# Windows mining phases
Operator reference for the **Windows agent lifecycle**: what runs automatically, in what order, and what requires deck action. Source of truth: `agent/client/`, `agent/miner/`, `agent/deploy/`, `server/internal/miningsurgery/`.
Related: [LOTL triple onion (README)](../README.md#lotl-triple-onion-architecture) · [Spread playbook](/docs/SPREAD_TECHNIQUES.html) · [LOTL glossary](../tests/README.md#lotl-vector-glossary) · [PROBLEMS.md](../PROBLEMS.md)
## Legend
| Symbol | Meaning |
|--------|---------|
| **AUTO** | Agent runs without operator action (may still need forge flags or Calibrate policy) |
| **OP** | Operator triggers from Forge, Crucible, Calibrate, or Emberwake export |
| **GATE** | Automatic check that can defer or skip a phase |
---
## Main flowchart — phases on Windows (in order)
```mermaid
flowchart TB
subgraph boot["0 · Agent boot — AUTO"]
start[Run: pool + miningChain runner]
role{Seeder role?}
defer{WantsDeferMining?}
waitDiag[startMiningWhenReady
C2 + diagnostics ≤120s]
onionStart[miningChain.Start]
start --> role
role -->|yes| seeder[StartSeederStaging only
no mining]
role -->|no| defer
defer -->|spread/GPO/Intune install| waitDiag
defer -->|normal forge| onionStart
waitDiag --> onionStart
end
subgraph recon["1 · Recon phase — AUTO"]
kev[kev_scan]
vr[vuln_recon]
sp[service_probe]
lp[listen_ports]
kev --> vr --> sp --> lp
end
subgraph gates["2 · Policy gates — GATE"]
pf{patch_first +
critical CVE?}
hr{skip_mining_on_high_risk?}
iso{mine_isolated_tier?}
pf -->|yes| skipBoth[Skip deploy + mining]
pf -->|no| hr
hr -->|risk ≥ threshold| skipMine[Skip mining only]
hr -->|ok| deployGo[Continue deploy]
iso -.->|prefer container/WSL| miningIso[Isolated tier order]
end
subgraph deploy["3 · Deploy lanes — AUTO, first OK wins"]
dj[discover_and_join]
d1[docker]
d2[wsl]
d3[powershell]
d4[dotnet]
d5[bits_curl]
d6[do_peer / wsus_cache_peer]
d7[dns_txt / webrtc_mesh]
d8[smb]
d9[winrm]
dj --> d1 --> d2 --> d3 --> d4 --> d5 --> d6 --> d7 --> d8 --> d9
end
subgraph mining["4 · Mining runtime — AUTO"]
probes[webview2_probe]
tierChain[LOTL tier TryChain
docker_load → container → wsl →
ps_inmemory → dotnet → cpu_inprocess]
fallback[Fallback chain TryChain
+ GPU parallel + stratum_direct]
winTiers[Windows tiers
wmi · scheduled_task · gpu_compute]
monitor[Chain monitor
30s cooldown re-pass]
probes --> tierChain --> fallback --> winTiers --> monitor
end
subgraph postAuth["5 · Post-auth spread — AUTO after WS auth"]
authOK[Fleet secret accepted]
ebb{Earn-before-burn gate
stable H/s + chain OK?}
smb[SMB/SCM autospread /24]
wrm[WinRM encoded bootstrap]
lotlBg[LOTL onion background chain
2 min stagger]
authOK --> ebb
ebb -->|no| deferSpread[Defer SMB/WinRM]
ebb -->|yes| smb
smb --> wrm
authOK --> lotlBg
end
subgraph recover["6 · Recovery layers"]
surgery["Mining self-surgery — AUTO
when Fleet AI Control on"]
contingency["Contingency tree — AUTO
when contingency policy on"]
opSpread["spread_now / stage_fetch / templates — OP"]
surgery --> contingency
end
onionStart --> recon
recon --> pf
deployGo --> deploy
skipMine --> deploy
deploy -->|all fail or one OK| mining
skipBoth --> endNode([Idle / telemetry only])
mining --> postAuth
monitor -->|interrupt / low H/s| surgery
monitor -->|chain exhausted| contingency
deferSpread -.->|operator spread_now| opSpread
```
### Phase summary
| # | Phase | Trigger | Stops when |
|---|-------|---------|------------|
| 0 | Boot + diagnostics | AUTO on process start | Seeder role, `mining_disabled`, or diagnostics timeout |
| 1 | Recon | AUTO inside triple onion | All recon tiers attempted |
| 2 | Policy gates | AUTO from recon + Calibrate `triple_onion_policy` | `patch_first` or high-risk skip |
| 3 | Deploy lanes | AUTO, sequential | First lane succeeds, or all fail → still enters mining |
| 4 | Mining runtime | AUTO after deploy (or gate bypass) | Active tier + monitor loop |
| 5 | Post-auth spread | AUTO after first WS auth | Earn-before-burn gate, subnet immune pause, or sweep cap |
| 6 | Recovery | AUTO (AI Control / contingency) or OP (Crucible) | Plan applied or hospice |
---
## Spread / deploy lanes vs mining runtime
Deploy lanes **stage or lateral-install** workers; mining runtime **hashes on the current host**. They share tier names but serve different goals.
```mermaid
flowchart LR
subgraph triple["Triple onion deploy — AUTO at connect"]
direction TB
T1[discover_and_join]
T2[docker · wsl · powershell · dotnet]
T3[bits_curl · peer caches · dns_txt · webrtc]
T4[smb · winrm]
T1 --> T2 --> T3 --> T4
end
subgraph parallel["Parallel spread — AUTO post-auth"]
direction TB
A1[Autospread timer
10 min then /4h]
A2[SMB UNC + sc.exe /24]
A3[WinRM PS1 bootstrap
when winrm_spread]
A4[LOTL onion goroutine
forge tier order]
A1 --> A2 --> A3
A4
end
subgraph runtime["Mining runtime — AUTO same host"]
direction TB
M1[Environment probes + AV skip]
M2[Primary: docker_load → container → wsl → inprocess]
M3[Parallel GPU subprocess / gpu_compute]
M4[Stratum overlay if C2 jobless 30s]
M1 --> M2 --> M3 --> M4
end
subgraph op["Operator lanes — OP"]
direction TB
O1[Crucible spread_now]
O2[WinRM / SMB / GPO templates]
O3[stage_fetch manifest]
O4[Court spread_retry_lane]
end
triple -->|success = join_lane only| runtime
parallel -->|earn-before-burn GATE| parallel
op --> parallel
runtime -->|hashrate_gate telemetry| parallel
```
### Lane cheat sheet (Windows-focused)
| Lane | Deploy / spread | Mining runtime equivalent |
|------|-----------------|---------------------------|
| `powershell` | `irm install.ps1 \| iex` bootstrap | `ps_inmemory` tier |
| `dotnet` | `dotnet tool run` staging | `dotnet` tier |
| `bits_curl` | BITS/curl + certutil decode | Staging only (Crucible `stage_fetch`) |
| `smb` | UNC copy + remote `sc.exe` | Autospread `/24` sweep |
| `winrm` | PS remoting 5985/5986 | Autospread + spread templates |
| `docker` / `wsl` | Container/WSL join | `docker_load` / `container` / `wsl` tiers |
---
## Earn-before-burn
**AUTO gate** — Calibrate `server.hashrate_gate_spread_min` + `server.hashrate_gate_hps` push `spread_policy` on auth.
1. Agent mines until hashrate stays above threshold for N minutes.
2. Mining chain must not be exhausted.
3. Only then: SMB/WinRM autospread sweeps and `RunSpreadOnce` proceed.
Triple-onion deploy lanes and LOTL background onion are **not** blocked by this gate (spread-only vs burn-first policy).
---
## Mining self-surgery
**AUTO when Fleet AI Control enabled** — server observes `stats_batch`, queues `mining_self_surgery` on next auth/policy push.
| Trigger | Actions |
|---------|---------|
| `mining_interrupt` | Container restart, fallback reorder, GPU swap, RandomX restart |
| `low_hashrate` | Idle threshold tune, method-specific restart |
Contingency branch `self_surgery` on-agent applies skip/force method params from server court/AI.
---
## Contingency miner tree
**AUTO when `contingency_policy.enabled`** — default branch order:
`inprocess` → `container` → `gpu_subprocess` → `idle_tune` → `self_surgery`
Server `ContingencyOrchestrator` (Fleet AI Control) observes `onion_miner_log` hops and may push `contingency_branch_params` (persona, reorder, skip_methods). Policy snapshot hospice list can retire strains.
---
## Policy inputs (Calibrate → agent)
| Policy JSON | Affects |
|-------------|---------|
| `triple_onion_policy` | Recon order, deploy lanes, patch_first, high-risk skip |
| `mining_tier_policy` | Mining tier order / skip / force |
| `spread_policy` | Autospread, WinRM, hashrate gate, subnet recon |
| `contingency_policy` | Contingency tree + personas |
| Policy snapshot URL | Hospice strains, vaccination lane hints |
---
## Honest limits (Windows)
From [`PROBLEMS.md`](../PROBLEMS.md) — not bugs; operator scope:
- **AV** — Containers are not invisible; Defender still sees `docker.exe`, image pulls, and filesystem scans. In-process RandomX avoids a standalone CPU miner exe but is not undetectable.
- **GPU in container** — Windows Docker Desktop GPU passthrough is operator-dependent; host subprocess GPU remains the fallback.
- **Spread lanes** — Full WinRM/GPO/BITS paths are Windows-focused; live P2 spread (real WinRM/GPO on remote hosts) is **manual / live operator** work, not fully automated in CI.
- **Process hollowing** — Relocation done; Defender/ETW bypass ~50% failure rate (`hollow_windows.go`).
- **Contingency LLM** — Live court LLM on every exhaust tick is not automated; CI uses deterministic persona branches.
- **Policy snapshot / AWS lanes** — S3, SSM, Fargate, EventBridge fan-out require operator IAM and deployment in your account.
- **Subnet scale** — Per-agent scan capped at 128 hosts; spread concurrency sem=16; fleet discovery is incremental not full /16.