:bb:cc:dd:ee:xx, 02:11:22:33:44:yy]