Releases: m1thraz/SpectreHUD
Releases · m1thraz/SpectreHUD
Release list
v2.2.3
SpectreHUD v2.2.3 - Release Notes
SpectreHUD v2.2.3 improves first-run guidance, strengthens report and project-state safety,
finishes the Professional Print navigation workflow, and publishes the first stable export-plugin
boundary. Existing projects and reports require no migration.
Highlights
Guided First Run and Clearer Capture Controls
- Getting Started: A compact first-run dialog introduces the core capture-to-report workflow.
- Contextual Guidance: Report editing, Clip, Quick IP, Quick Notes, and Loot provide clearer
in-context hints without interrupting experienced users. - Unambiguous Clipboard Control: The former
RECheader control now uses a clipboard icon and
fixedCliplabel while preserving the existing active warning state, shortcuts, tray icon, and
activation overlay.
Navigable Professional Reports
- Optional Linked Contents: Professional Print can add a dedicated contents page with links to
rendered sections and nested findings. - Consistent Finding References: Findings Matrix, Attack Path, Technical Findings, and
Remediation use deterministicF-001identifiers and share stable internal PDF/HTML targets. - Semantic Document Boundaries: Executive Summary closes as a management section; Technical
Findings and Appendix start on clean pages without forcing every report section onto a new page. - Print-Safe Flow: Existing semantic rules continue to keep finding leads, headings, code,
evidence, table rows, callouts, and attack-path steps together where practical while allowing
long findings and tables to break naturally.
Export Plugin API V1
- Stable Public Boundary: External exporters import the headless
spectrehud_plugin_api
facade instead of application-internal modules. - Compatibility Before Loading: Manifests declare API version, plugin version, and minimum host
version; incompatible plugins are rejected before their implementation or optional dependencies
load. - Capability-Based Design: Report export is the required V1 capability. Optional Loot append is
queried explicitly instead of being imposed on every exporter. - Plugin-Owned Metadata: Exporter names, descriptions, fields, translations, availability, and
failure results cross a small typed contract.accentremains only a host-interpreted hint. - Separate DOCX Reference Plugin: The editable Word exporter is built as an optional,
platform-specific plugin bundle and serves as the first non-bundled reference implementation. - Portable Discovery: Local plugins work with portable Windows builds, Linux packages, and
per-user plugin directories. Obsidian and CherryTree now use the same isolated host boundary.
Reliability and Data Safety
- All Target, authentication, scope, URL, subnet, DNS, wordlist, and hash variables now survive
project switches and application restarts. - Existing reports that are unreadable, oversized, or incorrectly encoded are no longer treated as
empty editable documents. Autosave, note append, regeneration, and Loot mutations fail closed. - Successful report saves warn when a recovery draft cannot be removed, and stale drafts older than
the saved report are not offered for recovery. - Bundled and optional exporters are included in Windows and Debian packaging checks and exercised
through packaged-runtime smoke tests, including missing and incompatible dependency failures.
Compatibility and Scope
- Existing project data, report Markdown, templates, Obsidian settings, and CherryTree workflows
remain compatible. - Classic HTML remains unchanged; internal anchors and pagination changes are scoped to
Professional Print. - V1 covers export plugins only. Import plugins, installation UI, updates, marketplaces, arbitrary
UI injection, and generic feature hooks remain intentionally out of scope. - Plugin authors should use the documented V1 facade and manifest format in
docs/export_plugin_api_v1.md.
v2.2.2
Highlights
Semantic Professional Print Pagination
- Content-Aware Page Planning: Professional Print now places page breaks at safe semantic
boundaries instead of relying only on browser pagination. - Stable Report Sections: Section headings, finding leads, attack-path steps, tables, code
blocks, blockquotes, and screenshots carry dedicated print behavior. - Better Page Use: Medium-sized findings can use remaining page space without stranding their
opening context, while recommendation and reference blocks remain intact. - Evidence Grouping: Screenshots stay with their captions and directly associated explanatory
notes whenever they fit on one page.
Visual Attack-Path Timeline
- Print-Safe Timeline: Structured attack paths render as a compact vertical sequence with
phase, description, and linked finding context. - Complete Narrative Preservation: Manually written text between or after structured steps is
retained in the exported report.
Consistent Findings Presentation
- Unified Severity Badges: Findings matrices, individual finding headers, executive summaries,
and remediation tables use the same severity colors and typography. - Readable Summary Totals: Compact severity totals now match their badges without oversized,
visually noisy counts. - Full Phase Names: Internal phase identifiers such as
privescandpostexare expanded to
their localized display names in exported executive-summary tables.
Reproducible Example Report
- Synthetic Demonstration: The repository includes an obviously fictional Professional Print
report, source Markdown, and README preview. - Repeatable Generation: A dedicated script regenerates the example through the production
export path so future layout changes can be reviewed against a stable reference.
Export Reliability & Verification
- Added a deterministic five-scenario stress harness covering dense findings, large remediation
tables, oversized evidence, extended attack paths, and long metadata with media. - Extended PDF preflight beyond word counts to inspect positioned content coverage and image bounds,
catching nearly empty pages without rejecting legitimate image-heavy pages. - The final stress matrix passes all five scenarios across 70 rendered pages and 11,019 positioned
words; the maintained example report remains stable at eight pages. - Interactive and classic HTML exports retain their existing editing and layout behavior; the new
evidence grouping and pagination rules are scoped to Professional Print.
Compatibility
- Existing report Markdown and project data require no migration.
- Existing manual page breaks remain supported and are anchored at clean section boundaries.
- The export pipeline remains headless in
core/and does not add Qt dependencies.
v2.2.1
Highlights
Quick-Find Spotlight HUD
- Global Hotkey Access: Pressing
Ctrl+Alt+Fopens a focused, lightweight spotlight
search popup centered at the active cursor position. - Cheatsheet-Wide Search: Queries existing snippets across all categories without
requiring view switching or navigation away from external terminal / browser workflows. - Glass HUD Layout & Styling: Styled with the SpectreHUD glass theme, 520x320 dimensions,
custom scrollbars, keyboard navigation (Arrow Up/Down, Enter to copy, Esc to close). - Reliable Dismissal: Dismisses seamlessly on Esc, clicking outside the card, or
switching focus to another application.
Live Variable Interpolation in Quick-Find
- Rendered Command Previews: Command preview lines in search results render active project
variables (TARGET_IP,LHOST,PORT,URL,WORDLIST, etc.) live viaTemplateEngine.render. - Dynamic Synchronization: Reads values directly from the active
VariableBarand
session cache, reflecting live updates without restarting or reloading.
Interactive Parameter Prompting & Session Cache Integration
- Inline Parameter Prompting: Selecting a snippet with unresolved command placeholders
({{INTERFACE}},{{FILE}},{{DIR}},{{PAYLOAD}}, etc.) seamlessly triggers
ParamPromptDialogto enter or confirm parameters. - Session Cache Synchronization: Presets and previously entered parameters are stored in
session_param_cacheand reused automatically across subsequent copies and searches.
Verification & Compatibility
- Pure Core Isolation: Maintained strict decoupling between
core/and UI layers. - Multi-Platform Support: Works consistently across Windows and Linux (X11).
- Packaging: Full compatibility verified with PyInstaller one-file executable, Debian package,
and wheel distributions.
v2.2.0
Highlights
Capture and Continue (Screenshots)
- Non-Disruptive Capture: Global screenshot capture (
Ctrl+Alt+S) no longer steals
OS focus from external terminals or IDEs, and no longer forces the UI mode to switch
to "Loot". - Focus Preservation: Window restoration cleanly distinguishes between visible/active
states (was_visible,was_active), ensuring that an active terminal keeps desktop focus. - HUD Toast Confirmation: Quick visual confirmation is rendered unobtrusively via
PhaseToastHUDwithout grabbing focus.
Context Provenance in Capture Pipeline
- Strict Provenance Prioritization: Promoting clipboard history entries to Loot or
Quick Notes strictly respects the context captured at the moment of copying:
captured phase_id>active phase> neutral fallback ("misc"), and
captured target_ip>active target> empty. - Elimination of Heuristic Overwrites: Removed legacy heuristics that previously
forced unknown commands into "recon".
Session Recap & Resume Checkpoint
- Mental Context Preservation: The Session Recap banner now summarizes current Phase,
Target, last relevant action, and open Notes / unsynced Loot count. - One-Click Resume: Includes an explicit
[Resume]button to instantly route the user
back into the work context where they were interrupted. - Relaxed Auto-Dismiss: Increased banner duration to a stress-free 25s with an explicit
close button, eliminating premature dismissal on casual mouse movements or clicks.
Focus Review Decisions
- Unambiguous Triage Actions: Quick Note triage features four clear primary actions:
Loot(convert to evidence),Report(append to findings/report),Done(resolve),
andLater(mark as follow-up). - Inbox Prioritization: Unreviewed inbox notes are presented ahead of postponed follow-up
notes.
Deterministic Next Attention Item
- Single Next Task: Determines exactly one next actionable recommendation based on
persisted state:- Follow-up notes (
status == "followup") - Unreviewed inbox notes (
status == "inbox") - Unsynchronized findings/loot
- None (no artificial noise or distractions)
- Follow-up notes (
- Displayed directly within the Session Recap banner and wired to
[Resume].
Fault-Tolerant Quick Loot
- Draft Caching:
AddLootDialogcaches uncommitted text and titles upon accidental
cancel, focus loss, or dialog close. - Recovery Banner: Restores drafts on subsequent dialog open with an explicit
[Discard Draft]option. - Frictionless Capture: Automatically derives the title from the first line of content
if the title field is left blank, avoiding blocking error popups.
Compositor & Rounded Corners on Zero Transparency
- Compositor Retention: Fixed an issue where setting background transparency or
simulated glass intensity to 0 disabledWA_TranslucentBackgroundon composited desktops,
causing frameless window corners to render with square or black artifacts. - Clean Antialiasing: Preserves antialiased 14px rounded corners and border drawing
even when glass effects and transparency are set to minimum.
Compatibility and Upgrade
- Python 3.10 through 3.13
- Windows, macOS, and Linux (X11 & Wayland)
- Fully backward compatible with existing SpectreHUD v2.1.x project databases, templates, and configurations.
v2.1.9
Highlights
Antivirus False-Positive Prevention & Snippet Partitioning
- Curated Safe Default Snippets: The built-in Cheatsheet database contains only
strictly curated, benign utility commands to prevent antivirus heuristics from flagging
packaged binaries (.exe,.deb). - External Community Snippets: Advanced offensive, payload-heavy, and specialized
pentest commands are now distributed as optional external release assets alongside
each release.
In-App Cheatsheet Snippet Import
- One-Click Snippet Import: Added an Import Snippets button to the Cheatsheet
interface, allowing users of standalone portable.exeand Debian installations to load
external snippet JSON files directly into their local database without manual CLI or Python
script execution. - Deduplication & Merge: Imported snippets are merged safely into existing categories
with validation and immediate UI refresh.
Professional Print Export Polish & Cover Projection
- Clean Executive Cover Projection: Report metadata (Client, Target / Scope, Lead Tester,
Assessment Period, Report Date, Classification, and Version) is cleanly projected onto the
executive cover page (.report-cover). - Eliminated Duplicate Table Leaks: Raw metadata HTML tables are automatically pruned
from the body of both structured and unstructured reports. - Preserved Manual Notes: Evaluator notes, custom disclaimers, and narrative text located
beneath metadata tables are strictly preserved in the report body. - Intelligent Fallback for Markerless Reports: Reports lacking HTML section comments
(e.g., imported or manually authored Markdown) now resolve their leading H1 title and
two-column metadata tables automatically onto the cover page. - Resilient Metadata Parsing: Metadata extraction supports unbolded keys, optional
trailing colons, and automatically strips empty placeholders (-,n/a). - Dynamic Cover Title Resolution: Cover page titles resolve to the document's H1 heading
rather than falling back to the generic label"Target".
Localization & Quality
- Localized Success Dialogs: Added
dialog.successtranslations in English (Success)
and German (Erfolg) ensuring clean i18n lint compliance.
Compatibility and Upgrade
- Python 3.10 through 3.13 supported.
- Fully backward compatible with SpectreHUD v2.1.8 and earlier project databases, reports,
Loot collections, and templates. - No project or database schema migration required.
- Primary production platform is Windows 10/11; Linux X11 verified.
v2.1.8
Enhanced Loot-to-Finding Workflow & Enriched Loot Capture
- Explicit Loot-to-Finding Transition: Transform Loot items directly into structured
report findings while bundling supporting Loot entries as linked evidence. - Enriched Loot Properties: Added CVSS score, vector calculation, finding status,
references, and multi-target associations directly in the session Loot capture dialog. - Evidence Provenance Preservation: CVSS scores, targets, and metadata provenance
remain intact when converting Loot into findings.
Granular Loot & Finding Reconciliation
- Smart Difference Review: Live comparison distinguishes new, modified, and
report-only entries with clear status indicators. - Actionable Conflict Resolution: Provides granular, non-destructive resolution
choices for every changed item (keep report version, update from Loot, preserve both,
detach, or delete).
Theme & Styling Harmonization
- Appendix & Form Field Readability: Unified text fields and code editors across the
Appendix Inspector to use standard themedCommandBoxstyling, eliminating contrast
blowouts and unreadable text across built-in themes. - Independent Workspace Sidebar Styling: The workspace navigation sidebar and toolbars
now retain their theme-governed cyber-HUD aesthetics regardless of whether the document
editor/preview is toggled into light mode. - Universal Palette Safety: Added fallback resolution for background tokens, ensuring
custom and legacy HUD popups maintain solid contrast without color leaks.
Workspace & Live Preview Polish
- Clean Metadata Display: Evidence metadata tags (
<!-- spectre:evidence:... -->) are
hidden from plain-text inspector descriptions during editing and cleanly reconciled upon save. - Live Preview Typography: Improved heading spacing and block margins between findings
and sections in the live preview document. - Removed Degrading Opacity: Eliminated fading opacity on quick notes and clipboard cards
for clearer readability.
Compatibility and Upgrade
- Python 3.10 through 3.13 supported.
- Fully backward compatible with existing SpectreHUD v2.1.7 and earlier project databases,
reports, Loot collections, and templates. - No project or storage migration required.
- Primary production platform is Windows 10/11; Linux X11 verified.
v2.1.7
Highlights
Report Workspace as the Primary Workflow
- The structured Report Workspace is now the default report view, keeping the semantic
navigator, focused inspector, and live report preview together during authoring. - Contextual Markdown tools remain available where direct source editing is useful,
while Editor, Split, Preview, and Workspace modes continue to support different tasks. - Report Actions groups additive Loot synchronization and full regeneration in one
compact menu, reducing permanent toolbar noise without hiding destructive semantics. - Navigator selections now resolve to typed report locations and remain aligned with
the active inspector and highlighted preview destination.
Report Readiness Review
- A dedicated readiness inspector evaluates the report before handoff or export.
- Actionable checks surface incomplete metadata, unresolved report content, and other
conditions that should be reviewed before delivery. - The assessment stays synchronized with the current workspace document and provides a
concise overall state instead of requiring a manual section-by-section audit.
Transparent Loot Synchronization
- Live synchronization status distinguishes new Loot, changed source entries, and
findings that currently exist only in the report. - Additive synchronization appends missing material without replacing unrelated report
edits or moving the current editing position. - Full regeneration remains an explicit, confirmed operation and saves pending editor
changes before replacing generated content.
Theme-Aware Report Experience
- Export, generation, and regeneration dialogs now inherit the active HUD theme instead
of falling back to an unstyled black surface. - Export cards retain format-specific accents while resolving their colors through theme
tokens across the built-in palettes. - Inspector headers, forms, tables, scroll surfaces, and section panels share a more
consistent visual hierarchy throughout the Report Workspace.
Reliability and Recovery
- Restored drafts now refresh the navigator, inspectors, readiness state, and preview as
one coherent document state. - Metadata aliases are normalized so known fields do not reappear as duplicate custom
properties. - Report loading, saving, crash-draft recovery, regeneration, and additive Loot sync use
typed outcomes and preserve fail-closed behavior at their UI boundaries.
Architecture and Maintainability
ReportEditorTabhas been reduced from roughly 2,300 to about 1,200 lines and now acts
primarily as the workflow composition root.- Preview transformation, rendering, typography, semantic focus, and scroll coordination
live in dedicated preview modules and aReportPreviewController. - Inspector routing, evidence attachment, the document-action toolbar, and workspace
construction are owned by focused components with explicit callback contracts. - Headless session and mutation services own report persistence, recovery, regeneration,
and additive synchronization outcomes without importing Qt. - Transitional widget aliases and mirrored preview state were removed. Tests now use the
public Report Editor workflow API or the component that owns the behavior, with an AST
architecture guard preventing renewed access to private tab state.
Compatibility and Upgrade
- Python 3.10 through 3.13.
- Existing valid SpectreHUD v2.1.6 projects, reports, templates, snippets, Loot,
Quick Notes, and settings remain supported. - Report section, finding, Loot-marker, export, Obsidian, and CherryTree formats remain
compatible; no project migration is required. - Windows remains the primary production platform. Linux X11 support is verified, while
Wayland behavior continues to depend on compositor security restrictions.
v2.1.6
Modular Report Workspace
- Tri-Pane Environment: Combines a semantic Report Navigator, structured
section/finding inspectors, and live Markdown preview with free-form splitter
resizing across Editor, Split, and Workspace view modes. - Dedicated Cockpits:
- Assessment Metadata & Scope: Client, tester, target, classification, and date properties.
- Executive Summary: Real-time posture scorecards, severity breakdown pills, and dynamic finding matrix.
- Scope & Methodology: In-scope/out-of-scope targets and assessment limitations with high-contrast themed dark inputs.
- Attack Path: Narrative attack chain modeling with step sequencing and visual path representation.
- Technical Findings: Hierarchical findings management with one-click Loot conversion, severity badges, and phase attribution.
- Remediation Plan: Action item prioritization and owner assignments.
- Appendix & Evidence: Curated terminal history commands and screenshot evidence cards.
- Raw Markdown: Direct bidirectional Markdown editing synchronized live with the workspace document model.
- Responsive Layout Reflow: Cockpit layouts dynamically adapt to narrow split
views (260px - 450px) and intermediate widths, preventing truncation and wrapping form controls cleanly. - Default-Collapsed Navigator: Findings categories start collapsed to reduce
clutter on large assessments, with smart auto-expansion when navigating to or selecting an entry. - Theme-Aware Navigation: Navigator section icons dynamically inherit active theme
accent palettes (e.g. Dracula violet, Matrix green, Red Team crimson).
Curated Clipboard History for Reports
- Individual terminal snippets can now be marked (
[x] Report) directly from
the History stream or card context menu. - Report generation (Appendix A: Terminal Command History) selectively includes only
curated commands, keeping noise and transient shell commands out of the final deliverable. - Clean placeholder feedback (
*Keine Befehle für den Report ausgewählt.*) when no
commands have been flagged for inclusion. - Streamlined History filter pill and Clipboard History Picker dialog support.
Themed Frameless Export Dialog
ReportExportTypeDialogmigrated to a framelessBaseHudDialogfeaturing custom
header dragging, HUD glowing frames, and interactive option cards for HTML/PDF presentation,
Obsidian Vault, CherryTree package, and Raw Markdown exports.- Seamless design token integration across all 14 built-in SpectreHUD themes.
Security, CI/CD & Build Hardening
- Pinned all GitHub Actions across workflows to immutable 40-character commit SHAs
with human-readable version annotations. - Enforced bit-deterministic wheel builds across CI and release workflows via
--no-build-isolationagainst pinnedsetuptoolsandwheelbuild backend constraints. - Automated fallback to serial test execution in
scripts/run_tests.pywhenpytest-xdist
is absent from the local environment. - Consolidated code security scanning onto native GitHub CodeQL analysis.
Compatibility and Upgrade
- Python 3.10 through 3.13.
- Existing valid SpectreHUD v2.1.5 projects, reports, templates, snippets, Loot,
Quick Notes, and settings remain fully supported. - Report section/finding/Loot markers, hashes, additive synchronization,
Recommendations, Obsidian, and CherryTree contracts remain unchanged.
v2.1.5
Highlights
Safer Project Persistence
- Project-session writes now return typed outcomes and load Loot, clipboard
history, Quick Notes, and phase state as one validated transaction. - Corrupted, unreadable, oversized, or unsupported project state is reported
explicitly instead of being mistaken for a missing or empty session. - Versionless valid project and Pentest-security state is migrated to schema 1
with an exact backup of the pre-migration file. - Failed project creation rolls back only files created by SpectreHUD and keeps
pre-existing user content intact. - Atomic replacement now also synchronizes the parent directory for stronger
crash durability on filesystems that require it.
Actionable Diagnostics
- Runtime logs now live in the machine-local SpectreHUD Diagnostics directory;
Settings can open that directory or copy the active log path. SPECTRE_LOG_DIRremains available as an explicit override for portable or
managed installations.- Standard error dialogs provide selectable, copyable diagnostics including
technical details and the active log location. - Warning, information, and confirmation dialogs now share one consistent UI
boundary while specialized multi-action prompts retain their workflow-specific
behavior.
Faster, Clearer Workflows
- Returning to an unchanged Cheatsheet reuses its rendered cards, while initial
construction is performed incrementally to reduce perceived blocking. - Context-aware empty states and tooltips explain capture, phase, report, and
export actions more directly in English and German. - History's Markdown action is identified as draft generation rather than an
export of the editable report. - New screenshot Loot inherits the active Pentest phase instead of falling back
to Misc.
Reliability Fixes
- Frameless header navigation remains clickable where it overlaps the top resize
region. - The test runner's simulated Windows process-group configuration works on Linux
CI hosts.
Compatibility and Upgrade
- Python 3.10 through 3.13.
- Existing valid SpectreHUD v2.1.4 projects, reports, templates, snippets, Loot,
Quick Notes, and settings remain supported. - Versionless valid project-state and Pentest-security files are backed up and
upgraded to schema 1 when loaded; unsupported future schemas are rejected with
an actionable error instead of being overwritten. - Report section/finding/Loot markers, hashes, additive synchronization,
Recommendations, Obsidian, and CherryTree contracts remain unchanged.
Full Changelog: v2.1.4...v2.1.5
v2.1.4
Highlights
Report Navigation and Theme Integration
- A compact semantic Report Navigator jumps directly to marked sections and
findings while preserving the existing Markdown editing workflow. - The former heading-based Sections dropdown was removed because the semantic
navigator now covers both sections and findings. - Report toolbar icons inherit the active theme accent instead of retaining the
Cyber Dark cyan color.
Faster Capture Controls
Ctrl+Alt+Rnow pauses or resumes clipboard recording system-wide and shows
brief state feedback on the monitor containing the mouse pointer.- The shortcut overview now presents Quick Capture & Controls before phase
switching, making the most frequently used actions easier to find.
Manual Update Checks
- Settings includes a non-blocking Check for Updates action backed by the
latest stable GitHub release. - Versions are compared semantically, pre-releases and drafts are rejected, and
available Windows.exeor Linux.debassets are detected without starting
downloads or installations automatically. - When an update exists, SpectreHUD offers the official GitHub release page.
Dialog and Desktop Reliability
- Report generation, template management, template editing, section editing,
and destructive regeneration confirmation now share the opaque frameless HUD
dialog shell. Parent report content no longer shows through these windows. - Frameless resize cursors reliably return to their neutral state after leaving
a resize edge. - Add Missing Loot uses the active template language when it must create the
fallback section.
Compatibility and Upgrade
- Python 3.10 through 3.13.
- Compatible with existing SpectreHUD v2.1.3 projects, reports, templates,
snippets, Loot, Quick Notes, and settings. - No project, report, or configuration migration is required.
- Report section/finding/Loot markers, content hashes, additive synchronization,
recommendations, Obsidian, and CherryTree contracts remain unchanged. - Update checks are manual and read-only; SpectreHUD does not automatically
download or install releases.
Full Changelog: v2.1.3...v2.1.4