d1e89bddf5c6abd82638e7c3d8a0ca4e0d0a7fa0
- Option A: OUI-based auto-exclusion for network equipment (Ubiquiti, Cisco, Aruba, TP-Link, Netgear, MikroTik, Ruckus) - Option B: Churn-based suppression (cycles 3+ times in 30min auto-suppresses device) - Option C: Verify NET_ALERTER_INFRA_IPS env var is documented and functional Implementation: - Added NETWORK_EQUIPMENT_OUIS set with 45 common network equipment OUI prefixes - Added _check_churn() function to track departure events within 30min window - Integrated OUI check into on_arrival() and seed_infrastructure_ips() - Integrated churn check into on_departure() before timer start - Enhanced seed_infrastructure_ips() docstring to document all 5 seeding steps - Removed interactive BB_ALERTER_INFRA_IPS prompt from operator_setup.sh (post-deploy config only)
Description
Network drop implant — passive SOC + active exploitation. Deploy on any Debian host.
Languages
Python
89.2%
Shell
8.5%
HTML
1.1%
C
0.9%
Jinja
0.3%