Expand monitoring for credential theft and covert protocols

This commit is contained in:
Luna 2026-06-13 03:30:36 -07:00
parent 3e5f8fc3f7
commit cb334c0c94
17 changed files with 675 additions and 25 deletions

View file

@ -37,6 +37,9 @@ work that is bigger than single alerts.
expected `sid` (`sentinel-redteam --list`), with a PASS/MISS verification pass.
- ✅ Document incident response runbooks for reverse shells, persistence, trojaned
binaries, hidden listeners, and sensor tampering ([RUNBOOKS.md](RUNBOOKS.md)).
- ✅ Add Gonzalo/Peopleswar-style behavior coverage: input-device keylogging,
credential-store/private-key access, SCTP/DCCP/raw/packet-family traffic, and
raw ICMP/special-protocol rootcheck detection.
Exit criteria: