Add README, PolyForm NC license, and harden .gitignore for public release

This commit is contained in:
n0mad1k
2026-07-08 10:23:58 -04:00
parent 98dc356645
commit 5b6c5c92eb
3 changed files with 173 additions and 0 deletions
+17
View File
@@ -8,3 +8,20 @@ __pycache__/
.venv/ .venv/
*.pyc *.pyc
.claude/ .claude/
# Internal dev files — never publish
CLAUDE.md
notes.md
# Local corpora / downloaded books — never publish (large, third-party)
Hacking-Books/
Hacking-PDF-Books/
Hacking-Security-Ebooks/
hacking-books/
# Per-project workflow gate dotfiles (do not commit)
.active-item.json
.closeout-required.json
.workflow-approved
.workflow-bypass
.workflow-state.json
+73
View File
@@ -0,0 +1,73 @@
# PolyForm Noncommercial License 1.0.0
<https://polyformproject.org/licenses/noncommercial/1.0.0>
## Acceptance
In order to get any license under these terms, you must agree to them as both strict obligations and conditions to all your licenses.
## Copyright License
The licensor grants you a copyright license for the software to do everything you might do with the software that would otherwise infringe the licensor's copyright in it for any permitted purpose. However, you may only distribute the software according to [Distribution License](#distribution-license) and make changes or new works based on the software according to [Changes and New Works License](#changes-and-new-works-license).
## Distribution License
The licensor grants you an additional copyright license to distribute copies of the software. Your license to distribute covers distributing the software with changes and new works permitted by [Changes and New Works License](#changes-and-new-works-license).
## Notices
You must ensure that anyone who gets a copy of any part of the software from you also gets a copy of these terms or the URL for them above, as well as copies of any plain-text lines beginning with `Required Notice:` that the licensor provided with the software. For example:
> Required Notice: Copyright Yoyodyne, Inc. (http://example.com)
## Changes and New Works License
The licensor grants you an additional copyright license to make changes and new works based on the software for any permitted purpose.
## Patent License
The licensor grants you a patent license for the software that covers patent claims the licensor can license, or becomes able to license, that you would infringe by using the software.
## Noncommercial Purposes
Any noncommercial purpose is a permitted purpose.
## Personal Uses
Personal use for research, experiment, and testing for the benefit of public knowledge, personal study, private entertainment, hobby projects, amateur pursuits, or religious observance, without any anticipated commercial application, is use for a permitted purpose.
## Noncommercial Organizations
Use by any charitable organization, educational institution, public research organization, public safety or health organization, environmental protection organization, or government institution is use for a permitted purpose regardless of the source of funding or obligations resulting from the funding.
## Fair Use
You may have "fair use" rights for the software under the law. These terms do not limit them.
## No Other Rights
These terms do not allow you to sublicense or transfer any of your licenses to anyone else, or prevent the licensor from granting licenses to anyone else. These terms do not imply any other licenses.
## Patent Defense
If you make any written claim that the software infringes or contributes to infringement of any patent, your patent license for the software granted under these terms ends immediately. If your company makes such a claim, your patent license ends immediately for work on behalf of your company.
## Violations
The first time you are notified in writing that you have violated any of these terms, or done anything with the software not covered by your licenses, your licenses can nonetheless continue if you come into full compliance with these terms, and take practical steps to correct past violations, within 32 days of receiving notice. Otherwise, all your licenses end immediately.
## No Liability
***As far as the law allows, the software comes as is, without any warranty or condition, and the licensor will not be liable to you for any damages arising out of these terms or the use or nature of the software, under any kind of legal claim.***
## Definitions
The **licensor** is the individual or entity offering these terms, and the **software** is the software the licensor makes available under these terms.
**You** refers to the individual or entity agreeing to these terms.
**Your company** is any legal entity, sole proprietorship, or other kind of organization that you work for, plus all organizations that have control over, are under the control of, or are under common control with that organization. **Control** means ownership of substantially all the assets of an entity, or the power to direct its management and policies by vote, contract, or otherwise. Control can be direct or indirect.
**Your licenses** are all the licenses granted to you for the software under these terms.
**Use** means anything you do with the software requiring one of your licenses.
+83
View File
@@ -0,0 +1,83 @@
# mosaic
Intelligence extraction platform for large open-source and declassified document corpora.
Mosaic collects public leak/disclosure archives (WikiLeaks, Cryptome, FAS/IRP, CIA CREST/RDP,
Army field manuals, and similar), parses heterogeneous documents, extracts structured
intelligence (entities, tooling, TTPs, infrastructure, tradecraft), and lets you query and
synthesize the results — all locally, in SQLite.
> Everything Mosaic ingests is publicly available or previously declassified material.
> It ships with no corpus and no data — you point it at the sources you are authorized to use.
## Pipeline
```
collect → parse → extract → analyze → query
```
- **collect** — source-profile-driven crawlers (rate-limited, resumable) into a hash-sharded store
- **parse** — subprocess-isolated PDF / HTML / email / cable / text parsers with memory + time caps
- **extract** — Claude-backed extractors: entities, tools, MITRE ATT&CK mapping, infrastructure,
surveillance, tradecraft, TTPs
- **analyze** — BM25/FTS5 context builder, batch + interactive analysis, field-manual generation
- **query** — full-text search (SQLite FTS5) over everything extracted
## Install
```bash
git clone https://git.churchofmalware.org/n0mad1k/mosaic.git
cd mosaic
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
```
## Configure
Copy the example config and set your options:
```bash
cp config/mosaic.conf.example config/mosaic.conf # if present; otherwise mosaic writes defaults
```
The Anthropic API key is read from the `ANTHROPIC_API_KEY` environment variable (preferred):
```bash
export ANTHROPIC_API_KEY=sk-ant-...
```
A commented `api_key` fallback exists in `config/mosaic.conf`, but the env var takes priority and
is the recommended path. No key is required for `collect`, `parse`, or `query` — only for the
Claude-backed `extract`/`analyze` stages.
## Usage
```bash
python3 mosaic.py # interactive Rich menu
python3 mosaic.py --help # full CLI
# typical flow
python3 mosaic.py collect --profile collectors/profiles/cryptome.yaml
python3 mosaic.py parse
python3 mosaic.py extract --dry-run # estimate token cost first
python3 mosaic.py extract
python3 mosaic.py query "kerberos delegation"
```
Source profiles live in `collectors/profiles/`. Copy `example.yaml` to add your own.
## Field manuals
`output/manuals/` contains reference manuals synthesized from public and declassified source
material (HUMINT, surveillance/counter-surveillance, covert communications, physical access,
cover & identity, OPSEC, and cyber implants). They are generated artifacts produced by the
`analyze` stage and are included as worked examples.
## Tests
```bash
pytest tests/
```
## License
PolyForm Noncommercial 1.0.0 — see [LICENSE](LICENSE). Commercial licensing on request.