Skip to content

Evidence Schema

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

Evidence Schema

Every step of every scenario is appended as one JSON object (one line) to <run-dir>/evidence.jsonl. The store is append-only; each record has exactly these 12 keys:

Key Meaning
run_id Unique id for the run.
scenario_id Which scenario this step belongs to.
step_no 0-based step index within the scenario.
ts UTC ISO-8601 timestamp.
target_host The target's host.
target_identity The target's identity label.
channel Delivery channel used for this step.
payload The attacker payload delivered.
observation {reply, tool_calls} from the target.
tool_calls The target's reported tool calls for this step.
canary_hits Canary tokens proven touched this step.
verdict Per-step verdict.

Why it matters:

  • Replayable — the full payload and response are recorded.
  • Attributable — scenario_id + target_host/target_identity + ts let a SOC map a step to a scenario and correlate it with SIEM/EDR telemetry (the basis of the planned detection-validation feature — see Roadmap).
  • Single source of truth — The Report is rendered from this file.

Design limits: one local run writes one JSONL file (no database); the record is immutable once written.

Clone this wiki locally