# BigBrother Scope Enforcement # Optional. When enabled, all passive/active modules respect these boundaries. # Prevents accidental out-of-scope activity during engagements. enabled: false # In-scope target networks (CIDR notation) networks: [] # - 10.10.0.0/16 # - 10.0.0.0/24 # In-scope individual hosts (IP or FQDN) hosts: [] # - dc01.corp.local # - 10.10.1.50 # In-scope domains (wildcard matching) domains: [] # - corp.local # - internal.example.com # Excluded networks — always out of scope (overrides networks/hosts above) exclude_networks: [] # - 10.10.99.0/24 # OT segment # Excluded hosts — always out of scope exclude_hosts: [] # - 10.10.1.1 # Production gateway