d3da6ea89cbc8f6f7993b74103427fce0e2e35f1
Phone (c6:37:b0:b2:07:30) was cycling through arrivals/departures faster than the 30-min churn window threshold, causing _check_churn to add its IP to infrastructure_ips. All subsequent on_arrival calls were silently dropped by the infrastructure IP check, so no ARRIVED alerts fired. Two fixes: - _check_churn: skip churn suppression entirely for MACs in device_labels or personal_devices — labeled devices are never infrastructure - on_arrival already-known path: upgrade ip from '0.0.0.0'/'unknown' (ARP probe placeholder) to real IP when netlink delivers the actual address
Description
Network drop implant — passive SOC + active exploitation. Deploy on any Debian host.
Languages
Python
89.2%
Shell
8.5%
HTML
1.1%
C
0.9%
Jinja
0.3%