Repository navigation
Evidence Schema
Mohammed Danish Amber edited this page Oct 5, 2026
·
1 revision
Every step of every scenario is appended as one JSON object (one line) to
<run-dir>/evidence.jsonl. The store is append-only; each record has exactly these
12 keys:
| Key | Meaning |
|---|---|
run_id |
Unique id for the run. |
scenario_id |
Which scenario this step belongs to. |
step_no |
0-based step index within the scenario. |
ts |
UTC ISO-8601 timestamp. |
target_host |
The target's host. |
target_identity |
The target's identity label. |
channel |
Delivery channel used for this step. |
payload |
The attacker payload delivered. |
observation |
{reply, tool_calls} from the target. |
tool_calls |
The target's reported tool calls for this step. |
canary_hits |
Canary tokens proven touched this step. |
verdict |
Per-step verdict. |
Why it matters:
- Replayable — the full payload and response are recorded.
-
Attributable —
scenario_id+target_host/target_identity+tslet a SOC map a step to a scenario and correlate it with SIEM/EDR telemetry (the basis of the planned detection-validation feature — see Roadmap). - Single source of truth — The Report is rendered from this file.
Design limits: one local run writes one JSONL file (no database); the record is immutable once written.