attack plan: v2.4.0 feature push tracker
This commit is contained in:
36
ATTACK-PLAN.md
Normal file
36
ATTACK-PLAN.md
Normal file
@@ -0,0 +1,36 @@
|
||||
# NexusOps — Feature Push: Attack Plan (2026-09-30)
|
||||
|
||||
## Progress tracker — resume here if cut off
|
||||
| # | Feature | Status |
|
||||
|---|---------|--------|
|
||||
| 0 | ATTACK-PLAN.md committed | DONE (this commit) |
|
||||
| 1 | Pivot mode — single-shot TCP fetch through a node (`pivot_fetch` action + drawer form) | TODO |
|
||||
| 2 | Clipboard capture (poll xclip/pbpaste/Get-Clipboard into input capture) | TODO |
|
||||
| 3 | File watcher exfil (agent action `watch_dir`, new files auto-exfil) | TODO |
|
||||
| 4 | Self-destruct TTL — 14 days from activation, wipes self + persistence | TODO |
|
||||
| 5 | Dead-drop failover — fallback callback URLs in register response + agent failover | TODO |
|
||||
| 6 | LLM analyst — /api/nodes/:id/brief via nightmare Ollama (qwen3.8fast:16k, think:false) | TODO |
|
||||
| 7 | Credential decrypt — Firefox key4.db (3DES/openssl) + Linux Chromium v10 (peanuts) in agent; GPU brute queue dir + nightmare worker script | TODO |
|
||||
| 8 | Topology map — /api/topology from lateral scan outputs + SVG graph page | TODO |
|
||||
| 9 | Telegram important alerts — server alert levels (critical only) + NEXUS_ALERT_WEBHOOK to n8n | TODO |
|
||||
| 10 | README update + final commit/push + verify | TODO |
|
||||
|
||||
## Key decisions
|
||||
- Everything stdlib-only in the agent (openssl CLI used for 3DES/AES where needed).
|
||||
- LLM endpoint: http://10.30.20.29:11434 (nightmare), model qwen3.8fast:16k, think:false. NEVER other hosts.
|
||||
- GPU decrypt: jobs dropped in /opt/nexus-decrypt-queue on CT111; worker script for nightmare hashcat (4080S) provided, wired later.
|
||||
- Webhook: only CRITICAL events (kill switch, creds harvested, node offline >15min, new node). URL: n8n on .239:5678 (workflow may need creation there).
|
||||
- TTL default 14 days, stored as activation stamp file next to agent (~/.nexus_agent_activated), env override NEXUS_TTL_DAYS.
|
||||
- Commit + git push gitea after EVERY feature. Rebuild baked binary after final agent change. Purge CF cache for /agent.py after agent changes.
|
||||
- Test node: mizar canary CT171 (10.30.20.152), agent v2.3.0. Bump to v2.4.0 in this push.
|
||||
|
||||
## Verification per feature
|
||||
1. pivot_fetch: curl via node to 127.0.0.1:3000 returns dashboard HTML.
|
||||
2. clipboard: copy string on a desktop box (skip on headless — code path tested by unit: call function directly).
|
||||
3. watch_dir: create file in watched dir → appears in /api/files.
|
||||
4. TTL: set NEXUS_TTL_DAYS=0 test → self-wipe executes (on a THROWAWAY copy, not the canary).
|
||||
5. fallback: stop dashboard, agent retries fallback URL (check logs).
|
||||
6. brief: curl endpoint returns LLM text.
|
||||
7. decrypt: plant a Chromium v10 profile on canary, harvest, verify plaintext.
|
||||
8. topology: after lateral scan, /api/topology has edges; page renders.
|
||||
9. alerts: kill-switch test → webhook POST logged.
|
||||
Reference in New Issue
Block a user