n0mad1k
|
d3d1deb99c
|
v3.1: Incorporate security tribe review findings into design doc
Add 7 new modules: ldap_harvester, rdp_monitor, quic_analyzer,
db_interceptor (passive), change_detector, security_posture,
operator_audit (intel). Add capture_bus for single AF_PACKET
demux to per-module queues (multiprocess architecture). Fix Pi
Zero memory budget (70MB interpreter, 4 passive modules max).
Move sensitive config inside LUKS with network-derived boot key.
Require 128GB SD card with zstd PCAP compression. Add coercion
tools (Coercer, PetitPotam), proxychains-ng, socat, sshuttle,
pypykatz, ldapdomaindump, smbmap, ROADtools. Add thermal
monitoring, SQLite contention fix (single DB + async writer),
bridge STP/CDP suppression, DHCP fingerprinting, wireless
interface conflict detection, optional scope.yaml, DoH/ECH
awareness, triage CLI command. Update implementation phases
and hardware tier matrix.
|
2026-03-17 10:57:51 -04:00 |
|
n0mad1k
|
7915ef17de
|
Add consolidated security review from 6-agent tribe analysis
91 raw findings from Security, OPSEC, Blue Team, APT, Red Team, and
Infra/Reliability analysts consolidated to 45 actionable items across
7 sections: new modules (9), design changes (10), infra fixes (6),
tool gaps (5), OPSEC warnings (10), and accepted limitations (7).
Key themes: LDAP/RDP monitoring gaps, PCAP storage crisis, data exfil
pipeline needed, ARP/Responder detection risk, Pi Zero memory budget
exceeded, multiprocess architecture required, config files outside LUKS.
|
2026-03-17 10:28:42 -04:00 |
|
n0mad1k
|
f959ef89cd
|
Rewrite design doc v3.0: surveillance platform + operator jump box
Complete rewrite of BIGBROTHER_DESIGN.md with new design philosophy:
- Removed autonomous decision engine, state machine, hard scope enforcement
- Removed lateral movement automation, tool wrappers, attack chain recipes
- Removed push notifications, automated attack chaining, OT lockout
- Added 8 new passive surveillance modules: DNS logger, TLS SNI extractor,
network relationship mapper, auth flow tracker, SMB file access monitor,
VoIP/SIP metadata capture, print job interception, email sniffer
- Added 4 new active modules: HTTP transaction logger, file extractor,
JS/HTML injection, mitmproxy integration
- Added per-user activity timeline intelligence module
- Pre-installed tools section (nmap, Certipy, Impacket, BloodHound,
CrackMapExec, Chisel, Ligolo-ng, etc.) - installed not wrapped
- Simplified to 5 implementation phases from 10
- Operator makes all decisions, no autonomous behavior
|
2026-03-17 10:04:14 -04:00 |
|
n0mad1k
|
45dc317c31
|
Add consolidated BigBrother design document post-tribe review
Comprehensive network implant architecture incorporating findings from
6-agent security review tribe. Key additions: 802.1X NAC bypass,
AD attack suite (Kerberoast/ADCS/coercion), autonomous decision engine,
multi-protocol C2 chain, traffic mimicry, hardware tier enforcement,
mandatory scope enforcement, OT/SCADA passive lockout, 5 attack chain
recipes, detection risk matrix, and reliability safeguards.
|
2026-03-17 07:39:01 -04:00 |
|