Relicense under GPL-3.0-or-later

Replace MIT with the full GNU GPLv3 text, update license metadata in
pyproject.toml (+ trove classifiers) and PKGBUILD, and add
SPDX-License-Identifier headers to all Python modules and shell scripts.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Luna 2026-05-31 06:52:34 -07:00
parent 28d67a1360
commit 586f74b929
27 changed files with 702 additions and 20 deletions

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""Detector registry.
Each detector is a ``Detector`` with a ``name`` and a ``detect(state, cfg)``

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""deleted_exe — a process running from a deleted or memfd-backed binary.
Fileless malware unlinks its dropper (or runs straight from ``memfd``) so there

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""egress — an interpreter holding an outbound connection to a public IP.
C2 beacons and exfil phone home. A scripting interpreter (bash/python/perl/nc)

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""ld_preload — userland rootkit / library-injection indicators.
Two signatures:

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""new_listener — a listening socket absent from the startup baseline.
Bind shells and backdoors have to listen somewhere. We diff the current set of

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""new_suid — a SUID/SGID binary that wasn't in the baseline.
A new setuid binary is a privilege-escalation persistence trick; one in a

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""persistence — modification of a watched persistence-relevant file.
Persistence has to land somewhere that survives a reboot: cron, systemd units,

View file

@ -1,3 +1,4 @@
# SPDX-License-Identifier: GPL-3.0-or-later
"""reverse_shell — an interpreter with a network socket on its stdio.
A real reverse shell dups a TCP/UDP socket onto fd 0/1/2 (``nc -e /bin/bash``,