-
Notifications
You must be signed in to change notification settings - Fork 1
posture report
Skill: post-hoc summary of everything sloth observed during a session. Not a live view — one file at shutdown.
-
--report FILE.md— Markdown, for hand-audit. -
--report-json FILE.json— JSON, for SIEM diff / CI compare.
Both can be set at the same time.
The report names credential exposures and high-risk devices, so it is
written 0600 whatever the umask (#87). An existing file at the path
is validated before it is truncated: a symlink, another user's file,
a multiply-linked file or one with any group/other bit is refused and
left untouched (could not open --report …: … refusing (report skipped)). A write that fails at close is reported instead of
announced as written.
- Session start / end timestamps and duration.
- Alert counts by severity (LOW / WARN / CRIT).
- MITRE ATT&CK technique breakdown — one row per unique technique
observed during the session, with hit counts. Posture-only alerts
like
NO_MONITOR_MODEare correctly omitted (they have no technique). - Cleartext credential exposures — src, dst, protocol, username, and whether a password was on the wire. Never the password value. The Markdown report includes a reminder note to the reader.
- High-risk devices — the
[g]Devices view is dedup'd to just the rows inHIGHandCRITbuckets, with the risk signal bitmask next to each.
Written once, at process exit, after the main loop has drained. This
means the file is a session record — not a mid-run snapshot. If sloth
exits abnormally (SIGKILL, panic), the file isn't produced. SIGINT
and SIGTERM go through the normal shutdown path and produce the
report.
Everything in the report is derived from tables sloth already maintains. No new observation surface, no probes, no writes to the wire. The report closes the loop between "we saw X" and "here's a sign-off document."
- alerts — where the ATT&CK tag on each alert comes from.
- jsonl-schema — the streaming event log the report summarises.
- cleartext-cred-guardrail — the "no password field, ever" rule.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance