You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
Split "Domain Intelligence" into "Domain Posture" + "Brand Threat." The old
category mixed two subjects: your own domain's health and external
impersonation threats. Now domain_security, domain_probe, dns_history
form Domain Posture (your DNS/email/RDAP health), and typosquat + asn_cluster form Brand Threat (lookalike domains + coordinated
phishing-infra clusters). Split by subject (a tool-clean cut — no rewrites);
execution phases unchanged. 8 → 9 phase groups. Display-only phase_group change.
Split the exposure findings out of Asset Discovery into a new "Asset
Exposure" category.takeover_check (subdomain takeover) and cloud_assets
(open cloud buckets) are findings about exposed assets, not discovery — so
they now group under Asset Exposure (phase 5), leaving Asset Discovery
(phases 3–4) as pure discovery: subfinder, amass, alterx, asn_discovery, dnsx. Execution order is unchanged (both still run at phase 5); display-only phase_group change. Also refreshed the stale phase-group table in DESIGN.md.
Renamed the "Surface Enumeration" tool category to "Asset Discovery." More
accurate and standard: the phases-3–5 tools (subfinder, amass, alterx, asn_discovery, dnsx, takeover_check, cloud_assets) discover the org's
external assets — subdomains, IP ranges, cloud storage. Parallels the existing
"Port Discovery" category and ties to the asset_inventory app. Display-only phase_group rename.
Removed
Retired the github_recon tool. The GitHub Org Recon tool (infra references —
internal hostnames/subdomains, cloud-bucket URLs, API endpoints — in the org's
public GitHub repos) is removed: app, tests, and its Full Scan + Passive Scan
workflow steps (migration 0033 cleans existing DBs on deploy). Registry tool
count 30 → 29. The secret-scanning GitHub tool (github_secrets) and infra
discovery via subdomains/ASN remain.
Changed
js_secrets moved to the Web Exposure category. It runs at phase 12 (it
needs discovered .js assets), so it now groups with its execution neighbors
(nuclei/web_checker) instead of Credential Exposure. This makes Credential
Exposure a clean, single-phase (phase 2) category — breach_check, hudson_rock, github_secrets. Display-only phase_group change; js_secrets
still finds and redacts hardcoded secrets, unchanged.