v1 — first stable release
First stable release of ShardLure.
Included in this release:
- SSH honeypot telemetry analysis (journald + Cowrie)
- Actor clustering by playbook fingerprint / HASSH
- Intent classification (probe, proxy, deploy, mixed)
- Web dashboard with 3D globe arcs
- Terminal TUI dashboard (Bubble Tea)
- Intel dashboard: session timeline, MITRE ATT&CK grid, TTP harvesting, IOC export (STIX 2.1 + CSV), threat intel enrichment (AbuseIPDB / VT / GreyNoise), credential wordlists, infrastructure pivot graph, payload inspection, bash session replay, command deobfuscation
- Live tail mode with streaming ingest
- Quarantined payload capture with SSRF-safe fetcher
- SQLite storage with migration ladder
Binary attached: linux/arm64