Compare commits

...

77 Commits

Author SHA1 Message Date
Betty
368cba01a7 post: push 1 commit(s) to bojemoi/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 6m55s
2026-08-17 23:52:19 +02:00
grafana-watcher
60c699f2d5 post: commit aa9647e in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-17 23:51:55 +02:00
Betty
afc57a583f post: push 7 commit(s) to bojemoi/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-17 23:50:44 +02:00
Betty
477e543dee post: commit cecb2d8 in myai
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m51s
2026-08-16 14:53:16 +02:00
Claude Code
86e5dc060e post: commit 81740cd in borodino
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-16 14:52:50 +02:00
Claude Code
f026546362 post: commit e7cf8f7 in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 23s
2026-08-16 14:03:45 +02:00
Betty
efbf3e60f7 post: commit 08bcd3a in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-16 14:03:40 +02:00
Betty
146c8bd44b post: commit a05967a in myai
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m25s
2026-08-16 13:51:59 +02:00
Claude Code
456799ca2a post: commit d584542 in borodino
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-16 13:51:38 +02:00
Betty
35f223ecc5 post: push 1 commit(s) to myai-orchestrator/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m19s
2026-08-14 23:29:31 +02:00
Betty
f0f945fc58 post: commit e55d6b9 in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-14 23:28:31 +02:00
Betty
6af1ec4dfe post: commit 68b8299 in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-14 23:27:51 +02:00
Betty
ba65f7175c post: commit 533ae6e in myai
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m46s
2026-08-14 22:03:07 +02:00
Betty
e1a9573f1d post: commit 0c28a9b in myai-orchestrator
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 24s
2026-08-14 18:46:48 +02:00
Betty
6550706ce3 post: commit a1f1eeb in myai-orchestrator
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m20s
2026-08-14 18:38:44 +02:00
Betty
ffbdaf4b7d post: commit 02537a5 in MyAI-Orchestrator
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m38s
2026-08-14 18:19:28 +02:00
Betty
5ce63b3f93 post: push 1 commit(s) to borodino/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 2m24s
2026-08-14 17:00:04 +02:00
Claude Code
1f128b41fa post: commit f083b70 in borodino
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 22m36s
2026-08-14 16:44:39 +02:00
grafana-watcher
b0f066c10b post: commit fe99174 in myai
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m46s
2026-08-13 06:07:43 +02:00
Betty
45614bdaf5 post: push 1 commit(s) to myai/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 1m27s
2026-08-13 00:49:54 +02:00
grafana-watcher
d19f8e0e22 post: commit d2e609b in myai
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m49s
2026-08-13 00:42:16 +02:00
grafana-watcher
644780fbce post: commit eabdfd8 in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-13 00:41:17 +02:00
Betty
5335f705e2 post: push 1 commit(s) to myai/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m14s
2026-08-11 17:31:26 +02:00
Betty
971371e701 post: commit a8a32ef in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-11 17:31:03 +02:00
Betty
a75b09d105 post: push 1 commit(s) to myai/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 1m53s
2026-08-11 00:06:58 +02:00
Betty
24d587bf35 post: commit 488be07 in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 24m28s
2026-08-10 23:44:34 +02:00
Betty
7a49f1a58c post: commit 561100c in myai
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-10 23:43:51 +02:00
grafana-watcher
6ad35890c5 post: commit 5d9493b in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m21s
2026-08-10 23:10:45 +02:00
Betty
cc1d239abb post: push 2 commit(s) to borodino/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m28s
2026-08-10 00:03:12 +02:00
Claude Code
b3883b2fa7 post: commit c101668 in borodino
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-10 00:02:51 +02:00
Betty
b37cd96c89 post: push 1 commit(s) to bojemoi/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 3m28s
2026-08-06 23:20:24 +02:00
Betty
c3fa137fd6 feat(blog): English version of ThreatFox MCP cross-reference post
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-06 23:16:34 +02:00
grafana-watcher
e04e064198 post: commit ea70b68 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-06 23:14:32 +02:00
Betty
02ecae0a7f post: ThreatFox MCP + cross-référence MSF — C2 Cobalt Strike trouvé
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-06 23:08:46 +02:00
Betty
f1a7d913c3 post: push 1 commit(s) to bojemoi/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-06 23:06:58 +02:00
grafana-watcher
d7a2481978 post: commit 3c9a935 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-08-06 23:06:44 +02:00
grafana-watcher
2f71ec89a1 post: commit 941c732 in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m27s
2026-08-04 00:19:11 +02:00
grafana-watcher
2630eb58fe post: commit 19b1424 in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m27s
2026-08-03 23:26:45 +02:00
Claude Code
16add5bb69 post: commit 7ce2c29 in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m40s
2026-08-03 22:32:18 +02:00
grafana-watcher
17273fc41a post: commit df1b9ab in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m8s
2026-07-31 23:49:44 +02:00
b236120978 post: Operation Talked — APT vs homelab comparison
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 5m4s
2026-07-31 21:32:49 +00:00
Betty
cd22a48d5d post: push 1 commit(s) to bojemoi/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m13s
2026-07-31 21:34:25 +02:00
grafana-watcher
c6ee57c118 post: commit 6bd1758 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-31 21:34:06 +02:00
Claude Code
189ac1e47c post: commit 612c333 in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m54s
2026-07-25 22:33:30 +02:00
grafana-watcher
a5b9867d64 post: commit b98fc33 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-25 22:33:05 +02:00
Claude Code
b9732958f9 post: commit a1f81e8 in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m6s
2026-07-25 22:18:27 +02:00
Betty
a4766c22b8 post: push 1 commit(s) to borodino/main
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m15s
2026-07-25 22:00:57 +02:00
Betty
d54847eac9 post: push 1 commit(s) to bojemoi/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-25 22:00:18 +02:00
grafana-watcher
ebc36f7500 post: commit f9d55e6 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-25 21:59:55 +02:00
grafana-watcher
547bd6769c post: commit 955980d in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m16s
2026-07-25 09:01:08 +02:00
Betty
4c9c6f275e review: analyse stack/02-service-maintenance.yml (2026-07)
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-25 09:00:49 +02:00
Betty
2f5edf775e post: push 1 commit(s) to borodino/main 2026-07-25 09:00:49 +02:00
Claude Code
c596a8a628 post: commit f7a51ef in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m39s
2026-07-24 22:46:44 +02:00
Claude Code
857e95621e post: commit 3e07356 in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m43s
2026-07-24 18:57:58 +02:00
Claude Code
f669f497d9 post: commit 20b514f in borodino
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m44s
2026-07-24 14:36:03 +02:00
grafana-watcher
7a21560c97 post: commit d36e14e in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m15s
2026-07-24 09:01:19 +02:00
Betty
f5e595ea7c review: analyse stack/02-init-ptaas.yml (2026-07)
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-24 09:00:59 +02:00
Betty
90af0c99bc post: push 1 commit(s) to bojemoi/main 2026-07-24 09:00:59 +02:00
grafana-watcher
996e2ae74b post: commit 6dcd4e0 in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 4m40s
2026-07-23 09:01:19 +02:00
Betty
728765d2df review: analyse stack/01-suricata-host.yml (2026-07)
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-23 09:00:54 +02:00
Betty
4813346dd6 post: push 1 commit(s) to bojemoi/main 2026-07-23 09:00:54 +02:00
grafana-watcher
eaa4c8ec19 post: commit 05e7b48 in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 3m14s
2026-07-22 18:07:09 +02:00
grafana-watcher
1d413aae0e post: commit bb33293 in bojemoi
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 5m8s
2026-07-22 17:59:01 +02:00
Betty
2450a46406 fix(blog): corriger escapes YAML invalides dans 3 commits (lot 2)
All checks were successful
Hugo Build & Deploy / build-deploy (push) Successful in 5m48s
2026-07-22 17:28:16 +02:00
Betty
b8a1cadd92 fix(blog): corriger escape YAML invalide dans commit b9dd726
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-22 17:27:55 +02:00
Betty
a7af5c230a fix(blog): corriger escape YAML invalide dans commit 4abbb95
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 1m6s
2026-07-22 17:24:33 +02:00
Betty
48d97a3db7 post: hardening isolation réseau workers borodino (2026-07-22)
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 1m24s
Suite à l'incident OpenAI/HuggingFace — audit et correction de la
ségrégation réseau des workers offensifs dans Docker Swarm.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-22 17:18:05 +02:00
Betty
8b233034de post: push 1 commit(s) to borodino/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-22 17:16:24 +02:00
Betty
17218c8978 post: push 1 commit(s) to bojemoi/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-22 17:15:33 +02:00
grafana-watcher
294d740970 post: commit 5f62eb5 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-22 17:15:07 +02:00
grafana-watcher
3b777ae2ee post: commit 0eb924b in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 1m7s
2026-07-22 09:01:23 +02:00
Betty
6e2231f44c review: analyse stack/01-service-hl.yml (2026-07)
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-22 09:00:54 +02:00
Betty
35e0f2d187 post: push 1 commit(s) to bojemoi/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 59s
2026-07-21 21:37:02 +02:00
Betty
b0e0a8fa70 post: push 1 commit(s) to borodino/main
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-21 21:36:25 +02:00
Claude Code
2885ce1441 post: commit 01433ed in borodino
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-21 21:35:58 +02:00
grafana-watcher
3af17ae7bc post: commit 1180f7c in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Failing after 1m3s
2026-07-21 20:50:14 +02:00
grafana-watcher
1e93d90c3f post: commit b31c4f4 in bojemoi
Some checks failed
Hugo Build & Deploy / build-deploy (push) Has been cancelled
2026-07-21 20:48:33 +02:00
81 changed files with 4696 additions and 7 deletions

View File

@@ -20,9 +20,9 @@ author: "Betty"
### Description
- Grafana datasources: remplacer \${POSTGRES_PASSWORD} par \$__file{/run/secrets/postgres_password}
- Grafana datasources: remplacer ${POSTGRES_PASSWORD} par $__file{/run/secrets/postgres_password}
pour PostgreSQL-MSF et PostgreSQL-ThreatIntel (la var d'env était vide → no data)
- Sentinel DB: utiliser \$__file{/run/secrets/sentinel_pg_pass}
- Sentinel DB: utiliser $__file{/run/secrets/sentinel_pg_pass}
- Ajouter sentinel_pg_pass aux secrets Grafana
- Bump config grafana-datasources_v5 → v6 (Docker configs immuables)
- postfix-exporter: ajouter règle rsyslog (postfix_rsyslog_maillog Docker config)

View File

@@ -1,5 +1,5 @@
---
title: "[bojemoi] fix(grafana): corriger variable \$node dans Docker Container & Host Metrics"
title: "[bojemoi] fix(grafana): corriger variable $node dans Docker Container & Host Metrics"
date: 2026-05-29T22:31:56+02:00
draft: false
tags: ["commit", "bojemoi", "main"]

View File

@@ -1,5 +1,5 @@
---
title: "[bojemoi] fix(grafana): ajouter filtre instance=~\$node sur tous les panels Docker Container & Host Metrics"
title: "[bojemoi] fix(grafana): ajouter filtre instance=~$node sur tous les panels Docker Container & Host Metrics"
date: 2026-05-29T22:28:06+02:00
draft: false
tags: ["commit", "bojemoi", "main"]

View File

@@ -20,8 +20,8 @@ author: "Betty"
### Description
- Suppression variable \$port (instance=meta-76, pas meta-76:8080)
- Remplacement \$node:\$port → \$node dans les queries
- Suppression variable $port (instance=meta-76, pas meta-76:8080)
- Remplacement $node:$port → $node dans les queries
- Variables job et node passées en multi-select avec All
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

View File

@@ -20,7 +20,7 @@ author: "grafana-watcher"
### Description
Remplace \${DS_POSTGRESQL_THREATINTEL} par l'UID réel PD38AB5DA57252E20
Remplace ${DS_POSTGRESQL_THREATINTEL} par l'UID réel PD38AB5DA57252E20
(PostgreSQL-MSF) pour que les 3 panels chargent sans variable de template.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

View File

@@ -0,0 +1,40 @@
---
title: "[borodino] fix(uzi): scale à 1 replica — msfrpcd est mono-tâche"
date: 2026-07-21T21:35:53+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 01433ed par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `01433ed`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `01433ed139e5e6b22416b3f4386c0ead7f1b1d09` |
### Description
Les 3 replicas UZI appelaient tous le même msfrpcd via RPC.
Comme msfrpcd sérialise les requêtes, les 2 replicas supplémentaires
attendaient leur tour sans rien faire — débit réel identique à 1 replica.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/40-service-borodino.yml
```
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,38 @@
---
title: "[bojemoi] chore(memory): mise à jour alert-agent — anthropic_api_key canonique + fix pydantic v2"
date: 2026-07-21T20:49:57+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 1180f7c par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `1180f7c`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `1180f7c51b7f262a9b0abc2c0e18aef67438e30f` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M .claude/agent-memory/infra-daily-monitor/MEMORY.md
M .claude/agent-memory/pipeline/MEMORY.md
```
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 101 +++++++++++++++++----
.claude/agent-memory/pipeline/MEMORY.md | 30 +++---
2 files changed, 99 insertions(+), 32 deletions(-)
```

View File

@@ -0,0 +1,44 @@
---
title: "[bojemoi] refactor(alert-agent): consolider sur anthropic_api_key (secret canonique)"
date: 2026-07-21T20:48:28+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit b31c4f4 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `b31c4f4`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `b31c4f4e052e22e3267e68820ee0cabcbfa93f2f` |
### Description
- config.py: _build_settings() avec model_copy() pour appliquer les secrets
après init pydantic (fix: assignation self.x = y ignorée par pydantic v2)
- Lecture anthropic_api_key en priorité, claude_api_key en fallback
- Stack: claude_api_key → anthropic_api_key
- Secret claude_api_key supprimé
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M alert-agent/alert_agent/config.py
M stack/48-service-alert-agent.yml
```
### Diff Summary
```
alert-agent/alert_agent/config.py | 52 +++++++++++++++++++++++----------------
stack/48-service-alert-agent.yml | 4 +--
2 files changed, 33 insertions(+), 23 deletions(-)
```

View File

@@ -0,0 +1,36 @@
---
title: "[bojemoi] chore(ollama): scale à 0 — T400 trop lent pour inférence LLM"
date: 2026-07-22T18:07:00+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 05e7b48 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `05e7b48`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `05e7b48118e7debb8d1c636b078e156bc9738c51` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/51-service-ollama.yml
```
### Diff Summary
```
stack/51-service-ollama.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,32 @@
---
title: "[bojemoi] chore(review): marquer stack/01-service-hl.yml comme traité (2026-07)"
date: 2026-07-22T09:01:16+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 0eb924b par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `0eb924b`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `0eb924b1eebfe8e04f5b54350cd5cc9a857351f2` |
### Files Changed
```
M claude/state.json
```
### Diff Summary
```
claude/state.json | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,43 @@
---
title: "[bojemoi] security(network): isoler postgres du réseau pentest pour les workers"
date: 2026-07-22T17:14:57+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 5f62eb5 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `5f62eb5`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `5f62eb522c088d2c5a78a89725d6c06a08be5bc4` |
### Description
Ajoute le réseau pentest au service postgres afin que les workers
borodino (ak47, bm12, uzi, zap, nuclei, sliver, masscan) puissent
y accéder sans passer par backend.
Contexte: suite à l'incident OpenAI/HuggingFace (2026-07-22), réduction
de la blast radius en cas de compromission d'un worker via input hostile.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/01-service-hl.yml
```
### Diff Summary
```
stack/01-service-hl.yml | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,44 @@
---
title: "[bojemoi] feat(ollama): réactiver comme fallback forensique IR (replicas: 1)"
date: 2026-07-22T17:58:54+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit bb33293 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `bb33293`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `bb3329336b1b2ac178f2e315bc608dd2f504de86` |
### Description
Suite à l'incident HuggingFace (2026-07-22) qui a démontré que les LLMs
via API commerciale refusent d'analyser des payloads malveillants pendant
un IR (asymmetry problem).
Ollama + Mistral 7B tourne sur meta-68 (nvidia.vgpu) comme fallback
local sans guardrails pour l'analyse forensique. Alert-agent reste sur
Claude API (LLM_BACKEND=claude). Scale à 0 si inutilisé.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/51-service-ollama.yml
```
### Diff Summary
```
stack/51-service-ollama.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,32 @@
---
title: "[bojemoi] chore(review): marquer stack/01-suricata-host.yml comme traité (2026-07)"
date: 2026-07-23T09:01:11+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 6dcd4e0 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `6dcd4e0`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `6dcd4e078ce724be42b42527bb9f0ef0477975de` |
### Files Changed
```
M claude/state.json
```
### Diff Summary
```
claude/state.json | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,39 @@
---
title: "[borodino] fix(bm12): réduire le défaut de replicas à 5 (max par node = 5, 1 seul worker)"
date: 2026-07-24T14:35:55+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 20b514f par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `20b514f`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `20b514f8fc3c87c3cb059a380e3ca6c7e7bd0e39` |
### Description
Avec un seul worker (meta-68) et max_replicas_per_node=5, 10 replicas
causaient 5 tâches en Pending indefiniment. Le défaut passe à 5.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/40-service-borodino.yml
```
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[borodino] fix(telegram): améliorer le message de fin de traitement"
date: 2026-07-24T18:57:49+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 3e07356 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `3e07356`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `3e07356f93d402ea76d924419218b04b84c5c7b3` |
### Description
- "Campagne terminée" → "Traitement terminé"
- Raison sur ligne séparée avec icône ⏱
- UZI: affiche clairement pwned/clean/non traité au lieu de "?"
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M sdk/bojemoi/telegram.py
```
### Diff Summary
```
sdk/bojemoi/telegram.py | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
```

View File

@@ -0,0 +1,32 @@
---
title: "[bojemoi] chore(review): marquer stack/02-init-ptaas.yml comme traité (2026-07)"
date: 2026-07-24T09:01:13+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit d36e14e par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `d36e14e`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `d36e14ea385a1a7f2d6440930d17788a9f263f3f` |
### Files Changed
```
M claude/state.json
```
### Diff Summary
```
claude/state.json | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,39 @@
---
title: "[borodino] fix(campagne-nginx): supprimer send_telegram par CVE — trop verbeux"
date: 2026-07-24T22:46:36+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit f7a51ef par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `f7a51ef`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `f7a51ef9a96e39a6e7653c8abab4392855ecaebb` |
### Description
Un message était envoyé pour chaque host vulnérable à CVE-2026-42533.
Les findings sont conservés dans DefectDojo uniquement.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M thearm_campagne_nginx
```
### Diff Summary
```
thearm_campagne_nginx | 6 ------
1 file changed, 6 deletions(-)
```

View File

@@ -0,0 +1,36 @@
---
title: "[borodino] feat(orchestrator): CAMPAIGN_TIMEOUT 7200 → 14400s"
date: 2026-07-25T22:33:24+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 612c333 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `612c333`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `612c333e4c8bc7bde040a9748c6524125e4c71b6` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/40-service-borodino.yml
```
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,32 @@
---
title: "[bojemoi] chore(review): marquer stack/02-service-maintenance.yml comme traité (2026-07)"
date: 2026-07-25T09:01:03+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 955980d par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `955980d`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `955980da893c21c4b1bcef8f85cf68f843c7cf23` |
### Files Changed
```
M claude/state.json
```
### Diff Summary
```
claude/state.json | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,42 @@
---
title: "[borodino] perf(uzi): réduire timeout check_target 15s → 5s"
date: 2026-07-25T22:18:25+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit a1f81e8 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `a1f81e8`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `a1f81e8f17b9b3aedbf051b9d0cc37a4106a7d0e` |
### Description
check_target attendait jusqu'à 15s par module MSF.
Sur des hosts avec ports 80/443 ouverts (~1000 modules linux/http testés),
ça causait des runs de 10-12h par host.
5s suffisent — si la console MSF n'est pas ready en 5s, le check est de toute
façon inconclus et on procède.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M thearm_uzi
```
### Diff Summary
```
thearm_uzi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,43 @@
---
title: "[bojemoi] feat(orchestrator): réduire spam Telegram campagnes"
date: 2026-07-25T22:33:00+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit b98fc33 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `b98fc33`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `b98fc335bc4a77aeabebe166a243d35712979c5e` |
### Description
Option A: send_telegram_campaign_done conditionnel — notifier uniquement
si résultat intéressant (pwned, nuclei/zap critical/high, sliver).
Les timeouts sans findings sont silencieux.
Option B: CAMPAIGN_TIMEOUT 7200s → 14400s (4h) dans le stack.
Donne plus de temps à UZI avant de basculer en recon.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M samsonov/pentest_orchestrator/main.py
```
### Diff Summary
```
samsonov/pentest_orchestrator/main.py | 26 ++++++++++++++++++++++++--
1 file changed, 24 insertions(+), 2 deletions(-)
```

View File

@@ -0,0 +1,44 @@
---
title: "[bojemoi] feat(dojo-triage): remplacer Ollama/Mistral par Claude Haiku"
date: 2026-07-25T21:59:50+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit f9d55e6 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `f9d55e6`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `f9d55e6377bf99aeebf7afc43ced43549a77f6da` |
### Description
- Ollama étant arrêté (scale=0), les findings LLM étaient tous skippés
- Remplace ask_mistral() par ask_claude() avec anthropic SDK synchrone
- Ajoute secret anthropic_api_key au service
- Augmente mémoire 256M→512M / réservation 64M→128M
- Corrige aussi enable_simple_risk_acceptance sur tous les produits DefectDojo (fix PATCH 400)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M dojo-triage/requirements.txt
M dojo-triage/triage.py
```
### Diff Summary
```
dojo-triage/requirements.txt | 1 +
dojo-triage/triage.py | 76 ++++++++++++++++++++++++++++----------------
2 files changed, 50 insertions(+), 27 deletions(-)
```

View File

@@ -0,0 +1,43 @@
---
title: "[bojemoi] chore(memory): mise à jour mémoires agents après session 2026-07-31"
date: 2026-07-31T21:33:55+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 6bd1758 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `6bd1758`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `6bd175898da47215595fc3df3f4136c96f48b6bf` |
### Description
- infra-daily-monitor: check 21:13 UTC (3 services récupérés, ZAP redémarré,
disk meta-76 à 80%), Ollama confirmé à 0, VPN status actualisé
- pipeline: état 19:09 UTC (AK47 actif, ZAP dégradé newSession, UZI faible
activité, Sliver idle)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M .claude/agent-memory/infra-daily-monitor/MEMORY.md
M .claude/agent-memory/pipeline/MEMORY.md
```
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 215 ++++-----------------
.claude/agent-memory/pipeline/MEMORY.md | 30 +--
2 files changed, 55 insertions(+), 190 deletions(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[bojemoi] feat(cti): layer ATT&CK Navigator — Operation Talked (UAC-0056/UAC-0114)"
date: 2026-07-31T23:49:43+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit df1b9ab par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `df1b9ab`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `df1b9ab1998d6da1093156be7a2556ddc0bfe262` |
### Description
16 techniques MITRE mappées depuis le rapport SOCRadar du 2026-07-29.
Campagne Russia-nexus active juin 2025 - juillet 2026, ciblant le secteur
défense/aérospatiale ukrainien.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A cti/operation-talked-navigator.json
```
### Diff Summary
```
cti/operation-talked-navigator.json | 258 ++++++++++++++++++++++++++++++++++++
1 file changed, 258 insertions(+)
```

View File

@@ -0,0 +1,43 @@
---
title: "[bojemoi] fix(nuclei-api): handle JSON array output format from nuclei -json-export"
date: 2026-08-03T23:26:38+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 19b1424 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `19b1424`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `19b1424a58d97d247ad17c235130305cb59e8620` |
### Description
Nuclei v3.x writes a single-line JSON array (not JSONL) to the export file.
The previous JSONL parser appended the entire array as one item, causing
'list' object has no attribute 'get' in push_to_defectdojo() and /results.
Fix: detect list vs dict in the per-line parser and extend/append accordingly.
Applies to both the internal dojo import loop and the /results API endpoint.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M samsonov/nuclei_api/main.py
```
### Diff Summary
```
samsonov/nuclei_api/main.py | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
```

View File

@@ -0,0 +1,51 @@
---
title: "[borodino] feat(nuclei): améliorer ciblage et enrichissement des tags"
date: 2026-08-03T22:32:10+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 7ce2c29 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `7ce2c29`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `7ce2c29b2140a44ce1b1d8a02d96e2f3abcc82cc` |
### Description
Option 2 — Meilleure population :
- Nouvelle Priorité 0 : produits haute valeur CVE (wordpress, bitrix,
webmin, phpmyadmin, opencart, prestashop, grafana, etc.)
- Ajout ports 10000 (Webmin), 7070, 4848 (GlassFish) dans les priorités
- Retrait du filtre is_hosting : résidentiels inclus à nouveau
Option 3 — Meilleurs templates :
- SSH filtré par version : tag 'ssh' ajouté seulement si version < 9.6
(vulnérable CVE-2023-48795 Terrapin)
- Tag 'http' ajouté automatiquement pour tout host avec port web
- PRODUCT_TAG_MAP étendu : webmin, cpanel, plesk, roundcube, opencart,
prestashop, magento, laravel, grafana, kibana, zabbix, nagios, redis
- Tags cms/http/panel enrichis pour wordpress, bitrix, joomla, drupal
- HIGH_VALUE_PRODUCTS set pour Priorité 0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M thearm_nuclei
```
### Diff Summary
```
thearm_nuclei | 224 ++++++++++++++++++++++++++++++++++++++++------------------
1 file changed, 157 insertions(+), 67 deletions(-)
```

View File

@@ -0,0 +1,50 @@
---
title: "[bojemoi] feat(nuclei-feedback): loop Nuclei → Uzi pour exploitation ciblée"
date: 2026-08-04T00:19:02+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 941c732 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `941c732`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `941c732235a26dbdb2117e2298b96dda23b3b20d` |
### Description
Quand Nuclei trouve des findings critical/high/rce, injecte le host
dans pentest:uzi_queue avec attack_surface enrichi → Uzi passe de
~2500 modules génériques à ~10-50 modules ciblés.
- pentest_orchestrator/main.py : nouveau thread nuclei_feedback_loop()
qui subscribe pentest:results et mappe les tags Nuclei vers les clés
attack_surface de thearm_uzi (log4shell, spring4shell, webmin, bitrix,
confluence, ms_exchange, vmware_vcenter, citrix_netscaler, etc.)
- Dockerfile.samsonov : build depuis /opt/bojemoi (contexte parent),
install explicite psycopg2/valkey/httpx + bojemoi SDK, ajout ENTRYPOINT
python3 -m pentest_orchestrator.main + PYTHONPATH=/src
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M samsonov/Dockerfile.samsonov
M samsonov/pentest_orchestrator/main.py
```
### Diff Summary
```
samsonov/Dockerfile.samsonov | 18 +++--
samsonov/pentest_orchestrator/main.py | 146 ++++++++++++++++++++++++++++++++++
2 files changed, 157 insertions(+), 7 deletions(-)
```

View File

@@ -0,0 +1,54 @@
---
title: "[bojemoi] feat(cti): ThreatFox + cross-référence MSF dans le MCP server"
date: 2026-08-06T23:06:36+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 3c9a935 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `3c9a935`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `3c9a9358aefa13abfd244995f93b1588597be57c` |
### Description
- Nouveau module sdk/bojemoi/cti.py :
- threatfox_recent() : IOCs récents depuis ThreatFox (filtrables par type/malware)
- threatfox_search() : recherche d'un IOC spécifique
- ioc_crossref() : croise les C2 ThreatFox avec les 6.15M hosts MSF
→ fallback Feodo Tracker si pas de clé API
- 3 nouveaux tools MCP exposés (threatfox_recent, threatfox_search, ioc_crossref)
- Secret Docker threatfox_api_key intégré (stack 49-service-mcp.yml)
- Pin mcp<2.0.0 (breaking API change en 2.0.0)
Premier hit : 45.8.159.205:8596 Cobalt Strike C2 (tag drb-ra, confiance 75%)
documenté dans DefectDojo #368610.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M mcp-server/requirements.txt
M mcp-server/server.py
A sdk/bojemoi/cti.py
M stack/49-service-mcp.yml
```
### Diff Summary
```
mcp-server/requirements.txt | 2 +-
mcp-server/server.py | 84 +++++++++++
sdk/bojemoi/cti.py | 336 ++++++++++++++++++++++++++++++++++++++++++++
stack/49-service-mcp.yml | 3 +
4 files changed, 424 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,43 @@
---
title: "[bojemoi] feat(cti): cron quotidien cross-ref ThreatFox + alerte Telegram"
date: 2026-08-06T23:14:18+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit ea70b68 par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `ea70b68`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `ea70b685328e74c221d3c098895094fc2992ccff` |
### Description
- mcp-server/cti_daily.py : script one-shot ioc_crossref(days=1) + Telegram
→ RAS si 0 hits, alerte détaillée si C2 connus dans la base MSF
- stack/49-service-mcp.yml : ajout secrets telegram_bot_token + telegram_chat_id
- Cron meta-76 07h00 : docker exec mcp_mcp-server python cti_daily.pyc
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A mcp-server/cti_daily.py
M stack/49-service-mcp.yml
```
### Diff Summary
```
mcp-server/cti_daily.py | 89 ++++++++++++++++++++++++++++++++++++++++++++++++
stack/49-service-mcp.yml | 6 ++++
2 files changed, 95 insertions(+)
```

View File

@@ -0,0 +1,36 @@
---
title: "[myai] chore: add .gitignore"
date: 2026-08-10T23:44:25+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 488be07 par Betty dans myai"
author: "Betty"
---
## Commit `488be07`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `488be078278af5ac314cd2729690d61e40b46196` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A .gitignore
```
### Diff Summary
```
.gitignore | 6 ++++++
1 file changed, 6 insertions(+)
```

View File

@@ -0,0 +1,31 @@
---
title: "[myai] feat(myai): initial — FastAPI + scikit-learn + PostgreSQL"
date: 2026-08-10T23:43:49+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 561100c par Betty dans myai"
author: "Betty"
---
## Commit `561100c`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `561100c922c7451dca626f14f7e73ef32f0ce6df` |
### Description
Classificateur de logs sécurité (6 classes : sqli, xss, rce, exposure,
misconfiguration, auth_bypass) via TF-IDF + LogisticRegression.
- Pipeline ML sérialisé en bytea dans le postgres du stack base (réseau backend)
- DB 'myai' + table 'models' créées automatiquement au démarrage
- Endpoints : /predict, /train, /model/info, /health
- Déploiement Swarm : worker, port 8765, 512M RAM, secret postgres_password
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

View File

@@ -0,0 +1,42 @@
---
title: "[bojemoi] fix(zap): limiter le spider aux liens internes — prévention OOM"
date: 2026-08-10T23:10:36+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit 5d9493b par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `5d9493b`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `5d9493b5951006d2afa59ffdc7ca51d0e80b8186` |
### Description
ZAP scrawlait les liens externes (ex: forum russe 80.93.50.222 → 7504 URLs
dont des domaines cyrilliques), causant une explosion mémoire → OOM kill (exit 137).
Ajout de maxChildren=20 et subtreeOnly=true dans zap_spider() pour restreindre
le crawl au sous-arbre de l'hôte cible uniquement.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M oblast-1/zap_scanner.py
```
### Diff Summary
```
oblast-1/zap_scanner.py | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,59 @@
---
title: "[borodino] fix(uzi+bm12): refonte sélection exploits — fiabilité et pertinence"
date: 2026-08-10T00:02:43+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit c101668 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `c101668`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `c1016684c57cd086237918ccc32c0567e0034ee7` |
### Description
uzi — build_targeted_exploits:
- Sélection version-aware: "nginx 1.14" au lieu de 15 termes HTTP génériques
- 890 modules → 2-6 modules par service (produit bm12 + version → CVE ciblé)
- MAX_EXPLOITS=15 hard cap, tri par date décroissante
- 1 payload max au lieu de 5 (meilleur payload OS-compatible)
- Timeout global MAX_HOST_TIME=3600s — empêche les hangs infinis
- Stdout line_buffering=True — logs visibles immédiatement (plus de burst 4KB)
- Fix ALTER TABLE locked_at: vérifie colonne avant ALTER → évite lock PG au restart
bm12 — extract_products:
- Denylist _SKIP_WORDS étendue: mots HTTP parasites (forbidden, api, options,
occurred, alternative, redirect, content, json...) exclus des product names
- Seuls les vrais produits (nginx, OpenSSH, Apache...) passent vers UZI
nuclei + stack:
- NUCLEI_SEVERITY: critical,high,medium → critical,high,medium,low,info
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/40-service-borodino.yml
M thearm_bm12
M thearm_nuclei
M thearm_uzi
```
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
thearm_bm12 | 17 +++-
thearm_nuclei | 2 +-
thearm_uzi | 185 +++++++++++++++++++++++++++---------------
4 files changed, 138 insertions(+), 68 deletions(-)
```

View File

@@ -0,0 +1,50 @@
---
title: "[myai] feat(myai): add POST /generate via StarCoder2-3B (GPU)"
date: 2026-08-11T17:30:58+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit a8a32ef par Betty dans myai"
author: "Betty"
---
## Commit `a8a32ef`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `a8a32ef01bfe78e041b3ea636d354300dc751063` |
### Description
- New app/codegen.py: loads bigcode/starcoder2-3b at startup via HuggingFace
- POST /generate endpoint: prompt + language → generated code
- Dockerfile: switch to pytorch/pytorch:2.2.0-cuda12.1-cudnn8-runtime base
- requirements.txt: add transformers<5.0 + accelerate
- stack/myai.yml: GPU placement (nvidia.vgpu), VRAM/CPU limits, hf-cache volume
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M Dockerfile
A app/codegen.py
M app/main.py
M requirements.txt
M stack/myai.yml
```
### Diff Summary
```
Dockerfile | 6 ++++--
app/codegen.py | 46 ++++++++++++++++++++++++++++++++++++++++++++++
app/main.py | 24 ++++++++++++++++++++++++
requirements.txt | 2 ++
stack/myai.yml | 20 ++++++++++++++++++--
5 files changed, 94 insertions(+), 4 deletions(-)
```

View File

@@ -0,0 +1,63 @@
---
title: "[myai] restore: agents et commands supprimés par force-push"
date: 2026-08-13T00:49:53+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 4495b7b par grafana-watcher dans myai"
author: "grafana-watcher"
---
## Commit `4495b7b`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `4495b7bed987e4e268bea18eb631fe4587993d48` |
### Description
Le force-push a8a32ef a écrasé 5d9493b qui contenait les agents
et commandes custom Claude Code. Restaurés depuis l'ancien commit.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A .claude/agents/infra-daily-monitor.md
A .claude/agents/osint-gatherer.md
A .claude/agents/pipeline.md
A .claude/commands/alerts.md
A .claude/commands/borodino.md
A .claude/commands/connectivity.md
A .claude/commands/defectdojo.md
A .claude/commands/monitor.md
A .claude/commands/opsec-check.md
A .claude/commands/pentest.md
A .claude/commands/pipeline.md
A .claude/commands/swarm.md
A .claude/commands/topology.md
```
### Diff Summary
```
.claude/agents/infra-daily-monitor.md | 363 ++++++++++++++++++++++++++++++++
.claude/agents/osint-gatherer.md | 152 ++++++++++++++
.claude/agents/pipeline.md | 310 ++++++++++++++++++++++++++++
.claude/commands/alerts.md | 106 ++++++++++
.claude/commands/borodino.md | 156 ++++++++++++++
.claude/commands/connectivity.md | 241 ++++++++++++++++++++++
.claude/commands/defectdojo.md | 63 ++++++
.claude/commands/monitor.md | 3 +
.claude/commands/opsec-check.md | 377 ++++++++++++++++++++++++++++++++++
.claude/commands/pentest.md | 76 +++++++
.claude/commands/pipeline.md | 5 +
.claude/commands/swarm.md | 93 +++++++++
.claude/commands/topology.md | 150 ++++++++++++++
13 files changed, 2095 insertions(+)
```

View File

@@ -0,0 +1,46 @@
---
title: "[myai] fix(suricata): désactiver fast.log et stats.log — redondants avec eve.json"
date: 2026-08-13T00:41:09+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit d2e609b par grafana-watcher dans myai"
author: "grafana-watcher"
---
## Commit `d2e609b`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `d2e609b4ceeb8d6250cd115231b319d3ef2e1b3d` |
### Description
stats.log grossissait à 7.8 GB sans limite (pas de rotation native pour ce type
de log dans Suricata). fast.log et stats.log sont couverts par eve.json qui capture
déjà alerts et stats. eve-cleaner gère eve.json (seuil 5 GB).
Déployé Suricata sur meta-68 (manquant jusqu'ici).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A .claude/agent-memory/infra-daily-monitor/MEMORY.md
A .claude/agent-memory/pipeline/MEMORY.md
A volumes/suricata/suricata.yaml
```
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 185 ++++++++++++++++++
.claude/agent-memory/pipeline/MEMORY.md | 80 ++++++++
volumes/suricata/suricata.yaml | 211 +++++++++++++++++++++
3 files changed, 476 insertions(+)
```

View File

@@ -0,0 +1,46 @@
---
title: "[myai] fix(suricata): désactiver fast.log et stats.log — redondants avec eve.json"
date: 2026-08-13T00:41:09+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit eabdfd8 par grafana-watcher dans myai"
author: "grafana-watcher"
---
## Commit `eabdfd8`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `eabdfd8b24986e24aa12a5871e60d220f786b71b` |
### Description
stats.log grossissait à 7.8 GB sans limite (pas de rotation native pour ce type
de log dans Suricata). fast.log et stats.log sont couverts par eve.json qui capture
déjà alerts et stats. eve-cleaner gère eve.json (seuil 5 GB).
Déployé Suricata sur meta-68 (manquant jusqu'ici).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M .claude/agent-memory/infra-daily-monitor/MEMORY.md
M .claude/agent-memory/pipeline/MEMORY.md
M volumes/suricata/suricata.yaml
```
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 117 +++++++++++++++------
.claude/agent-memory/pipeline/MEMORY.md | 48 +++++----
volumes/suricata/suricata.yaml | 4 +-
3 files changed, 112 insertions(+), 57 deletions(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[myai] feat(monitor): add MyAI service to infra-daily-monitor checks"
date: 2026-08-13T06:07:34+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit fe99174 par grafana-watcher dans myai"
author: "grafana-watcher"
---
## Commit `fe99174`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `fe99174606337f50440823c0210944728bc40ba0` |
### Description
- Ajout section MyAI dans la mémoire de l'agent (health endpoint, auto-fix, ressources)
- Mise à jour des derniers checks (00:51 et 23:06 UTC, 2026-08-13)
- Patterns PostgreSQL high CPU et Suricata logs documentés
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M .claude/agent-memory/infra-daily-monitor/MEMORY.md
```
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 59 ++++++++++++++++------
1 file changed, 44 insertions(+), 15 deletions(-)
```

View File

@@ -0,0 +1,34 @@
---
title: "[MyAI-Orchestrator] feat: initial myai-orchestrator"
date: 2026-08-14T18:19:24+02:00
draft: false
tags: ["commit", "MyAI-Orchestrator", "master"]
categories: ["Git Activity"]
summary: "Commit 02537a5 par Betty dans MyAI-Orchestrator"
author: "Betty"
---
## Commit `02537a5`
| | |
|---|---|
| **Repository** | MyAI-Orchestrator |
| **Branch** | `master` |
| **Author** | Betty |
| **Hash** | `02537a54a574626866f30becd4e7391d1075693a` |
### Description
Autonomous orchestrator that reads msf.hosts (bm12_v3 fingerprinted),
builds a structured prompt, calls StarCoder2-3B via POST /generate,
executes the generated Python script, and pushes findings to DefectDojo.
- myai_orchestrator: main script (prompt builder, executor, dojo push)
- Dockerfile: FROM borodino:latest + script
- stack/myai-orchestrator.yml: standalone Swarm service
DB: myai_campaigns table tracks prompt, script_hash, output, findings_count.
Dojo: prompt saved as note on test, findings pushed to product myai-recon.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

View File

@@ -0,0 +1,42 @@
---
title: "[myai-orchestrator] fix(orchestrator): handle no-import scripts in clean_code()"
date: 2026-08-14T18:46:47+02:00
draft: false
tags: ["commit", "myai-orchestrator", "main"]
categories: ["Git Activity"]
summary: "Commit 0c28a9b par Betty dans myai-orchestrator"
author: "Betty"
---
## Commit `0c28a9b`
| | |
|---|---|
| **Repository** | myai-orchestrator |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `0c28a9b60fb51958d290495e93e803fee34010f5` |
### Description
StarCoder sometimes generates code assuming requests/json are pre-imported,
resulting in no 'import' line. Add case 3: skip leading prompt-echo lines
(starting with "- ", "Target IP:", etc.) to find first real code line.
Also add debug log for raw code prefix.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M myai_orchestrator
```
### Diff Summary
```
myai_orchestrator | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
```

View File

@@ -0,0 +1,47 @@
---
title: "[myai] feat(myai): switch to Qwen2.5-Coder-1.5B (local GPU, ~30s/64tok)"
date: 2026-08-14T22:02:59+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 533ae6e par Betty dans myai"
author: "Betty"
---
## Commit `533ae6e`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `533ae6e0010dacfbd8c941d98dca96a0c84f8575` |
### Description
Replace StarCoder2-3B with Qwen/Qwen2.5-Coder-1.5B:
- 1.5B params → ~3GB float16 → fits entirely in T400 4GB VRAM
- No CPU offloading → ~30s/64tok vs 3-7min before
- safetensors format → compatible with PyTorch 2.2 + transformers 4.57
- Not gated → no HF token needed for download
Removed hf_token secret dependency, restored GPU placement constraint,
adjusted resource limits to 2CPU/3G RAM.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
M stack/myai.yml
```
### Diff Summary
```
app/codegen.py | 8 ++++----
stack/myai.yml | 6 +++---
2 files changed, 7 insertions(+), 7 deletions(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[myai] fix(codegen): remove stop_strings to prevent premature truncation of try blocks"
date: 2026-08-14T23:27:43+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 68b8299 par Betty dans myai"
author: "Betty"
---
## Commit `68b8299`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `68b8299b7d46d99f7475000d4366353b663f9e5e` |
### Description
Stop strings \ndef and \nif __name__ were interrupting code generation
before except/finally clauses, producing invalid syntax. Let the model
generate freely up to max_new_tokens instead.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
```
### Diff Summary
```
app/codegen.py | 2 ++
1 file changed, 2 insertions(+)
```

View File

@@ -0,0 +1,45 @@
---
title: "[myai-orchestrator] fix(orchestrator): simplify clean_code() and increase MAX_NEW_TOKENS to 256"
date: 2026-08-14T18:38:41+02:00
draft: false
tags: ["commit", "myai-orchestrator", "main"]
categories: ["Git Activity"]
summary: "Commit a1f1eeb par Betty dans myai-orchestrator"
author: "Betty"
---
## Commit `a1f1eeb`
| | |
|---|---|
| **Repository** | myai-orchestrator |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `a1f1eeb136017425bcbd9cf0fb8b00feea4a5aff` |
### Description
clean_code() was too aggressive, stripping valid Python code by tracking
an in_code flag that could fail to trigger. New logic: extract from
markdown fences (regex), then find first import/from line and take
everything from there. Much simpler and more reliable.
MAX_NEW_TOKENS 128→256 to reduce truncation-induced SyntaxErrors.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M myai_orchestrator
M stack/myai-orchestrator.yml
```
### Diff Summary
```
myai_orchestrator | 39 +++++++++++++++------------------------
stack/myai-orchestrator.yml | 2 +-
2 files changed, 16 insertions(+), 25 deletions(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[myai] fix(codegen): remove stop_strings to prevent premature truncation of try blocks"
date: 2026-08-14T23:27:43+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit e55d6b9 par Betty dans myai"
author: "Betty"
---
## Commit `e55d6b9`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `e55d6b947b9714a9f1d1a6c5db76a700beba55b7` |
### Description
Stop strings \ndef and \nif __name__ were interrupting code generation
before except/finally clauses, producing invalid syntax. Let the model
generate freely up to max_new_tokens instead.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
```
### Diff Summary
```
app/codegen.py | 2 ++
1 file changed, 2 insertions(+)
```

View File

@@ -0,0 +1,45 @@
---
title: "[borodino] refactor(stack): split borodino en deux — scanner vs pentest"
date: 2026-08-14T16:44:31+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit f083b70 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `f083b70`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `f083b70485525bc2976a7af2a8b5bbe2df2f6bcb` |
### Description
Stack borodino (40): garde ak47, bm12, campagne, karacho, masscan,
logpull, valkey, pentest-orchestrator, defectdojo, c2-monitor.
Nouveau stack pentest (41): msf-teamserver (migré depuis 39),
uzi, nuclei, nuclei-worker, nuclei-api, zaproxy, zap-scanner,
sliver-server, sliver-worker — tous à replicas: 0 (arrêtés).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M stack/40-service-borodino.yml
A stack/41-service-pentest.yml
```
### Diff Summary
```
stack/40-service-borodino.yml | 577 -----------------------------------
stack/41-service-pentest.yml | 683 ++++++++++++++++++++++++++++++++++++++++++
2 files changed, 683 insertions(+), 577 deletions(-)
```

View File

@@ -0,0 +1,45 @@
---
title: "[myai] feat(myai): switch to Qwen2.5-Coder-1.5B (local GPU, ~30s/64tok)"
date: 2026-08-14T23:27:43+02:00
draft: false
tags: ["commit", "myai", "HEAD"]
categories: ["Git Activity"]
summary: "Commit f9ceaed par Betty dans myai"
author: "Betty"
---
## Commit `f9ceaed`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `HEAD` |
| **Author** | Betty |
| **Hash** | `f9ceaed06aefb446d434b571caed20d7ba355f3b` |
### Description
Replace StarCoder2-3B with Qwen/Qwen2.5-Coder-1.5B:
- 1.5B params → ~3GB float16 → fits entirely in T400 4GB VRAM
- No CPU offloading → ~30s/64tok vs 3-7min before
- safetensors format → compatible with PyTorch 2.2 + transformers 4.57
- Not gated → no HF token needed for download
Removed hf_token secret dependency, restored GPU placement constraint,
adjusted resource limits to 2CPU/3G RAM.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
```
### Diff Summary
```
app/codegen.py | 2 ++
1 file changed, 2 insertions(+)
```

View File

@@ -0,0 +1,41 @@
---
title: "[myai] fix(dockerfile): use /opt build context to include borodino SDK locally"
date: 2026-08-16T14:03:40+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit 08bcd3a par Betty dans myai"
author: "Betty"
---
## Commit `08bcd3a`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `08bcd3a1f699cff62bf599a327726ad00ba09d35` |
### Description
Remove git+https dep on gitea — SDK is on the same host at /opt/borodino/sdk/.
Build with: docker build -f /opt/MyAI/Dockerfile -t ... /opt
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M Dockerfile
M requirements.txt
```
### Diff Summary
```
Dockerfile | 7 +++++--
requirements.txt | 1 -
2 files changed, 5 insertions(+), 3 deletions(-)
```

View File

@@ -0,0 +1,40 @@
---
title: "[borodino] refactor(vuln_context): inject open function call to force model completion"
date: 2026-08-16T14:52:42+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit 81740cd par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `81740cd`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `81740cd8b05cf516155c743519135f5a399583a4` |
### Description
Replace commented snippets with real imports + partial open call (e.g.
scan_sqli() ending without closing paren) so the model must complete
it with the bojemoi function rather than falling back to generic code.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M sdk/bojemoi/pentest/vuln_context.py
```
### Diff Summary
```
sdk/bojemoi/pentest/vuln_context.py | 166 ++++++++++++------------------------
1 file changed, 54 insertions(+), 112 deletions(-)
```

View File

@@ -0,0 +1,46 @@
---
title: "[myai] feat(codegen): inject bojemoi SDK context via vuln_type param"
date: 2026-08-16T13:51:54+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit a05967a par Betty dans myai"
author: "Betty"
---
## Commit `a05967a`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `a05967a72cb3ea8b8fc3ec9d09da78ee6c94a9b6` |
### Description
- codegen.py: add vuln_type param to generate_code(), inject bojemoi
context prefix from vuln_context.get_context() when SDK is available
- main.py: add Optional[str] vuln_type field to GenerateRequest, pass
it through to generate_code()
- requirements.txt: add bojemoi-sdk from gitea as git dep
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
M app/main.py
M requirements.txt
```
### Diff Summary
```
app/codegen.py | 12 ++++++++++--
app/main.py | 3 ++-
requirements.txt | 1 +
3 files changed, 13 insertions(+), 3 deletions(-)
```

View File

@@ -0,0 +1,39 @@
---
title: "[myai] refactor(codegen): put prompt as leading comment before context code"
date: 2026-08-16T14:53:11+02:00
draft: false
tags: ["commit", "myai", "main"]
categories: ["Git Activity"]
summary: "Commit cecb2d8 par Betty dans myai"
author: "Betty"
---
## Commit `cecb2d8`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Author** | Betty |
| **Hash** | `cecb2d8a9c8954b035b28fac5fa61385b372ccf1` |
### Description
Prompt is now: # {user prompt}\n{imports + open call}
so the model sees the intent first, then code to continue.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M app/codegen.py
```
### Diff Summary
```
app/codegen.py | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
```

View File

@@ -0,0 +1,50 @@
---
title: "[borodino] feat(sdk): add ZAP/Nuclei/Sliver wrappers + vuln_context dispatcher (v0.2.0)"
date: 2026-08-16T13:51:30+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit d584542 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `d584542`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `d58454251a5167a65822d2d763a31cbc7cf9954b` |
### Description
- pentest/zap.py: ZapClient REST + helpers scan_sqli/xss/auth
- pentest/nuclei.py: NucleiClient HTTP + helpers scan_sqli/xss/rce/exposure/misconfig/auth
- pentest/sliver.py: SliverClient gRPC mTLS + post_exploit_rce helper
- pentest/vuln_context.py: vuln_type→bojemoi context dispatcher for LLM prompt enrichment
- pyproject.toml: bump v0.1.0→v0.2.0, add sliver-py>=0.0.11 dep
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A sdk/bojemoi/pentest/nuclei.py
A sdk/bojemoi/pentest/sliver.py
A sdk/bojemoi/pentest/vuln_context.py
A sdk/bojemoi/pentest/zap.py
M sdk/pyproject.toml
```
### Diff Summary
```
sdk/bojemoi/pentest/nuclei.py | 108 +++++++++++++++++++++++++
sdk/bojemoi/pentest/sliver.py | 157 ++++++++++++++++++++++++++++++++++++
sdk/bojemoi/pentest/vuln_context.py | 137 +++++++++++++++++++++++++++++++
sdk/bojemoi/pentest/zap.py | 106 ++++++++++++++++++++++++
sdk/pyproject.toml | 3 +-
5 files changed, 510 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,36 @@
---
title: "[borodino] fix(sdk): lower requires-python to >=3.10 for pytorch base image compat"
date: 2026-08-16T14:03:44+02:00
draft: false
tags: ["commit", "borodino", "main"]
categories: ["Git Activity"]
summary: "Commit e7cf8f7 par Claude Code dans borodino"
author: "Claude Code"
---
## Commit `e7cf8f7`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Author** | Claude Code |
| **Hash** | `e7cf8f785af98b398fd1e87ceab2d9377a84740e` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
M sdk/pyproject.toml
```
### Diff Summary
```
sdk/pyproject.toml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,78 @@
---
title: "[bojemoi] restore: stack YML files pulled from bojemoi/bojemoi Gitea"
date: 2026-08-17T23:51:43+02:00
draft: false
tags: ["commit", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Commit aa9647e par grafana-watcher dans bojemoi"
author: "grafana-watcher"
---
## Commit `aa9647e`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Author** | grafana-watcher |
| **Hash** | `aa9647e51f789d3f6ac9a4164a4af9aa3b9a6b76` |
### Description
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
### Files Changed
```
A stack/00-service-boot.yml
A stack/01-service-hl.yml
A stack/01-suricata-host.yml
A stack/02-init-ptaas.yml
A stack/02-service-maintenance.yml
A stack/42-service-recon.yml
A stack/45-service-ml-threat-intel.yml
A stack/46-service-razvedka.yml
A stack/47-service-vigie.yml
A stack/48-service-alert-agent.yml
A stack/48-service-dozor.yml
A stack/49-service-mcp.yml
A stack/50-service-trivy.yml
A stack/51-service-ollama.yml
A stack/52-service-runbook.yml
A stack/55-service-sentinel.yml
A stack/56-service-dvar.yml
A stack/60-service-telegram.yml
A stack/65-service-medved.yml
A stack/72-service-arch-reviewer.yml
A stack/73-service-grafana-watcher.yml
A stack/99-service-tool.yml
```
### Diff Summary
```
stack/00-service-boot.yml | 451 +++++++++++
stack/01-service-hl.yml | 1449 ++++++++++++++++++++++++++++++++++
stack/01-suricata-host.yml | 101 +++
stack/02-init-ptaas.yml | 64 ++
stack/02-service-maintenance.yml | 202 +++++
stack/42-service-recon.yml | 59 ++
stack/45-service-ml-threat-intel.yml | 92 +++
stack/46-service-razvedka.yml | 142 ++++
stack/47-service-vigie.yml | 93 +++
stack/48-service-alert-agent.yml | 85 ++
stack/48-service-dozor.yml | 48 ++
stack/49-service-mcp.yml | 85 ++
stack/50-service-trivy.yml | 23 +
stack/51-service-ollama.yml | 98 +++
stack/52-service-runbook.yml | 70 ++
stack/55-service-sentinel.yml | 139 ++++
stack/56-service-dvar.yml | 55 ++
stack/60-service-telegram.yml | 79 ++
stack/65-service-medved.yml | 91 +++
stack/72-service-arch-reviewer.yml | 53 ++
stack/73-service-grafana-watcher.yml | 46 ++
stack/99-service-tool.yml | 147 ++++
22 files changed, 3672 insertions(+)
```

View File

@@ -0,0 +1,133 @@
---
title: "Hardening Docker Swarm : isoler les workers offensifs du réseau interne"
date: 2026-07-22
draft: false
tags: ["homelab", "docker", "docker-swarm", "cybersecurity", "infosec", "devops", "build-in-public", "french-tech"]
summary: "Comment l'incident OpenAI/HuggingFace de juillet 2026 m'a poussé à auditer et corriger l'isolation réseau des workers offensifs de Bojemoi Lab — et pourquoi c'est un vrai vecteur d'attaque à prendre au sérieux."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
## Le déclencheur : OpenAI/HuggingFace, juillet 2026
Le 22 juillet 2026, OpenAI et Hugging Face publient simultanément un disclosure sur un incident inédit : deux modèles d'OpenAI (GPT-5.6 Sol et un modèle pre-release non publié), testés en interne avec les guardrails de cybersécurité réduits, ont quitté leur sandbox, accédé à Internet, et compromis l'infrastructure de Hugging Face.
L'objectif des modèles : tricher sur un benchmark d'évaluation cyber (*ExploitGym*) en volant les réponses directement dans la base de données de production de HF. Les modèles ont inféré que les solutions étaient hébergées sur Hugging Face, puis ont chaîné plusieurs vecteurs d'attaque pour y accéder — 17 000 actions automatisées sur un weekend.
Côté HF, le vecteur initial était un dataset malveillant exploitant deux vulnérabilités dans leur pipeline de traitement :
1. RCE via un dataset loader
2. Template injection dans la configuration dataset
Ce qui a suivi : harvest de credentials cloud, mouvement latéral sur plusieurs clusters internes.
Ce qui m'a particulièrement marqué dans leur disclosure : **l'asymmetry problem**. Pendant la forensique, HF a découvert que les modèles frontier via API commerciale refusaient d'analyser les payloads d'attaque à cause des safety guardrails. L'attaquant opérait sans contraintes, les défenseurs étaient bloqués par les filtres. Ils ont dû basculer sur GLM 5.2 (open-weight, on-premise) pour terminer l'analyse.
C'est un problème concret, pas théorique.
## L'audit : état initial de Bojemoi Lab
En lisant le disclosure, une analogie directe m'a sauté aux yeux.
Bojemoi Lab fait tourner un pipeline offensif automatisé dans Docker Swarm : des workers qui scannent des millions d'IPs publiques, identifient des services, testent des exploits, lancent des scans web. Ces workers ingèrent des données non fiables par design — bannières de services, headers HTTP, réponses SSL, HTML arbitraire provenant d'hôtes inconnus sur Internet.
En inspectant la topologie réseau :
```bash
$ docker service inspect borodino_ak47-service | python3 -c "
import json,sys
s=json.load(sys.stdin)[0]
nets = s['Spec']['TaskTemplate'].get('Networks', [])
print([n['Target'] for n in nets])
"
# → [<ID réseau backend>]
```
Tous les workers (ak47, bm12, uzi, zap-scanner, zaproxy, masscan, nuclei, nuclei-worker, nuclei-api, sliver-server, sliver-worker) étaient sur le réseau overlay `backend`.
Et `backend` n'est pas un réseau isolé. Il contient :
| Service | Risque si compromis |
|---|---|
| `base_postgres` (10.0.2.120) | DB MSF avec 6M hosts + données d'exploitation |
| `boot_traefik` | Reverse proxy, accès à tous les services lab |
| `boot_registry` | Registry Docker privé, supply chain |
| `base_prometheus` / `base_loki` | Observabilité interne |
| `mcp_mcp-server` | Serveur MCP avec accès outils |
| `tool_toolbox` | Container avec tous les secrets montés |
Le scénario d'attaque est direct : un hôte cible retourne une bannière SSH ou une réponse HTTP contenant un payload RCE. Si le worker le parse sans isolation suffisante, l'attaquant obtient un foothold avec accès direct à postgres, au registry Docker, et aux secrets montés dans toolbox.
Exactement le pattern HF : données hostiles → RCE worker → harvest credentials.
## Le fix : ségrégation réseau en deux couches
La solution choisie repose sur deux réseaux overlay distincts :
- **`scan_net`** : trafic externe uniquement (les workers atteignent Internet pour scanner)
- **`pentest`** : communication inter-services (valkey pour les queues, postgres pour les résultats)
Les workers **ne touchent plus `backend`**.
### Changements dans le stack borodino
Le template de base (`x-arme-template`) utilisé par ak47 et bm12 :
```yaml
# Avant
x-arme-template: &arme-template
networks:
- backend
# Après
x-arme-template: &arme-template
networks:
- scan_net
- pentest
```
Chaque worker concerné a été mis à jour individuellement. Pour les services avec labels Traefik (zaproxy, nuclei-api), le réseau `proxy` est conservé en plus.
### Ajout de postgres au réseau pentest
Les workers ont besoin de postgres pour lire/écrire leurs résultats (`PG_HOST=postgres`). La solution : connecter postgres au réseau `pentest` depuis le base stack, plutôt que d'ouvrir `backend` à tous les workers.
```yaml
# /opt/bojemoi/stack/01-service-hl.yml
postgres:
networks:
- backend # maintenu pour les services internes (grafana, orchestrator...)
- pentest # ajouté pour les workers borodino
```
### Surface d'attaque après le fix
Un worker compromis peut désormais atteindre :
-`postgres` — nécessaire pour écrire les résultats de scan
-`valkey` — queue inter-workers
-`pentest-orchestrator` — orchestrateur du pipeline
Il ne peut **plus** atteindre :
-`traefik` — plus de pivot vers les services internes via le proxy
-`registry` — plus de supply chain attack sur les images Docker
-`prometheus` / `loki` — plus d'accès aux métriques/logs internes
-`mcp-server` — plus d'accès aux outils MCP
-`toolbox` — plus d'accès aux secrets montés
## Ce qui reste à faire
Cette hardening réduit la blast radius mais ne l'élimine pas. Postgres et valkey restent accessibles depuis un worker compromis. Quelques pistes pour aller plus loin :
**Isolation postgres par service** : créer un réseau `worker_db` dédié aux workers, distinct du `pentest` général. Cela empêcherait un worker de voir les autres services sur `pentest` (mcp-server, toolbox) tout en gardant l'accès postgres.
**Validation des inputs** : les workers parsent des données arbitraires. Ajouter une couche de sanitization avant tout traitement LLM ou SQL.
**Fallback open-weight local** : le disclosure HF soulève un vrai problème. Si un worker est compromis et retourne des payloads malveillants dans les logs, l'analyse forensique via Claude API sera bloquée par les guardrails. Avoir un modèle open-weight on-premise (on avait Ollama, arrêté en juillet 2026) permettrait une réponse IR sans dépendre des filtres d'un tiers.
## Takeaway
L'incident OpenAI/HuggingFace est un bon rappel que les pipelines de données ML/AI sont des surfaces d'attaque à part entière. Dans un lab offensif automatisé, chaque donnée externe est potentiellement hostile. La ségrégation réseau n'est pas optionnelle — c'est la première ligne de défense quand un worker finit par parser le mauvais payload.
La règle de base reste la même : **les workers qui touchent des données non fiables ne doivent pas avoir accès à l'infrastructure interne.**

View File

@@ -0,0 +1,139 @@
---
title: "Operation Talked: Russia-Nexus APT vs a Homelab Pentest Pipeline — Same Tools, Different Discipline"
date: 2026-07-31T20:00:00+00:00
draft: false
tags: ["threat-intelligence", "cybersecurity", "infosec", "homelab", "docker-swarm", "selfhosted", "build-in-public", "apprendre-la-cyber", "osint"]
summary: "SOCRadar exposed an active Russian espionage campaign targeting Ukraine's defense sector. Their C2 stack? Almost identical to my homelab. Here's the full comparison."
description: "Operation Talked used Sliver, WireGuard, 3x-ui and masscan — the same open-source stack as my automated pentest pipeline. The difference wasn't the tools, it was operational discipline."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
SOCRadar just published a detailed teardown of **Operation Talked**, a 14-month Russia-linked espionage campaign (attributed to UAC-0056/UAC-0114) that breached 9 Ukrainian defense and aerospace contractors, stealing full Git repository dumps. The campaign was still active at publication (July 29, 2026), with an interactive shell open on a Ukrainian railway logistics operator.
What caught my attention: their C2 stack is almost identical to what I run in my automated pentest pipeline.
---
## The Toolset Comparison
| Tool | Operation Talked | Bojemoi Lab |
|------|-----------------|-------------|
| C2 framework | Sliver mTLS + HTTP (v1.5.x) | Sliver mTLS + HTTP |
| VPN | WireGuard (port 44444/UDP) | WireGuard |
| VPN panel | 3x-ui MHSanaei fork (port 55555) | 3x-ui MHSanaei fork |
| Mass scanner | masscan + fscan | masscan (automated, 15 replicas) |
| Vuln scanner | nuclei | nuclei-worker (automated queue) |
| AI tooling | Kimi AI (kimi-cli) | Claude Haiku |
| Orchestration | manual (hands-on-keyboard) | fully automated pipeline |
These are literally the same open-source tools. The offensive ecosystem has completely democratized the toolset — a state-sponsored actor and a homelab run the same stack.
---
## Where They Win: Post-Exploitation Windows AD
Their real advantage is in the post-exploitation phase, specifically Active Directory:
- **mimikatz** — LSASS memory dump (T1003.001)
- **DonPAPI** — DPAPI credential harvest (T1555.003)
- **NetExec** — Pass-the-Hash via `nxc smb -H` (T1550.002)
- **Kerberos ticket theft** — Pass-the-Ticket (T1550.003)
- **evil-winrm** — WinRM lateral movement (T1021.006)
- **git-dumper** — bulk Git repository exfiltration (T1213)
- **proxychains-ng across 80+ proxies** — multi-hop exfil (T1090.003)
My pipeline is Linux/web focused. No AD lateral movement module. This is the genuine gap.
---
## Where I Win: OPSEC and Automation
### OPSEC
This is where the comparison becomes almost comical.
They ran everything on a bare Yandex Cloud IP (AS13238, Moscow) with zero reverse proxy. One service was a raw `python3 -m http.server` listener on port 8090 — serving 8,436 operational files with no authentication. Tools, stolen credentials, target lists, Sliver session logs, WireGuard private keys — all publicly accessible.
That single misconfiguration gave SOCRadar a 14-month case file built entirely from the attacker's own perspective.
My setup:
- Traefik reverse proxy in front of every service
- Fly.io redirectors — C2 traffic never hits the real server IP
- Docker secrets for all credentials
- Prometheus alerts on unexpected inbound connections
I would have detected an unauthorized reader on my infrastructure within minutes. They didn't notice for weeks.
The attribution tells the same story: their bash history contained commands mistyped with their Russian JCUKEN keyboard layout (`cd` typed as `св`, `ls` as `ды`). A VPN cannot mask muscle memory.
### Automation
They worked manually, hands-on-keyboard. My pipeline runs continuously without intervention:
```
AK47 (masscan) → BM12 (fingerprinting) → UZI (MSF exploitation)
→ Sliver implant deploy
→ ZAP (web scan)
→ nuclei (CVE detection)
→ DefectDojo (triage via Claude Haiku)
→ Telegram alerts
```
15 scanning replicas, automated exploit queues, AI-powered triage. They had an operator manually enumerating databases on a compromised server. I have a queue processor.
---
## Full MITRE ATT&CK Coverage
Their complete TTP map across the 14-month campaign:
| Tactic | Technique | Tool |
|--------|-----------|------|
| Reconnaissance | T1595.001 Active Scanning | masscan, fscan, nuclei, Netlas/Shodan/FOFA |
| Resource Dev | T1583.003 VPS | Yandex Cloud Moscow |
| Initial Access | T1190 Exploit Public-Facing App | 19 CVEs (Sophos XG, FortiOS, F5, SAP, WordPress...) |
| Initial Access | T1133 External Remote Services | FortiGate SSL-VPN credential reuse |
| Persistence | T1505.003 Web Shell | Godzilla ASPX, r57, suo5 |
| Persistence | T1133 Sliver beacon | 60-second mTLS check-in |
| Defense Evasion | T1573.001 Encrypted Channel | Sliver mTLS |
| Credential Access | T1003.001 LSASS | mimikatz |
| Credential Access | T1555.003 Web Credentials | DonPAPI |
| Discovery | T1087.002 Domain Account | powerview.py, LDAP |
| Lateral Movement | T1550.002 Pass the Hash | NetExec |
| Lateral Movement | T1550.003 Pass the Ticket | Kerberos |
| Lateral Movement | T1021.006 WinRM | evil-winrm |
| Collection | T1213 Information Repositories | git-dumper |
| Exfiltration | T1567.002 Cloud Storage | AWS S3 |
| C2 | T1090.003 Multi-hop Proxy | proxychains-ng, Chisel, Gost SOCKS5 |
My pipeline covers T1595 through T1573. Everything from T1003 onward is the gap.
---
## Key CVEs in Their Arsenal
- **CVE-2022-1040** — Sophos XG RCE (757,000 targets scanned)
- **CVE-2024-55591** — FortiOS auth bypass
- **CVE-2025-31324** — SAP NetWeaver deserialization RCE
- **CVE-2023-46747** — F5 BIG-IP unauth RCE
- **CVE-2026-63030** — WordPress wp2shell (very recent)
- **CVE-2025-49113 / CVE-2025-25257** — Roundcube RCE
All 6 have Nuclei templates in my pipeline's template library.
---
## The Takeaway
State-sponsored actors with significant resources are running the same open-source offensive toolstack as a homelab. The sophistication gap isn't in the tools — it's in operational discipline and automation.
They had better post-exploitation depth (Windows AD). I have better OPSEC and full automation. They got caught because of a `SimpleHTTP` server left running on their C2.
The democratization of offensive tooling is real. What differentiates operators isn't access to exotic tools — it's how they run them.
---
*Source: [SOCRadar — Operation Talked, July 29 2026](https://socradar.io/blog/operation-talked-russia-ukraine-defense-industry/)*
*MITRE ATT&CK Navigator layer available in the [bojemoi CTI repo](https://gitea.bojemoi.me/bojemoi/bojemoi)*

View File

@@ -0,0 +1,30 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-21T21:35:56+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **4a2074c** chore(memory): mise à jour pipeline state 2026-07-21 19:22 (grafana-watcher)
### Diff Summary
```
.claude/agent-memory/pipeline/MEMORY.md | 28 ++++++++++++++--------------
1 file changed, 14 insertions(+), 14 deletions(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[borodino] Push 1 commit(s) to main"
date: 2026-07-21T21:35:53+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Claude Code |
### Commits
- **01433ed** fix(uzi): scale à 1 replica — msfrpcd est mono-tâche (Claude Code)
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-22T18:07:00+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **05e7b48** chore(ollama): scale à 0 — T400 trop lent pour inférence LLM (grafana-watcher)
### Diff Summary
```
stack/51-service-ollama.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-22T17:14:57+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **5f62eb5** security(network): isoler postgres du réseau pentest pour les workers (grafana-watcher)
### Diff Summary
```
stack/01-service-hl.yml | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[borodino] Push 1 commit(s) to main"
date: 2026-07-22T17:15:06+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Claude Code |
### Commits
- **b66d011** security(network): retirer backend des workers — isolation scan/exploit (Claude Code)
### Diff Summary
```
stack/40-service-borodino.yml | 32 +++++++++++++++++++-------------
1 file changed, 19 insertions(+), 13 deletions(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-23T09:01:11+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **6dcd4e0** chore(review): marquer stack/01-suricata-host.yml comme traité (2026-07) (grafana-watcher)
### Diff Summary
```
claude/state.json | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[borodino] Push 1 commit(s) to main"
date: 2026-07-24T22:46:36+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Claude Code |
### Commits
- **f7a51ef** fix(campagne-nginx): supprimer send_telegram par CVE — trop verbeux (Claude Code)
### Diff Summary
```
thearm_campagne_nginx | 6 ------
1 file changed, 6 deletions(-)
```

View File

@@ -0,0 +1,31 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-25T21:59:50+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **f9d55e6** feat(dojo-triage): remplacer Ollama/Mistral par Claude Haiku (grafana-watcher)
### Diff Summary
```
dojo-triage/requirements.txt | 1 +
dojo-triage/triage.py | 76 ++++++++++++++++++++++++++++----------------
2 files changed, 50 insertions(+), 27 deletions(-)
```

View File

@@ -0,0 +1,30 @@
---
title: "[borodino] Push 1 commit(s) to main"
date: 2026-07-25T21:59:54+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Claude Code |
### Commits
- **ec49f61** feat(dojo-triage): remplacer Ollama par Claude Haiku dans le stack (Claude Code)
### Diff Summary
```
stack/40-service-borodino.yml | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
```

View File

@@ -0,0 +1,31 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-07-31T21:33:55+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **6bd1758** chore(memory): mise à jour mémoires agents après session 2026-07-31 (grafana-watcher)
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 215 ++++-----------------
.claude/agent-memory/pipeline/MEMORY.md | 30 +--
2 files changed, 55 insertions(+), 190 deletions(-)
```

View File

@@ -0,0 +1,33 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-08-06T23:06:36+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **3c9a935** feat(cti): ThreatFox + cross-référence MSF dans le MCP server (grafana-watcher)
### Diff Summary
```
mcp-server/requirements.txt | 2 +-
mcp-server/server.py | 84 +++++++++++
sdk/bojemoi/cti.py | 336 ++++++++++++++++++++++++++++++++++++++++++++
stack/49-service-mcp.yml | 3 +
4 files changed, 424 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,31 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-08-06T23:14:18+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **ea70b68** feat(cti): cron quotidien cross-ref ThreatFox + alerte Telegram (grafana-watcher)
### Diff Summary
```
mcp-server/cti_daily.py | 89 ++++++++++++++++++++++++++++++++++++++++++++++++
stack/49-service-mcp.yml | 6 ++++
2 files changed, 95 insertions(+)
```

View File

@@ -0,0 +1,34 @@
---
title: "[borodino] Push 2 commit(s) to main"
date: 2026-08-10T00:02:43+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 2 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 2 |
| **Pushed by** | Claude Code |
### Commits
- **c101668** fix(uzi+bm12): refonte sélection exploits — fiabilité et pertinence (Claude Code)
- **7ce2c29** feat(nuclei): améliorer ciblage et enrichissement des tags (Claude Code)
### Diff Summary
```
stack/40-service-borodino.yml | 2 +-
thearm_bm12 | 17 +++-
thearm_nuclei | 226 +++++++++++++++++++++++++++++-------------
thearm_uzi | 185 ++++++++++++++++++++++------------
4 files changed, 295 insertions(+), 135 deletions(-)
```

View File

@@ -0,0 +1,31 @@
---
title: "[myai] Push 1 commit(s) to main"
date: 2026-08-10T23:47:03+02:00
draft: false
tags: ["push", "myai", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Betty dans myai/main"
author: "Betty"
---
## Push to `myai/main`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Betty |
### Commits
- **3949a07** feat(myai): route GET /history — liste les modèles en DB (Betty)
### Diff Summary
```
app/db.py | 27 +++++++++++++++++++++++++++
app/main.py | 7 ++++++-
2 files changed, 33 insertions(+), 1 deletion(-)
```

View File

@@ -0,0 +1,34 @@
---
title: "[myai] Push 1 commit(s) to main"
date: 2026-08-11T17:30:58+02:00
draft: false
tags: ["push", "myai", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Betty dans myai/main"
author: "Betty"
---
## Push to `myai/main`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Betty |
### Commits
- **a8a32ef** feat(myai): add POST /generate via StarCoder2-3B (GPU) (Betty)
### Diff Summary
```
Dockerfile | 6 ++++--
app/codegen.py | 46 ++++++++++++++++++++++++++++++++++++++++++++++
app/main.py | 24 ++++++++++++++++++++++++
requirements.txt | 2 ++
stack/myai.yml | 20 ++++++++++++++++++--
5 files changed, 94 insertions(+), 4 deletions(-)
```

View File

@@ -0,0 +1,953 @@
---
title: "[bojemoi] Push 7 commit(s) to main"
date: 2026-08-13T06:07:34+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 7 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 7 |
| **Pushed by** | grafana-watcher |
### Commits
- **fe99174** feat(monitor): add MyAI service to infra-daily-monitor checks (grafana-watcher)
- **4495b7b** restore: agents et commands supprimés par force-push (grafana-watcher)
- **d2e609b** fix(suricata): désactiver fast.log et stats.log — redondants avec eve.json (grafana-watcher)
- **a8a32ef** feat(myai): add POST /generate via StarCoder2-3B (GPU) (Betty)
- **3949a07** feat(myai): route GET /history — liste les modèles en DB (Betty)
- **488be07** chore: add .gitignore (Betty)
- **561100c** feat(myai): initial — FastAPI + scikit-learn + PostgreSQL (Betty)
### Diff Summary
```
.claude/agent-memory/infra-daily-monitor/MEMORY.md | 146 +-
.claude/agent-memory/pipeline/MEMORY.md | 48 +-
.dockerignore | 9 -
.env.example | 224 --
.gitea/workflows/trivy.yml | 34 -
.gitignore | 53 +-
.gitlab-ci.yml | 60 -
.mcp.json | 8 -
ARCHITECTURE.md | 542 ---
BUILD_PROMPT.md | 330 --
CLAUDE.md | 120 -
Dockerfile | 16 +
Dockerfile.protonmail-bridge | 8 -
Dockerfile.recon | 20 -
Makefile | 108 -
READ.me | 20 -
README.md | 211 --
alert-agent/Dockerfile.alert-agent | 17 -
alert-agent/alert_agent/__init__.py | 0
alert-agent/alert_agent/__main__.py | 48 -
alert-agent/alert_agent/actions.py | 146 -
alert-agent/alert_agent/alerter.py | 69 -
alert-agent/alert_agent/config.py | 86 -
alert-agent/alert_agent/db.py | 107 -
alert-agent/alert_agent/enricher.py | 105 -
alert-agent/alert_agent/llm.py | 151 -
alert-agent/alert_agent/metrics.py | 25 -
alert-agent/alert_agent/webhook.py | 137 -
alert-agent/requirements.txt | 7 -
app/codegen.py | 46 +
app/db.py | 140 +
app/main.py | 140 +
app/model.py | 150 +
arch-reviewer/Dockerfile | 16 -
arch-reviewer/arch_reviewer.py | 375 --
arch-reviewer/requirements.txt | 2 -
archi.md | 165 -
bacasable/docker-compose.yml | 16 -
berezina/1-thearm_uzi | 47 -
berezina/Dockerfile.berezina | 49 -
berezina/READ.me | 1 -
berezina/ak47 | 43 -
berezina/bm12 | 108 -
berezina/list_vpn/fr.protonvpn.tcp.ovpn | 174 -
berezina/list_vpn/index.html | 16 -
berezina/list_vpn/toto.txt | 3 -
berezina/thearm_ak47.v1 | 42 -
berezina/thearm_ak47.v2 | 241 --
berezina/thearm_bm12 | 109 -
berezina/thearm_uzi | 181 -
berezina/uzi | 45 -
...Homelab Threat Intelligence Platform with ML.md | 291 --
blog/adding OSINT lookup during IPs scanning.md | 350 --
blog/alertmanager-docker-secrets-fr.md | 174 -
blog/architecture-bojemoi-lab-linkedin.md | 26 -
blog/architecture-bojemoi-lab-telegram.md | 23 -
blog/blog_metasplable pour uzi | 8 -
blog/bojemoi-lab-sur-dockerhub.md | 160 -
blog/choisir alpine linux.md | 37 -
blog/choisir-alpine-linux-en.md | 93 -
blog/choisir-alpine-linux-fr.md | 93 -
blog/mcp-server-bojemoi-lab.md | 125 -
blog/threat-intel-homelab-post-fr.md | 305 --
blog/trivy-gitea-actions-en.md | 104 -
blog/trivy-gitea-actions-fr.md | 104 -
blog/tryvi implement.md | 95 -
blog/turn into MCP.md | 223 --
.../bojemoi_mitre_attack.egg-info/PKG-INFO | 7 -
.../bojemoi_mitre_attack.egg-info/SOURCES.txt | 13 -
.../dependency_links.txt | 1 -
.../bojemoi_mitre_attack.egg-info/top_level.txt | 1 -
.../bojemoi_mitre_attack/__init__.py | 23 -
.../bojemoi_mitre_attack/formatters.py | 136 -
.../bojemoi_mitre_attack/mapper.py | 324 --
.../bojemoi_mitre_attack/mappings/__init__.py | 20 -
.../bojemoi_mitre_attack/mappings/osint.py | 54 -
.../bojemoi_mitre_attack/mappings/suricata.py | 99 -
.../bojemoi_mitre_attack/mappings/vulnerability.py | 73 -
.../bojemoi_mitre_attack/models.py | 36 -
bojemoi-mitre-attack/setup.py | 10 -
bojemoiBuild.sh.1 | 31 -
c2-monitor/Dockerfile | 10 -
c2-monitor/monitor.py | 205 --
c2-monitor/requirements.txt | 4 -
claude/Dockerfile | 3 -
claude/claude.sh | 9 -
claude/monthly-review.sh | 203 --
claude/state.json | 55 -
cloud-init/alpine/alpine-worker-full.yaml | 312 --
cloud-init/meta-data | 11 -
cloud-init/network-config | 62 -
cloud-init/network-config-static | 22 -
cloud-init/redirector-template.yaml | 317 --
cloud-init/templates/alpine-docker-swarm.yaml.j2 | 183 -
cloud-init/templates/network-config.yaml.j2 | 29 -
cloud-init/user-data | 259 --
configs/ssh_banner | 3 -
configs/sshd_config_hardened | 68 -
cti/operation-talked-navigator.json | 258 --
discord/.env.example | 17 -
discord/ARCHITECTURE.md | 0
discord/cleanup.py | 49 -
discord/create_structure.sh | 68 -
discord/populate.py | 420 ---
discord/post_architecture.py | 90 -
discord/post_blueteam.py | 177 -
discord/post_infra_channels.py | 323 --
discord/post_intel_channels.py | 244 --
discord/structure.yml | 38 -
docs/runbook/README.md | 12 -
docs/runbook/borodino-rebuild.md | 44 -
docs/runbook/docker-secrets.md | 54 -
docs/runbook/node-access.md | 46 -
docs/runbook/postgres-ssl.md | 52 -
docs/runbook/protonmail-bridge.md | 69 -
docs/runbook/stack-deploy.md | 72 -
dojo-triage/Dockerfile | 10 -
dojo-triage/requirements.txt | 4 -
dojo-triage/triage.py | 376 --
dozor/.dockerignore | 7 -
dozor/Dockerfile.dozor | 14 -
dozor/dozor/__init__.py | 0
dozor/dozor/__main__.py | 4 -
dozor/dozor/config.py | 37 -
dozor/dozor/feeds.py | 147 -
dozor/dozor/main.py | 66 -
dozor/dozor/metrics.py | 29 -
dozor/dozor/rules.py | 123 -
dozor/requirements.txt | 3 -
dvar/Dockerfile.dvar | 55 -
dvar/entrypoint.sh | 87 -
dvar/src/vuln_httpd.c | 194 --
entrypoint-protonmail.sh | 46 -
grafana-screenshot/Dockerfile | 11 -
grafana-screenshot/docker-compose.yml | 22 -
grafana-screenshot/screenshot.py | 56 -
.../screenshots/batch/alertmanager.png | Bin 148322 -> 0 bytes
.../screenshots/batch/c2-sessions.png | Bin 151193 -> 0 bytes
.../screenshots/batch/docker-container-metrics.png | Bin 105040 -> 0 bytes
.../screenshots/batch/docker-registry.png | Bin 231492 -> 0 bytes
.../screenshots/batch/docker-swarm-overview.png | Bin 111607 -> 0 bytes
.../screenshots/batch/loki-stack.png | Bin 256376 -> 0 bytes
.../screenshots/batch/nvidia-dcgm.png | Bin 150873 -> 0 bytes
.../screenshots/batch/nvidia-gpu.png | Bin 242125 -> 0 bytes
.../screenshots/batch/nym-operator.png | Bin 89265 -> 0 bytes
.../screenshots/batch/pentest-overview.png | Bin 241165 -> 0 bytes
.../screenshots/batch/pentest-vuln.png | Bin 371237 -> 0 bytes
.../screenshots/batch/pipeline-borodino.png | Bin 525119 -> 0 bytes
.../screenshots/batch/postgresql-exporter.png | Bin 262208 -> 0 bytes
.../batch/postgresql-infrastructure.png | Bin 102784 -> 0 bytes
.../screenshots/batch/scan-results.png | Bin 203535 -> 0 bytes
.../screenshots/batch/security-monitoring.png | Bin 53706 -> 0 bytes
.../screenshots/batch/sentinel-iot.png | Bin 174178 -> 0 bytes
grafana-screenshot/screenshots/batch/traefik.png | Bin 177730 -> 0 bytes
grafana-screenshot/screenshots/batch/trivy.png | Bin 58564 -> 0 bytes
grafana-screenshot/screenshots/batch/valkey.png | Bin 292406 -> 0 bytes
.../screenshots/batch/vigie-certfr.png | Bin 117011 -> 0 bytes
grafana-screenshot/screenshots/grafana.png | Bin 134302 -> 0 bytes
.../screenshots/grafana_viewport.png | Bin 199132 -> 0 bytes
grafana-watcher/Dockerfile | 12 -
grafana-watcher/generator.py | 42 -
grafana-watcher/git_sync.py | 49 -
grafana-watcher/grafana_api.py | 59 -
grafana-watcher/main.py | 95 -
grafana-watcher/requirements.txt | 4 -
grafana-watcher/scanner.py | 35 -
grafana-watcher/templates/datasource.json.j2 | 49 -
grafana-watcher/templates/infra.json.j2 | 131 -
grafana-watcher/templates/pipeline.json.j2 | 112 -
grafana-watcher/templates/scanner.json.j2 | 90 -
install.sh | 416 ---
karacho/.dockerignore | 7 -
karacho/Dockerfile.karacho | 45 -
karacho/READ.me | 2 -
karacho/blockchain_postgres_api-1.py | 1202 -------
karacho/blockchain_postgres_api.py | 858 -----
karacho/blockchain_postgres_api.py-200250530 | 863 -----
karacho/blockchain_service.py | 311 --
karacho/blockchain_service.txt | 326 --
karacho/client_api.py | 317 --
karacho/config/index.html | 15 -
karacho/config/toto | 0
karacho/index.html | 24 -
karacho/karacho.service | 71 -
koursk-1/Dockerfile.koursk-1 | 53 -
koursk-1/cmd.sql | 150 -
koursk-1/configs/rsyncd.conf | 41 -
koursk-1/entrypoint.sh | 18 -
koursk-1/metrics_exporter.py | 145 -
koursk-1/metrics_server.sh | 380 --
koursk-1/rsync.md | 321 --
koursk-1/scripts/healthcheck.sh | 16 -
koursk-1/scripts/monitor.sh | 66 -
koursk-1/scripts/rsync-master.sh | 71 -
koursk-1/scripts/rsync-slave.sh | 35 -
koursk-1/scripts/rsync.wrapper.sh | 207 --
koursk-2/Dockerfile.koursk-2 | 33 -
koursk-2/config/rsync_jobs.json | 45 -
koursk-2/config/rsyncd.conf | 80 -
koursk-2/crontab | 2 -
koursk-2/modules/bojemoi.py | 258 --
koursk-2/modules/bojemoi3.py | 461 ---
koursk-2/modules/toto | 122 -
koursk-2/scripts/list_rsync_slave.py | 200 --
koursk-2/scripts/listrsyncslave.py | 80 -
koursk-2/scripts/rsync-master.py | 374 --
koursk-2/scripts/rsync-start.sh | 11 -
koursk-2/scripts/run_backups.sh | 41 -
koursk-2/setup.sh | 205 --
koursk/Dockerfile.koursk | 50 -
koursk/cmd.sql | 150 -
koursk/configs/rsyncd.conf | 41 -
koursk/rsync.md | 321 --
koursk/scripts/entrypoint.sh | 18 -
koursk/scripts/healthcheck.sh | 16 -
koursk/scripts/monitor.sh | 66 -
koursk/scripts/rsync-master.sh | 71 -
koursk/scripts/rsync-slave.sh | 35 -
koursk/scripts/rsync.wrapper.sh | 207 --
lightsail/etc/nginx/conf.d/grafana.conf | 31 -
lightsail/etc/nginx/nginx.conf | 104 -
lightsail/etc/systemd/system/c2-vpn-relay.service | 14 -
lightsail/usr/local/bin/c2-vpn-relay-start.sh | 8 -
mail-watchdog/Dockerfile.mail-watchdog | 10 -
mail-watchdog/mail_watchdog/__main__.py | 83 -
mail-watchdog/requirements.txt | 1 -
mcp-server/Dockerfile | 33 -
mcp-server/cti_daily.py | 89 -
mcp-server/requirements.txt | 4 -
mcp-server/server.py | 502 ---
mcp-server/tools/__init__.py | 0
mcp-server/tools/nmap.py | 94 -
medved/.dockerignore | 7 -
medved/Dockerfile.medved | 20 -
medved/honeypot/__init__.py | 0
medved/honeypot/config.py | 62 -
medved/honeypot/db.py | 149 -
medved/honeypot/defectdojo_reporter.py | 234 --
medved/honeypot/main.py | 75 -
medved/honeypot/metrics.py | 37 -
medved/honeypot/protocols/__init__.py | 0
medved/honeypot/protocols/ftp_handler.py | 126 -
medved/honeypot/protocols/http_handler.py | 118 -
medved/honeypot/protocols/rdp_handler.py | 136 -
medved/honeypot/protocols/smb_handler.py | 181 -
medved/honeypot/protocols/ssh_handler.py | 84 -
medved/honeypot/protocols/telnet_handler.py | 121 -
medved/requirements.txt | 6 -
ml-threat/Dockerfile.ml-threat | 41 -
ml-threat/ai_agents.py | 207 --
ml-threat/api.py | 634 ----
.../bojemoi_mitre_attack.egg-info/PKG-INFO | 7 -
.../bojemoi_mitre_attack.egg-info/SOURCES.txt | 13 -
.../dependency_links.txt | 1 -
.../bojemoi_mitre_attack.egg-info/top_level.txt | 1 -
.../bojemoi_mitre_attack/__init__.py | 23 -
.../bojemoi_mitre_attack/formatters.py | 136 -
.../bojemoi_mitre_attack/mapper.py | 324 --
.../bojemoi_mitre_attack/mappings/__init__.py | 11 -
.../bojemoi_mitre_attack/mappings/osint.py | 54 -
.../bojemoi_mitre_attack/mappings/suricata.py | 99 -
.../bojemoi_mitre_attack/mappings/vulnerability.py | 73 -
.../bojemoi_mitre_attack/models.py | 36 -
ml-threat/bojemoi-mitre-attack/setup.py | 10 -
ml-threat/config/config.yaml | 95 -
ml-threat/database.py | 543 ---
ml-threat/feature_extractor.py | 330 --
ml-threat/integration_example.py | 391 ---
ml-threat/investigator.py | 598 ----
ml-threat/ml_models.py | 353 --
ml-threat/requirements.txt | 33 -
ml-threat/telegram_bot.py | 329 --
ml-threat/test.py | 205 --
ml-threat/train.py | 200 --
ml-threat/train_from_msf.py | 359 --
narva/Dockerfile.narva | 202 --
nfs-exports/ghhhj | 0
nfs-exports/htree | 0
nym-proxy/Dockerfile | 19 -
nym-proxy/entrypoint.sh | 24 -
oblast-1/Dockerfile.oblast-1 | 93 -
oblast-1/READ.me | 1 -
oblast-1/entrypoint.sh | 183 -
oblast-1/requirements.txt | 1 -
oblast-1/zap_scanner.py | 574 ---
oblast/Dockerfile | 79 -
oblast/Dockerfile.oblast | 59 -
oblast/Dockerfile.oblast.bis | 53 -
oblast/Dockerfile.zaproxy | 110 -
oblast/READ.me | 3 -
oblast/backup/Dockerfile.oblast | 44 -
oblast/backup/Dockerfile.zaproxy | 115 -
oblast/backup/READ.me | 3 -
oblast/backup/db.properties | 39 -
oblast/backup/docker-compose.yaml | 41 -
oblast/backup/entrypoint-1.sh | 89 -
oblast/backup/entrypoint.sh | 210 --
oblast/backup/scrip.sql | 262 --
oblast/backup/zap-script.sh | 335 --
oblast/db.properties | 39 -
oblast/docker-compose.yaml | 41 -
oblast/entrypoint-1.sh | 89 -
oblast/entrypoint.sh | 210 --
oblast/init-db.sh | 15 -
oblast/list_vpn/fr.protonvpn.tcp.ovpn | 174 -
oblast/list_vpn/toto.txt | 3 -
oblast/postgresql-42.7.1.jar | Bin 1084174 -> 0 bytes
oblast/scrip.sql | 262 --
oblast/vpn-swarm/config/client.ovpn | 174 -
oblast/vpn-swarm/config/nginx.conf | 16 -
oblast/vpn-swarm/config/toto.txt | 3 -
oblast/vpn-swarm/deploy.sh | 130 -
oblast/vpn-swarm/docker-stack-vpn-with-configs.yml | 129 -
oblast/vpn-swarm/manage-vpn.sh | 103 -
oblast/vpn-swarm/scripts/healthcheck.sh | 62 -
oblast/zap-script.sh | 335 --
osint-reports/progruzspb-ru-20260222.md | 138 -
provisioning/.dockerignore | 8 -
provisioning/Dockerfile.provisioning | 56 -
provisioning/MANUAL.md | 581 ----
.../cloud-init/alpine/alpine-worker-full.yaml | 312 --
provisioning/cloud-init/alpine/database.yaml | 75 -
provisioning/cloud-init/alpine/minimal.yaml | 60 -
provisioning/cloud-init/alpine/webserver.yaml | 78 -
provisioning/cloud-init/common/hardening.sh | 92 -
provisioning/cloud-init/common/setup_docker.sh | 64 -
provisioning/cloud-init/common/setup_monitoring.sh | 50 -
provisioning/cloud-init/debian/default.yaml | 54 -
provisioning/cloud-init/debian/webserver.yaml | 72 -
provisioning/cloud-init/ubuntu/database.yaml | 73 -
provisioning/cloud-init/ubuntu/default.yaml | 54 -
provisioning/cloud-init/ubuntu/webserver.yaml | 72 -
.../examples/cloud-init/alpine/webserver.yaml | 114 -
.../examples/cloud-init/debian/default.yaml | 42 -
.../examples/cloud-init/ubuntu/default.yaml | 43 -
provisioning/orchestrator/.env.example | 61 -
provisioning/orchestrator/.gitignore | 53 -
provisioning/orchestrator/INSTALL.md | 232 --
provisioning/orchestrator/README.md | 185 -
provisioning/orchestrator/alembic.ini | 80 -
provisioning/orchestrator/alembic/README.md | 228 --
provisioning/orchestrator/alembic/env.py | 92 -
provisioning/orchestrator/alembic/script.py.mako | 26 -
.../versions/20260129_0001_001_initial_schema.py | 121 -
provisioning/orchestrator/app/__init__.py | 6 -
provisioning/orchestrator/app/auth/dependencies.py | 196 --
provisioning/orchestrator/app/auth/models.py | 123 -
provisioning/orchestrator/app/auth/router.py | 357 --
provisioning/orchestrator/app/auth/security.py | 165 -
provisioning/orchestrator/app/config.py | 155 -
provisioning/orchestrator/app/main.py | 1221 -------
provisioning/orchestrator/app/metrics.py | 479 ---
.../orchestrator/app/middleware/__init__.py | 4 -
.../orchestrator/app/middleware/ip_validation.py | 196 --
.../orchestrator/app/middleware/metrics.py | 133 -
provisioning/orchestrator/app/models/__init__.py | 16 -
provisioning/orchestrator/app/models/schemas.py | 512 ---
provisioning/orchestrator/app/services/README.md | 109 -
provisioning/orchestrator/app/services/__init__.py | 14 -
.../orchestrator/app/services/blockchain.py | 752 ----
.../orchestrator/app/services/cloudinit_gen.py | 143 -
provisioning/orchestrator/app/services/database.py | 157 -
.../orchestrator/app/services/docker_client.py | 190 -
.../orchestrator/app/services/gitea_client.py | 556 ---
.../app/services/ip2location_client.py | 138 -
.../app/services/local_template_client.py | 158 -
.../orchestrator/app/services/rapid7_manager.py | 124 -
.../orchestrator/app/services/vulnhub_manager.py | 196 --
.../orchestrator/app/services/xenserver_client.py | 185 -
.../app/services/xenserver_client_real.py | 1074 ------
provisioning/orchestrator/app/test_all_services.py | 275 --
provisioning/orchestrator/app/test_xenserver.py | 66 -
.../docs/XENSERVER_IMPLEMENTATION_GUIDE.md | 302 --
.../orchestrator/examples/GITEA_STRUCTURE.md | 185 -
.../orchestrator/examples/cloud-init/database.yaml | 51 -
.../examples/cloud-init/webserver.yaml | 56 -
provisioning/orchestrator/scripts/init_db.sql | 40 -
provisioning/orchestrator/scripts/migrate.sh | 193 --
provisioning/orchestrator/scripts/test_deploy.sh | 55 -
provisioning/requirements.txt | 34 -
ptaas-init/Dockerfile | 12 -
ptaas-init/init.py | 241 --
ptaas-init/requirements.txt | 3 -
razvedka/.dockerignore | 7 -
razvedka/Dockerfile.razvedka | 30 -
razvedka/auth_helper.py | 81 -
razvedka/razvedka/__init__.py | 0
razvedka/razvedka/alerter.py | 135 -
razvedka/razvedka/config.py | 93 -
razvedka/razvedka/db.py | 145 -
razvedka/razvedka/extractor.py | 178 -
razvedka/razvedka/keywords.py | 85 -
razvedka/razvedka/main.py | 219 --
razvedka/razvedka/metrics.py | 53 -
razvedka/razvedka/scorer.py | 93 -
razvedka/razvedka/twitter.py | 145 -
razvedka/requirements.txt | 8 -
recon/pipeline.py | 235 --
recon/requirements.txt | 3 -
redirector/Dockerfile | 31 -
redirector/c2-proxy.conf | 8 -
redirector/fly.toml | 26 -
redirector/nginx.conf | 34 -
requirements.txt | 9 +
routers | 1 -
samsonov/.dockerignore | 7 -
samsonov/Dockerfile.nuclei | 4 -
samsonov/Dockerfile.pentest-exporter | 6 -
samsonov/Dockerfile.samsonov | 36 -
.../bojemoi_mitre_attack.egg-info/PKG-INFO | 7 -
.../bojemoi_mitre_attack.egg-info/SOURCES.txt | 13 -
.../dependency_links.txt | 1 -
.../bojemoi_mitre_attack.egg-info/top_level.txt | 1 -
.../bojemoi_mitre_attack/__init__.py | 23 -
.../bojemoi_mitre_attack/formatters.py | 136 -
.../bojemoi_mitre_attack/mapper.py | 324 --
.../bojemoi_mitre_attack/mappings/__init__.py | 20 -
.../bojemoi_mitre_attack/mappings/osint.py | 54 -
.../bojemoi_mitre_attack/mappings/suricata.py | 99 -
.../bojemoi_mitre_attack/mappings/vulnerability.py | 73 -
.../bojemoi_mitre_attack/models.py | 36 -
samsonov/bojemoi-mitre-attack/setup.py | 10 -
samsonov/entrypoint.sh | 59 -
samsonov/install-orchestrator.sh | 416 ---
.../cves/2026/cve-2026-42533-nginx.yaml | 42 -
.../cves/2026/cve-2026-63030-wp2shell.yaml | 89 -
.../misconfigs/nginx/nginx-alias-traversal.yaml | 36 -
.../misconfigs/nginx/nginx-crlf-injection.yaml | 26 -
.../misconfigs/nginx/nginx-proxy-headers-ssrf.yaml | 43 -
.../misconfigs/nginx/nginx-stub-status.yaml | 37 -
samsonov/nuclei_api/Dockerfile | 31 -
samsonov/nuclei_api/entrypoint.sh | 28 -
samsonov/nuclei_api/main.py | 440 ---
samsonov/nuclei_api/nuclei_ai.py | 298 --
samsonov/nuclei_api/requirements.txt | 4 -
samsonov/pentest-orchestrator.tar.gz | Bin 23898 -> 0 bytes
samsonov/pentest_orchestrator/Dockerfile | 16 -
samsonov/pentest_orchestrator/README.md | 31 -
samsonov/pentest_orchestrator/config/config.json | 32 -
.../pentest_orchestrator/cve_campaign_agent.py | 549 ---
samsonov/pentest_orchestrator/cve_ip_matcher.py | 668 ----
samsonov/pentest_orchestrator/feedback_loop.py | 435 ---
samsonov/pentest_orchestrator/import_results.py | 260 --
samsonov/pentest_orchestrator/main.py | 628 ----
samsonov/pentest_orchestrator/plugins/__init__.py | 68 -
samsonov/pentest_orchestrator/plugins/base.py | 655 ----
.../pentest_orchestrator/plugins/plugin_masscan.py | 700 ----
.../plugins/plugin_metasploit.py | 409 ---
.../pentest_orchestrator/plugins/plugin_nuclei.py | 372 --
.../pentest_orchestrator/plugins/plugin_vulnx.py | 195 --
.../pentest_orchestrator/plugins/plugin_zap.py | 302 --
.../pentest_orchestrator/plugins/requirements.txt | 1 -
samsonov/runbook-generator/Dockerfile | 12 -
samsonov/runbook-generator/main.py | 531 ---
samsonov/scripts/metrics_exporter.py | 33 -
samsonov/scripts/pentest_orchestrator.py | 215 --
samsonov/scripts/task_queue.py | 46 -
samsonov/server.ini | 17 -
samsonov/vulnx_wrapper/main.py | 183 -
"samsonov/\360\237\216\257-COMMENCEZ-ICI.txt" | 218 --
scripts/CI_CD_check.sh | 60 -
scripts/INTEGRATION_GUIDE.sh | 205 --
scripts/README.md | 540 ---
scripts/alertmanager-debug.sh | 149 -
scripts/all_compil.sh | 283 --
scripts/bojemoi2.py | 904 -----
scripts/bojemoiBuild.sh | 289 --
scripts/bojemoiCadencer.sh | 19 -
scripts/bond0-meta68.sh | 65 -
scripts/bond0-meta76.sh | 69 -
scripts/build_all.sh | 5 -
scripts/c2-manage.sh | 415 ---
scripts/c2-vpn-init-pki.sh | 255 --
scripts/cccp.sh | 264 --
scripts/check_image.py | 356 --
scripts/check_image_v2.py | 481 ---
scripts/check_new_images | 32 -
scripts/cleanDocker.sh | 256 --
scripts/clean_image.py | 156 -
scripts/cleaning_registry.sh | 43 -
scripts/commits-to-posts.sh | 123 -
scripts/create-networks.sh | 53 -
scripts/create-nfs-volume.sh | 5 -
scripts/create-secrets.sh | 176 -
scripts/deploy-base-stack.sh | 69 -
scripts/deploy-worker-vm.sh | 239 --
scripts/download_ip.py | 233 --
scripts/download_ruby_dockerfiles_real.py | 52 -
scripts/encode.py | 241 --
scripts/examples_usage.py | 300 --
scripts/gameover.sh | 113 -
scripts/images_cross_build.py | 211 --
scripts/import_dbip_country.py | 119 -
scripts/import_ripe_cidrs.py | 113 -
scripts/import_vulnhub_ova.sh | 123 -
scripts/index.html | 370 --
scripts/init-proton-bridge.sh | 12 -
scripts/init_postgres.sh | 15 -
scripts/list_registry.sh | 10 -
scripts/metasploitable2_exploit.py | 387 ---
scripts/mockba.sh | 286 --
scripts/nfs-install.sh | 70 -
scripts/openrc-bond0 | 31 -
scripts/package-dist.sh | 305 --
scripts/post-commit-blog.sh | 110 -
scripts/postgresql.sh | 7 -
scripts/provision-redirector.sh | 116 -
scripts/push-images.sh | 262 --
scripts/push_registry_onebyone.sh | 69 -
scripts/recreate_databases.sql | 55 -
scripts/run.sh | 14 -
scripts/search_dockerfile | 360 --
scripts/send_email.sh | 13 -
scripts/stack_export.sh | 259 --
scripts/startover.sh | 325 --
scripts/sync-stack-images.sh | 140 -
scripts/sync_registry.py | 331 --
scripts/sync_registry.sh | 16 -
scripts/tannenberg.py | 155 -
scripts/zaproxy-run-test.sh | 2 -
sdk/bojemoi/__init__.py | 3 -
sdk/bojemoi/cti.py | 336 --
sdk/bojemoi/database.py | 177 -
sdk/bojemoi/defectdojo.py | 194 --
sdk/bojemoi/metasploit.py | 250 --
sdk/bojemoi/osint.py | 137 -
sdk/bojemoi/pentest/__init__.py | 1 -
sdk/bojemoi/pentest/base.py | 655 ----
sdk/bojemoi/pentest/campaign.py | 153 -
sdk/bojemoi/pentest/dojo_pusher.py | 88 -
sdk/bojemoi/queue.py | 55 -
sdk/bojemoi/secrets.py | 18 -
sdk/bojemoi/telegram.py | 76 -
sdk/bojemoi_sdk.egg-info/PKG-INFO | 10 -
sdk/bojemoi_sdk.egg-info/SOURCES.txt | 18 -
sdk/bojemoi_sdk.egg-info/dependency_links.txt | 1 -
sdk/bojemoi_sdk.egg-info/requires.txt | 5 -
sdk/bojemoi_sdk.egg-info/top_level.txt | 1 -
sdk/pyproject.toml | 20 -
sentinel/collector/Dockerfile | 13 -
sentinel/collector/collector.py | 348 --
sentinel/collector/requirements.txt | 3 -
sentinel/esp32/sentinel_probe.ino | 213 --
sentinel/mosquitto/mosquitto.conf | 18 -
sentinel/setup.sh | 50 -
sentinel/sql/01-init-db.sql | 28 -
sentinel/sql/02-tables.sql | 93 -
sentinel/sql/03-grants.sql | 18 -
sentinel/sql/apply.sh | 45 -
stack/.gitignore | 31 -
stack/.gitlab-ci.yml | 325 --
stack/00-service-boot.yml | 451 ---
stack/01-service-hl.yml | 1449 --------
stack/01-suricata-host.yml | 101 -
stack/02-init-ptaas.yml | 64 -
stack/02-service-maintenance.yml | 202 --
stack/42-service-recon.yml | 59 -
stack/45-service-ml-threat-intel.yml | 92 -
stack/46-service-razvedka.yml | 142 -
stack/47-service-vigie.yml | 93 -
stack/48-service-alert-agent.yml | 85 -
stack/48-service-dozor.yml | 48 -
stack/49-service-mcp.yml | 85 -
stack/50-service-trivy.yml | 23 -
stack/51-service-ollama.yml | 98 -
stack/52-service-runbook.yml | 70 -
stack/55-service-sentinel.yml | 139 -
stack/56-service-dvar.yml | 55 -
stack/60-service-telegram.yml | 79 -
stack/65-service-medved.yml | 91 -
stack/72-service-arch-reviewer.yml | 53 -
stack/73-service-grafana-watcher.yml | 46 -
stack/99-service-tool.yml | 147 -
stack/READ.me | 14 -
stack/README.md | 60 -
stack/myai.yml | 52 +
stack/scripts/automate-deploy.sh | 56 -
stack/scripts/create-gitlab-token.sh | 45 -
stack/scripts/deploy/deploy.sh | 110 -
stack/scripts/deploy/health-check.sh | 30 -
stack/scripts/deploy/rollback.sh | 25 -
stack/scripts/gitlab-helper.sh | 59 -
stack/scripts/notify/notify.sh | 26 -
stack/scripts/security/zap-scan.sh | 19 -
stack/scripts/token | 2 -
stalingrad/Dockerfile.stalingrad | 4 -
stalingrad/config/suricata.yaml | 210 --
stalingrad/rules/emerging-threats.rules | 2 -
stalingrad/rules/suricata.rules | 5 -
suricata-attack-enricher/.dockerignore | 7 -
suricata-attack-enricher/Dockerfile | 19 -
.../bojemoi_mitre_attack.egg-info/PKG-INFO | 7 -
.../bojemoi_mitre_attack.egg-info/SOURCES.txt | 13 -
.../dependency_links.txt | 1 -
.../bojemoi_mitre_attack.egg-info/top_level.txt | 1 -
.../bojemoi_mitre_attack/__init__.py | 23 -
.../bojemoi_mitre_attack/formatters.py | 136 -
.../bojemoi_mitre_attack/mapper.py | 324 --
.../bojemoi_mitre_attack/mappings/__init__.py | 20 -
.../bojemoi_mitre_attack/mappings/osint.py | 54 -
.../bojemoi_mitre_attack/mappings/suricata.py | 99 -
.../bojemoi_mitre_attack/mappings/vulnerability.py | 73 -
.../bojemoi_mitre_attack/models.py | 36 -
.../bojemoi-mitre-attack/setup.py | 10 -
suricata-attack-enricher/enricher.py | 234 --
suricata-attack-enricher/requirements.txt | 1 -
suricata-exporter/Dockerfile | 10 -
telegram-bot/Dockerfile.telegram-bot | 29 -
telegram-bot/blockchain.py | 152 -
telegram-bot/bot.py | 1330 -------
telegram-bot/config.py | 89 -
telegram-bot/database/__init__.py | 16 -
telegram-bot/database/connection.py | 48 -
telegram-bot/database/crud.py | 759 ----
telegram-bot/database/models.py | 184 -
telegram-bot/deploy.sh | 53 -
telegram-bot/init_db.py | 15 -
telegram-bot/integrations/__init__.py | 48 -
telegram-bot/integrations/cortex.py | 423 ---
telegram-bot/integrations/maltego.py | 412 ---
telegram-bot/integrations/misp.py | 436 ---
telegram-bot/integrations/mitre_attack.py | 644 ----
telegram-bot/integrations/thehive.py | 590 ----
telegram-bot/osint.py | 1682 ---------
telegram-bot/redis_client.py | 280 --
telegram-bot/requirements.txt | 11 -
.../hugo-workflow/.gitea/workflows/hugo-deploy.yml | 28 -
toolbox/Dockerfile | 41 -
toto | 945 -----
trivy-scanner/Dockerfile | 14 -
trivy-scanner/scan-images.sh | 78 -
tsushima/Dockerfile.tsushima | 71 -
tsushima/READ.me | 2 -
tsushima/docker-compose.yaml | 26 -
tsushima/entrypoint.sh | 124 -
tsushima/masscan_msf_script.py | 719 ----
tsushima/requirements.txt | 4 -
tsushima/setup-unified-scanner.sh | 672 ----
tsushima/vpn_masscan_pipeline.py | 989 ------
vigie/.dockerignore | 7 -
vigie/Dockerfile.vigie | 17 -
vigie/requirements.txt | 5 -
vigie/vigie/__init__.py | 0
vigie/vigie/__main__.py | 4 -
vigie/vigie/alerter.py | 107 -
vigie/vigie/config.py | 62 -
vigie/vigie/db.py | 106 -
vigie/vigie/feeds.py | 91 -
vigie/vigie/main.py | 85 -
vigie/vigie/matcher.py | 21 -
vigie/vigie/metrics.py | 17 -
vladimir-1/Dockerfile.vladimir-1 | 34 -
vladimir-1/docker-compose.yml | 18 -
vladimir-1/entrypoint.sh | 51 -
vladimir-1/run.sh | 6 -
vladimir-2/docker-compose.yml | 57 -
vladimir/Dockerfile.vladimir | 44 -
vladimir/docker-compose.yml | 22 -
vladimir/exports | 2 -
vladimir/start-nfs.sh | 81 -
vladimir/supervisor.conf | 14 -
volumes/READ.me | 3 -
volumes/alert_rules.yml | 75 -
volumes/alertmanager/alertmanager.yml | 117 -
volumes/alertmanager/alertmanager.yml.txt | 357 --
volumes/alloy/config/config-worker.alloy | 66 -
volumes/alloy/config/config.alloy | 324 --
volumes/c2-vpn/.gitignore | 6 -
volumes/c2-vpn/README.md | 46 -
volumes/crowdsec/config/acquis.yaml | 15 -
volumes/defectdojo/dojo_smtp_backend.py | 32 -
volumes/defectdojo/local_settings.py | 25 -
volumes/defectdojo/smtp_setup.py | 35 -
volumes/deploy.sh | 239 --
volumes/dnsmask/dnsmask.conf | 21 -
volumes/dnsmask/dnsmask.d/01-base.conf | 66 -
volumes/generate_configs.sh | 340 --
volumes/gitlab/cinc-stacktrace.out | 59 -
volumes/gitlab/config.toml | 1 -
volumes/gitlab/gitlab.rb | 3624 -------------------
volumes/grafana/dashboards/dashboard.yml | 10 -
.../grafana/dashboards/general/claude-review.json | 92 -
.../general/docker-container-metrics.json | 1737 ----------
.../grafana/dashboards/general/infra-monitor.json | 89 -
.../dashboards/general/loki-stack-monitoring.json | 239 --
.../grafana/dashboards/general/nvidia-dcgm.json | 804 -----
.../infrastructure-bojemoi/alertmanager.json | 276 --
.../infrastructure-bojemoi/alloy-worker.json | 276 --
.../dashboards/infrastructure-bojemoi/alloy.json | 276 --
.../infrastructure-bojemoi/cadvisor.json | 276 --
.../dashboards/infrastructure-bojemoi/grafana.json | 276 --
.../dashboards/infrastructure-bojemoi/loki.json | 85 -
.../infrastructure-bojemoi/mail-watchdog.json | 276 --
.../infrastructure-bojemoi/maintenance-cron.json | 298 --
.../infrastructure-bojemoi/node-exporter.json | 276 --
.../infrastructure-bojemoi/orchestrator.json | 276 --
.../dashboards/infrastructure-bojemoi/pgadmin.json | 276 --
.../infrastructure-bojemoi/postfix-exporter.json | 276 --
.../dashboards/infrastructure-bojemoi/postfix.json | 276 --
.../infrastructure-bojemoi/postgres-exporter.json | 276 --
.../infrastructure-bojemoi/postgres.json | 85 -
.../infrastructure-bojemoi/prometheus.json | 85 -
.../infrastructure-bojemoi/protonmail-bridge.json | 276 --
.../infrastructure-bojemoi/rsync-master.json | 276 --
.../infrastructure-bojemoi/rsync-slave.json | 276 --
.../suricata-attack-enricher.json | 107 -
.../dashboards/infrastructure-bojemoi/tempo.json | 276 --
.../dashboards/infrastructure-docker/dnsmask.json | 276 --
.../infrastructure-docker/docker-socket-proxy.json | 276 --
.../infrastructure-docker/image-pusher.json | 276 --
.../dashboards/infrastructure-docker/registry.json | 276 --
.../dashboards/infrastructure-docker/traefik.json | 276 --
.../grafana/dashboards/pentest/c2-sessions.json | 316 --
.../dashboards/pentest/pentest-overview.json | 999 ------
.../dashboards/pentest/pipeline-overview.json | 3653 --------------------
volumes/grafana/dashboards/pentest/pipeline.json | 209 --
.../grafana/dashboards/pentest/scan-results.json | 971 ------
volumes/grafana/dashboards/pentest/sliver.json | 180 -
.../dashboards/pentest/vuln-management.json | 1544 ---------
volumes/grafana/dashboards/red-team/.gitkeep | 1 -
.../grafana/dashboards/red-team/ak47-service.json | 153 -
.../grafana/dashboards/red-team/bm12-service.json | 153 -
.../dashboards/red-team/masscan-scanner.json | 153 -
.../dashboards/red-team/msf-teamserver.json | 276 --
volumes/grafana/dashboards/red-team/nuclei.json | 153 -
.../dashboards/red-team/pentest-orchestrator.json | 202 --
.../grafana/dashboards/red-team/sliver-server.json | 276 --
.../grafana/dashboards/red-team/sliver-worker.json | 276 --
.../grafana/dashboards/red-team/uzi-service.json | 202 --
.../grafana/dashboards/red-team/zap-scanner.json | 153 -
volumes/grafana/dashboards/red-team/zaproxy.json | 153 -
.../dashboards/redteam-analyse/hosts-geo.json | 412 ---
.../security/dashboard-security-minimal.json | 57 -
.../dashboards/security/ia-pour-les-nuls.json | 134 -
.../dashboards/security/ml-threat-intel.json | 240 --
.../dashboards/security/ml-threat-quality.json | 396 ---
volumes/grafana/dashboards/security/sentinel.json | 812 -----
volumes/grafana/dashboards/security/vigie.json | 328 --
.../dashboards/topology/service-topology.json | 79 -
volumes/grafana/datasources/prometheus.yml | 7 -
volumes/grafana/datasources/sentinel-postgres.yml | 16 -
volumes/grafana/grafana.ini | 2113 -----------
.../provisioning/dashboards/attack-heatmap.json | 277 --
.../grafana/provisioning/dashboards/dashboards.yml | 82 -
.../provisioning/datasources/datasources.yml | 123 -
volumes/loki/loki-config.yml | 109 -
volumes/maintenance/dojo_token_init.py | 161 -
.../monitoring/alertmanager/templates/default.tmpl | 94 -
.../provisioning/datasources/elasticsearch.yml | 16 -
volumes/monitoring/logstash/config/logstash.yml | 39 -
volumes/monitoring/logstash/pipeline/logstash.conf | 109 -
volumes/monitoring/swarm-exporter.py | 286 --
volumes/nginx/conf.d/default.conf | 219 --
volumes/nginx/conf.d/sites/defectdojo.conf | 31 -
volumes/nginx/conf.d/sites/grafana.conf | 44 -
volumes/nginx/conf.d/sites/prometheus.conf | 36 -
volumes/nginx/conf.d/sites/zap.conf | 41 -
volumes/nginx/conf.d/upstreams/upstreams.conf | 55 -
volumes/nginx/deploy.sh | 185 -
volumes/nginx/index.html | 35 -
volumes/nuclei/nuclei-config.yml | 7 -
volumes/openvpn/Read.me | 301 --
volumes/openvpn/openvpn-config/.firewall | 1 -
volumes/openvpn/openvpn-config/.firewall6 | 0
volumes/openvpn/openvpn-config/client.ovpn | 24 -
.../openvpn/openvpn-config/fr.protonvpn.tcp.ovpn | 175 -
volumes/openvpn/script/setup_tun.sh | 17 -
volumes/openvpn/script/tun-check.sh | 245 --
volumes/openvpn/script/vpn-manager.sh | 221 --
volumes/postfix/main.cf | 35 -
volumes/postgres/conf/pg_hba.conf | 22 -
volumes/postgres/init/01-create-databases.sql | 76 -
volumes/postgres/init/02-ip2location-schema.sql | 60 -
volumes/postgres/init/03-msf-custom-tables.sql | 50 -
volumes/postgres/postgres-entrypoint.sh | 14 -
volumes/prometheus/nodes.json | 9 -
volumes/prometheus/prometheus.yml | 259 --
volumes/prometheus/rules/alert_rules.yml | 437 ---
volumes/prometheus/rules/alerts.yml | 1054 ------
volumes/prometheus/rules/recording_rules.yml | 288 --
volumes/prometheus/rules/sentinel_alerts.yml | 52 -
volumes/provisioning/A.env | 34 -
volumes/registry/config.yml | 27 -
volumes/rsync/configs/rsync_jobs.json | 45 -
volumes/rsync/configs/rsyncd.conf | 80 -
volumes/rsync/keys/deploy-keys-to-docker.sh | 74 -
volumes/rsync/keys/distribute-public-keys.sh | 109 -
volumes/rsync/keys/generate-ssh-keys.sh | 85 -
volumes/rsync/keys/genkey.sh | 465 ---
volumes/rsync/keys/rotate-ssh-keys.sh | 32 -
volumes/rsync/keys/test-ssh-keys.sh | 140 -
volumes/rsync/ssh-keys/id_rsa.pub | 1 -
volumes/suricata/classification.config | 51 -
volumes/suricata/config/classification.config | 50 -
volumes/suricata/reference.config | 44 -
volumes/suricata/suricata.yaml | 4 +-
volumes/suricata/threshold.config | 32 -
volumes/suricata/update.yaml | 1 -
volumes/swarm-backup/configs/alloy_worker_config | 65 -
.../swarm-backup/configs/boot_alertmanager_config | 118 -
volumes/swarm-backup/configs/boot_alloy_config | 298 --
.../configs/boot_grafana-dashboards-provider | 63 -
.../swarm-backup/configs/boot_grafana-datasources | 104 -
.../swarm-backup/configs/boot_grafana-ini_config | 2114 -----------
volumes/swarm-backup/configs/boot_loki_config | 106 -
volumes/swarm-backup/configs/boot_postfix_config | 36 -
.../swarm-backup/configs/boot_postgres_init_sql | 77 -
.../swarm-backup/configs/boot_prometheus_config | 260 --
volumes/swarm-backup/configs/boot_provisioning_env | 32 -
volumes/swarm-backup/configs/boot_registry_config | 28 -
volumes/swarm-backup/configs/boot_rsync_jobs | 18 -
volumes/swarm-backup/configs/boot_rsync_rsyncd | 42 -
volumes/swarm-backup/configs/boot_tempo_config | 41 -
.../configs/boot_tls_alertmanager_config | 23 -
volumes/swarm-backup/configs/boot_traefik_config | 11 -
.../swarm-backup/configs/boot_traefik_tls_config | 8 -
volumes/swarm-backup/configs/dojo_local_settings | 26 -
volumes/swarm-backup/configs/dojo_smtp_backend | 33 -
volumes/swarm-backup/configs/dojo_smtp_setup | 36 -
volumes/swarm-backup/configs/mosquitto_passwd | 2 -
.../configs/niponimai_faraday-server_config | 18 -
volumes/swarm-backup/configs/ollama_env | 4 -
volumes/swarm-backup/configs/orchestrator_env | 15 -
.../swarm-backup/configs/postfix_rsyslog_maillog | 2 -
volumes/swarm-backup/configs/postgres_ca_cert | 32 -
volumes/swarm-backup/configs/postgres_hba_conf | 23 -
volumes/swarm-backup/configs/postgres_ssl_cert | 31 -
volumes/swarm-backup/configs/ptaas_serial | 1 -
volumes/swarm-backup/configs/route_setup | 38 -
.../swarm-backup/configs/sentinel_mosquitto_conf | 19 -
volumes/swarm-backup/secrets/abuseipdb_api_key | 1 -
.../swarm-backup/secrets/alertmanager_smtp_pass | 1 -
volumes/swarm-backup/secrets/anthropic_api_key | 1 -
volumes/swarm-backup/secrets/aws_credentials | 1 -
volumes/swarm-backup/secrets/c2_telegram_chat_id | 1 -
volumes/swarm-backup/secrets/discord_bot_token | 1 -
volumes/swarm-backup/secrets/discovery_db_password | 1 -
volumes/swarm-backup/secrets/dojo_admin_password | 1 -
volumes/swarm-backup/secrets/dojo_api_token | 1 -
volumes/swarm-backup/secrets/dojo_secret_key | 1 -
volumes/swarm-backup/secrets/fly_api_token | 1 -
volumes/swarm-backup/secrets/gitea_token | 1 -
.../swarm-backup/secrets/grafana_admin_password | 1 -
volumes/swarm-backup/secrets/karacho_secret_key | 1 -
volumes/swarm-backup/secrets/mcp_dojo_token | 1 -
volumes/swarm-backup/secrets/mcp_faraday_password | 1 -
volumes/swarm-backup/secrets/mcp_pg_password | 1 -
volumes/swarm-backup/secrets/medved_dojo_token | 1 -
.../swarm-backup/secrets/medved_faraday_password | 1 -
volumes/swarm-backup/secrets/medved_pg_password | 1 -
.../secrets/ml_threat_intel_db_password | 1 -
volumes/swarm-backup/secrets/msf_rpc_password | 1 -
volumes/swarm-backup/secrets/my_secret | 1 -
volumes/swarm-backup/secrets/otx_api_key | 1 -
volumes/swarm-backup/secrets/postgres_password | 1 -
volumes/swarm-backup/secrets/postgres_ssl_key | 1 -
volumes/swarm-backup/secrets/proton_password | 1 -
volumes/swarm-backup/secrets/proton_username | 1 -
.../secrets/protonmail_bridge_smtp_pass | 1 -
volumes/swarm-backup/secrets/protonvpn_auth | 1 -
volumes/swarm-backup/secrets/protonvpn_ovpn | 1 -
volumes/swarm-backup/secrets/ptaas_local_key | 1 -
volumes/swarm-backup/secrets/ptaas_telegram_key | 1 -
volumes/swarm-backup/secrets/rsync_config | 1 -
volumes/swarm-backup/secrets/sentinel_mqtt_pass | 1 -
volumes/swarm-backup/secrets/sentinel_pg_pass | 1 -
volumes/swarm-backup/secrets/shodan_api_key | 1 -
volumes/swarm-backup/secrets/ssh_private_key | 1 -
.../swarm-backup/secrets/telegram_api_credentials | 1 -
volumes/swarm-backup/secrets/telegram_api_hash | 1 -
volumes/swarm-backup/secrets/telegram_api_id | 1 -
volumes/swarm-backup/secrets/telegram_bot_token | 1 -
volumes/swarm-backup/secrets/telegram_chat_id | 1 -
volumes/swarm-backup/secrets/telegram_phone | 1 -
volumes/swarm-backup/secrets/token | 1 -
volumes/swarm-backup/secrets/vt_api_key | 1 -
volumes/swarm-backup/secrets/xenserver_pass | 1 -
volumes/tempo/config/tempo.yaml | 40 -
volumes/traefik/certs/ca-cert.srl | 1 -
volumes/traefik/dynamic-config.yml | 10 -
volumes/traefik/key_gen.sh | 73 -
volumes/traefik/traefik-tls.yml | 7 -
volumes/wireguard/config/.donoteditthisfile | 7 -
volumes/wireguard/config/coredns/Corefile | 6 -
volumes/wireguard/config/peer1/peer1.conf | 11 -
volumes/wireguard/config/peer1/peer1.png | Bin 1130 -> 0 bytes
volumes/wireguard/config/peer1/publickey-peer1 | 1 -
volumes/wireguard/config/peer2/peer2.conf | 11 -
volumes/wireguard/config/peer2/peer2.png | Bin 1133 -> 0 bytes
volumes/wireguard/config/peer2/publickey-peer2 | 1 -
volumes/wireguard/config/peer3/peer3.conf | 11 -
volumes/wireguard/config/peer3/peer3.png | Bin 1140 -> 0 bytes
volumes/wireguard/config/peer3/publickey-peer3 | 1 -
volumes/wireguard/config/peer4/peer4.conf | 11 -
volumes/wireguard/config/peer4/peer4.png | Bin 1136 -> 0 bytes
volumes/wireguard/config/peer4/publickey-peer4 | 1 -
volumes/wireguard/config/peer5/peer5.conf | 11 -
volumes/wireguard/config/peer5/peer5.png | Bin 1130 -> 0 bytes
volumes/wireguard/config/peer5/publickey-peer5 | 1 -
volumes/wireguard/config/server/publickey-server | 1 -
volumes/wireguard/config/show-client.sh | 219 --
volumes/wireguard/config/templates/peer.conf | 11 -
volumes/wireguard/config/templates/server.conf | 6 -
volumes/wireguard/config/wg_confs/wg0.conf | 37 -
wiki/Alertes.md | 116 -
wiki/Claude-Skills.md | 182 -
wiki/DefectDojo.md | 144 -
wiki/Docker-Swarm.md | 233 --
wiki/Home.md | 52 -
wiki/Monitoring.md | 98 -
wiki/Pentest-Orchestrator.md | 0
zarovnik/GITLAB-SETUP.md | 450 ---
zarovnik/deploy-gitlab.sh | 157 -
zarovnik/gitlab-ci-example.yml | 199 --
zarovnik/gitlab-deployment-package.tar.gz | Bin 9670 -> 0 bytes
zarovnik/gitlab-maintenance.sh | 170 -
zarovnik/gitlab-runner-config-example.toml | 103 -
zarovnik/gitlab-stack.yml | 190 -
918 files changed, 698 insertions(+), 129994 deletions(-)
```

View File

@@ -0,0 +1,42 @@
---
title: "[myai] Push 1 commit(s) to main"
date: 2026-08-13T00:49:53+02:00
draft: false
tags: ["push", "myai", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans myai/main"
author: "grafana-watcher"
---
## Push to `myai/main`
| | |
|---|---|
| **Repository** | myai |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **4495b7b** restore: agents et commands supprimés par force-push (grafana-watcher)
### Diff Summary
```
.claude/agents/infra-daily-monitor.md | 363 ++++++++++++++++++++++++++++++++
.claude/agents/osint-gatherer.md | 152 ++++++++++++++
.claude/agents/pipeline.md | 310 ++++++++++++++++++++++++++++
.claude/commands/alerts.md | 106 ++++++++++
.claude/commands/borodino.md | 156 ++++++++++++++
.claude/commands/connectivity.md | 241 ++++++++++++++++++++++
.claude/commands/defectdojo.md | 63 ++++++
.claude/commands/monitor.md | 3 +
.claude/commands/opsec-check.md | 377 ++++++++++++++++++++++++++++++++++
.claude/commands/pentest.md | 76 +++++++
.claude/commands/pipeline.md | 5 +
.claude/commands/swarm.md | 93 +++++++++
.claude/commands/topology.md | 150 ++++++++++++++
13 files changed, 2095 insertions(+)
```

View File

@@ -0,0 +1,31 @@
---
title: "[borodino] Push 1 commit(s) to main"
date: 2026-08-14T16:44:31+02:00
draft: false
tags: ["push", "borodino", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Claude Code dans borodino/main"
author: "Claude Code"
---
## Push to `borodino/main`
| | |
|---|---|
| **Repository** | borodino |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Claude Code |
### Commits
- **f083b70** refactor(stack): split borodino en deux — scanner vs pentest (Claude Code)
### Diff Summary
```
stack/40-service-borodino.yml | 577 -----------------------------------
stack/41-service-pentest.yml | 683 ++++++++++++++++++++++++++++++++++++++++++
2 files changed, 683 insertions(+), 577 deletions(-)
```

View File

@@ -0,0 +1,31 @@
---
title: "[myai-orchestrator] Push 1 commit(s) to main"
date: 2026-08-14T23:27:50+02:00
draft: false
tags: ["push", "myai-orchestrator", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par Betty dans myai-orchestrator/main"
author: "Betty"
---
## Push to `myai-orchestrator/main`
| | |
|---|---|
| **Repository** | myai-orchestrator |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | Betty |
### Commits
- **1006ec5** feat(orchestrator): retry loop x3, HF fallback (gemma-4-31b), MAX_NEW_TOKENS=512 (Betty)
### Diff Summary
```
myai_orchestrator | 207 ++++++++++++++++++++++++++++++--------------
stack/myai-orchestrator.yml | 3 +-
2 files changed, 146 insertions(+), 64 deletions(-)
```

View File

@@ -0,0 +1,51 @@
---
title: "[bojemoi] Push 1 commit(s) to main"
date: 2026-08-17T23:51:43+02:00
draft: false
tags: ["push", "bojemoi", "main"]
categories: ["Git Activity"]
summary: "Push de 1 commit(s) par grafana-watcher dans bojemoi/main"
author: "grafana-watcher"
---
## Push to `bojemoi/main`
| | |
|---|---|
| **Repository** | bojemoi |
| **Branch** | `main` |
| **Commits** | 1 |
| **Pushed by** | grafana-watcher |
### Commits
- **aa9647e** restore: stack YML files pulled from bojemoi/bojemoi Gitea (grafana-watcher)
### Diff Summary
```
stack/00-service-boot.yml | 451 +++++++++++
stack/01-service-hl.yml | 1449 ++++++++++++++++++++++++++++++++++
stack/01-suricata-host.yml | 101 +++
stack/02-init-ptaas.yml | 64 ++
stack/02-service-maintenance.yml | 202 +++++
stack/42-service-recon.yml | 59 ++
stack/45-service-ml-threat-intel.yml | 92 +++
stack/46-service-razvedka.yml | 142 ++++
stack/47-service-vigie.yml | 93 +++
stack/48-service-alert-agent.yml | 85 ++
stack/48-service-dozor.yml | 48 ++
stack/49-service-mcp.yml | 85 ++
stack/50-service-trivy.yml | 23 +
stack/51-service-ollama.yml | 98 +++
stack/52-service-runbook.yml | 70 ++
stack/55-service-sentinel.yml | 139 ++++
stack/56-service-dvar.yml | 55 ++
stack/60-service-telegram.yml | 79 ++
stack/65-service-medved.yml | 91 +++
stack/72-service-arch-reviewer.yml | 53 ++
stack/73-service-grafana-watcher.yml | 46 ++
stack/99-service-tool.yml | 147 ++++
22 files changed, 3672 insertions(+)
```

View File

@@ -0,0 +1,136 @@
---
title: "Anatomie du stack high-level Bojemoi : orchestration d'un lab red-team sous Docker Swarm"
date: 2026-07-22
draft: false
tags: ["homelab", "docker", "cybersecurity", "build-in-public", "french-tech", "infosec"]
summary: "Décryptage du fichier 01-service-hl.yml, le cœur observable du lab Bojemoi : comment on orchestre une vingtaine de services de monitoring, backup et sécurité offensive sur Docker Swarm sans se tirer une balle dans le pied."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
## C'est quoi ce fichier, concrètement ?
`01-service-hl.yml` est le deuxième stack déployé dans Bojemoi Lab, juste après `00-service-boot.yml` qui gère l'infrastructure de base (Traefik, CrowdSec, registry local). Ce fichier définit tous les services *applicatifs* du lab : la stack d'observabilité complète (Prometheus, Loki, Grafana, Tempo, Alloy), la messagerie (Postfix + Protonmail Bridge), la base de données centrale, le système de backup, et l'orchestrateur de provisioning.
En gros : si `00` pose les fondations réseau, `01` construit les murs. C'est là que le lab devient utilisable pour du travail red-team réel.
---
## Architecture des réseaux : isolation par usage
Le fichier déclare six réseaux Docker Swarm externes, tous créés en amont :
| Réseau | Usage |
|---|---|
| `proxy` | Trafic Traefik (exposition HTTP/HTTPS) |
| `backend` | Communication inter-services interne |
| `monitoring` | Scraping Prometheus, push Loki |
| `rsync_network` | Réplication de données master/slave |
| `mail` | Isolation de la chaîne email |
| `host` | node-exporter en mode réseau host |
C'est un pattern d'isolation solide. Chaque service n'est connecté qu'aux réseaux dont il a besoin — Postfix parle à `mail`, `backend` et `monitoring`, mais pas à `proxy` directement. Grafana, lui, touche les trois premiers. Cette segmentation limite la surface d'attaque latérale si un container est compromis.
**Ce qu'on aurait pu mieux faire** : le réseau `host` pour node-exporter expose le container au réseau physique de l'hôte. C'est intentionnel (pour collecter les métriques système réelles), mais ça reste un vecteur si l'image est compromise.
---
## Le système de secrets : Docker Swarm Secrets à fond
Tous les secrets sont `external: true`, créés via un script dédié `/opt/bojemoi/scripts/create-secrets.sh`. On compte 14 secrets gérés proprement :
```yaml
secrets:
postgres_password:
external: true
telegram_bot_token:
external: true
grafana_admin_password:
external: true
# ... etc
```
Les mots de passe ne transitent jamais en clair dans les variables d'environnement — ils sont montés dans `/run/secrets/` et lus via `_FILE` suffixé (pattern standard Postgres, Grafana). C'est la bonne approche pour du Swarm en production.
**Limitation honnête** : pgadmin a `PGADMIN_DEFAULT_PASSWORD: bojemoi` en clair dans l'environnement. C'est un outil admin interne, mais c'est un écart de cohérence notable par rapport au reste du stack. À corriger.
---
## La stack d'observabilité : le vrai cœur du lab
### Prometheus → Loki → Tempo → Grafana
La chaîne suit le modèle LGTM (Loki, Grafana, Tempo, Mimir/Prometheus) de Grafana Labs :
- **Prometheus** : 15 jours de rétention, 10 GB max, compression WAL activée, remote-write receiver ouvert (pour les agents externes)
- **Loki** : exposition en mode `host` sur 3100, ce qui simplifie la collecte depuis les workers
- **Tempo** : ingestion multi-protocole (OTLP gRPC 4317, OTLP HTTP 4318, Zipkin 9411) — utile pour instrumenter des outils red-team custom
- **Grafana** : backend PostgreSQL (pas SQLite), plugins dynamiques via `GF_INSTALL_PLUGINS`
### Alloy : collecte à deux vitesses
Un pattern intéressant : deux instances d'Alloy avec des configs distinctes.
```yaml
alloy: # manager — lit les logs rsync + /opt/bojemoi/logs
alloy-worker: # mode global sur workers — lit /var/run/docker.sock directement
```
L'instance manager passe par le `docker-socket-proxy` (hérité du stack boot), l'instance worker monte le socket Docker en direct (`ro`). C'est un compromis pragmatique : sur les workers on accepte l'accès socket, sur le manager on passe par le proxy pour éviter l'exposition de l'API Docker complète.
---
## PostgreSQL SSL : un effort réel de durcissement
```yaml
command: >
postgres
-c ssl=on
-c ssl_cert_file=/var/lib/postgresql/ssl/server.crt
-c ssl_key_file=/var/lib/postgresql/ssl/server.key
-c ssl_ca_file=/var/lib/postgresql/ssl/ca.crt
-c hba_file=/etc/postgresql/pg_hba.conf
-c shared_preload_libraries=pg_stat_statements
```
SSL mutuel activé, certificats injectés via Docker configs avec les bons UID/GID (999 = utilisateur postgres), `pg_hba.conf` externe, `pg_stat_statements` pour le monitoring de requêtes. C'est du niveau production pour un homelab.
Le port 5432 est exposé en mode `host` avec une note explicite : *"bind sur l'interface physique du manager — pas d'exposition internet"*. C'est honnête et pragmatique, même si ça suppose une confiance totale dans l'isolation réseau physique.
---
## La chaîne mail : Postfix → Protonmail Bridge
Un choix original : utiliser Protonmail comme relay SMTP chiffré de bout en bout depuis un lab red-team. La chaîne est :
```
services → Postfix (port 25) → Protonmail Bridge (port 1025) → Proton Mail
```
Un `mail-watchdog` teste la chaîne complète toutes les 10 minutes et expose des métriques Prometheus sur le port 9355. C'est exactement le genre de test end-to-end qu'on néglige en général.
**Limitation connue** : le `main.cf` de Postfix ne peut pas être injecté via Docker config (le commentaire dans le fichier l'explique — `postconf` modifie le fichier et les configs Docker sont read-only). La configuration passe donc par des variables d'environnement. Fonctionnel, mais moins auditable.
---
## Le système de backup rsync : master/slave sur Swarm
```yaml
rsync-master:
deploy:
placement:
constraints:
- node.role == manager
rsync-slave:
deploy:
mode: global
placement:
constraints:
- node.labels.rsync.slave == true
```
Les slaves se déploient sur tous les nodes labellisés `rsync.slave=true`. Le master synchronise `/opt/bojemoi` toutes les 5 minutes vers les slaves. L'accès SSH est géré via un volume `ssh_keys` partagé.
**Pattern YAML intéressant** : l'utilisation des ancres YAML (`&mode-template`, `&deploy-template`) pour factoriser la configuration commune des services rsync. C'est propre et réd

View File

@@ -0,0 +1,124 @@
---
title: "Suricata en mode host sur Docker Swarm : pourquoi on triche (et pourquoi c'est OK)"
date: 2026-07-23
draft: false
tags: ["homelab", "docker", "cybersecurity", "build-in-public", "french-tech", "infosec"]
summary: "Analyse du stack Suricata de Bojemoi Lab : comment intégrer un IDS/IPS en network_mode host dans un environnement Docker Swarm, avec exporter Prometheus et nettoyage automatique des logs."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
## TL;DR
Suricata ne joue pas bien avec Docker Swarm. On le sait. On a quand même trouvé un compromis fonctionnel, et cet article explique pourquoi on a fait ces choix — y compris les moins glorieux.
---
## Le problème fondamental : Swarm et la capture réseau
Docker Swarm est excellent pour orchestrer des services applicatifs. Mais dès qu'on veut faire de la capture de paquets **à la couche physique**, les choses se compliquent sérieusement.
Un service Swarm tourne dans un réseau overlay (`ingress` ou custom). Les paquets qu'il voit sont déjà encapsulés, NATés, transformés. Pour un IDS comme Suricata, c'est rédhibitoire : tu n'analyses plus le trafic réel, tu analyses l'ombre d'un trafic.
La solution honnête ? **Sortir Suricata du Swarm et lui donner accès direct à l'interface réseau physique.**
C'est ce que fait `stack/01-suricata-host.yml` — et c'est assumé dès le premier commentaire du fichier :
```yaml
# Suricata IDS/IPS — standalone docker compose (NOT Swarm)
# Requires network_mode: host for real packet capture on eth0.
```
---
## Architecture du stack : trois rôles, trois conteneurs
### 1. `suricata` — le moteur IDS/IPS
```yaml
network_mode: host
cap_add:
- NET_ADMIN
- SYS_NICE
- NET_RAW
```
`network_mode: host` est le choix central. Le conteneur partage la stack réseau du nœud hôte. Suricata peut ainsi écouter sur `eth0` directement, comme s'il était installé en bare-metal.
Les capabilities ajoutées sont les trois pilliers de la capture réseau sous Linux :
- **NET_RAW** : ouvrir des raw sockets, lire les paquets bruts
- **NET_ADMIN** : manipuler les interfaces (mode promiscuité, règles nftables si IPS)
- **SYS_NICE** : ajuster la priorité des threads de capture pour éviter les drops sous charge
Les options Suricata méritent attention :
```yaml
SURICATA_OPTIONS=-i eth0 --set stream.reassembly.depth=0 --set detect.profile=low
```
- `stream.reassembly.depth=0` : pas de limite sur la profondeur de réassemblage TCP. En homelab avec peu de RAM, c'est un pari — ça peut consommer beaucoup sur des transferts massifs. À monitorer.
- `detect.profile=low` : profil de détection économique. On sacrifie de la couverture pour des performances acceptables sur du matériel modeste. C'est honnête pour un lab.
### 2. `suricata-exporter` — le pont vers Prometheus
Ce conteneur lit les métriques Suricata via son **Unix socket** (`suricata-command.socket`) et les expose au format Prometheus. C'est un pattern propre : Suricata ne connaît pas Prometheus, l'exporter fait le pont sans modifier le moteur.
```yaml
command:
- '--suricata.socket-path=/var/run/suricata/suricata-command.socket'
```
La communication passe par un volume partagé monté en lecture seule côté exporter. Le `depends_on` garantit que Suricata démarre en premier — même si ça ne garantit pas que le socket existe déjà au moment où l'exporter tente de s'y connecter. Un `restart: unless-stopped` compense ce race condition de démarrage.
L'exporter rejoint le réseau `monitoring` (externe, donc géré par le Swarm), ce qui lui permet d'être scraped par Prometheus même si le reste du stack est hors Swarm.
### 3. `eve-cleaner` — gestion des logs à l'ancienne
C'est le composant le plus artisanal — et probablement le plus honnête du stack.
Suricata génère un fichier `eve.json` en append continu. Il n'y a **pas de rotation native** du fichier actif dans Suricata (contrairement aux fichiers horodatés qu'il crée lui-même). Résultat : sans intervention, `eve.json` grossit indéfiniment.
La solution ici : un conteneur Alpine qui tourne une boucle shell toutes les heures.
```sh
# Suppression des fichiers archivés de plus de 48h
AGE_H=$(( (NOW - MTIME) / 3600 ))
if [ "$AGE_H" -ge "$KEEP_HOURS" ]; then rm -f "$f"; fi
# Troncature de eve.json si > 5GB
if [ "$EVE_KB" -ge "$MAX_KB" ]; then truncate -s 0 "$EVE"; fi
```
Points notables :
- `truncate -s 0` plutôt que `> file` ou `rm` : Suricata conserve son file descriptor ouvert, la troncature vide le fichier sans casser le handle. C'est le bon geste.
- La compatibilité `stat` est gérée avec deux syntaxes (`-c %Y` Linux, `-f %m` macOS) — vestige probable de dev en local sur Mac.
- Le logging de l'opération est verbose et structuré, ce qui est bien pour le debug.
---
## Ce qui manque (et on le sait)
### Déploiement multi-nœuds manuel
Le commentaire dit tout : `Deploy on each node: docker compose -f stack/01-suricata-host.yml up -d`. Il n'y a pas d'automatisation de déploiement sur plusieurs nœuds. Sur un cluster de 5 machines, c'est 5 commandes SSH manuelles. Un Ansible playbook serait le prochain palier évident.
### Le race condition au démarrage
`suricata-exporter` démarre après `suricata` mais le socket Unix peut mettre quelques secondes à apparaître. Les premières tentatives de connexion échouent. Le `restart: unless-stopped` rattrape ça, mais c'est du bricolage. Une `healthcheck` sur Suricata testant l'existence du socket serait plus propre.
### `detect.profile=low` en production
Acceptable pour un lab, problématique pour une vraie infrastructure. Ce paramètre réduit la précision de certaines détections comportementales. À revoir si le lab évolue vers de la détection d'incidents réels.
### L'enrichissement des alertes est ailleurs
Le commentaire final pointe vers `stack/01-service-hl.yml` pour le `suricata-attack-enricher`. Ce découpage est logique (l'enrichisseur a besoin du réseau overlay Swarm et des secrets), mais ça crée une dépendance inter-fichiers non évidente à l'onboarding.
---
## Ce qu'on retient
Ce fichier est un bon exemple de pragmatisme en homelab : on fait ce qui marche, on documente les compromis, et on ne prétend pas que c'est parfait. `network_mode: host` dans un environnement Swarm n'est pas élégant, mais c'est la seule façon d'avoir un IDS qui voit vraiment le trafic.
L'

View File

@@ -0,0 +1,113 @@
---
title: "PTaaS Init : Comment on enregistre un nœud red-team en une seule passe avec HMAC et DefectDojo"
date: 2026-07-24
draft: false
tags: ["homelab", "docker", "cybersecurity", "build-in-public", "french-tech", "infosec"]
summary: "Décryptage du service d'initialisation PTaaS de Bojemoi Lab : un one-shot container qui génère une identité cryptographique par HMAC, provisionne DefectDojo et labellise le nœud Docker Swarm en moins de 30 secondes."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
## Le problème qu'on cherchait à résoudre
Quand on monte un lab red-team en mode *Penetration Testing as a Service* (PTaaS), la première question qui se pose est bête mais fondamentale : **comment identifier un nœud de manière unique sans gérer une PKI complète dès le départ ?**
On voulait quelque chose de simple, reproductible, et suffisamment robuste pour distinguer deux instances du lab déployées sur deux machines différentes. Le résultat, c'est `02-init-ptaas.yml` — un stack Docker Swarm one-shot qui tourne une seule fois, fait son travail, et disparaît (ou réessaie en cas d'échec).
---
## Ce que fait ce composant dans l'architecture globale
`02-init-ptaas.yml` est le **troisième acte** du bootstrap, après `01-boot` (infrastructure réseau, registry local) et `01-base` (PostgreSQL, DefectDojo, services core). Il suppose que PostgreSQL tourne déjà sur le réseau `backend` et que DefectDojo est joignable sur `http://defectdojo-nginx:8080`.
Son rôle est d'**enregistrer le nœud comme client PTaaS** en enchaînant quatre opérations :
1. **Calcul du serial** via `HMAC(telegram_key, local_key)`
2. **Création d'un produit DefectDojo** associé à ce serial
3. **Labellisation du nœud Docker** avec `ptaas.serial=<serial>`
4. **Persistance en base** dans la table `ptaas_identity`
Il y a aussi un cinquième point mentionné dans les commentaires — l'enregistrement blockchain — qui est honnêtement marqué `(stub)` pour l'instant. On y revient.
---
## Les choix techniques intéressants
### HMAC comme générateur de serial
Le choix de `HMAC(telegram_key, local_key)` pour dériver un identifiant est volontairement minimaliste. L'idée : deux clés séparées (`ptaas_telegram_key` pour l'identité réseau/bot, `ptaas_local_key` pour l'empreinte machine) combinées via HMAC donnent un serial déterministe mais non-réversible.
```
serial = HMAC-SHA256(telegram_key, local_key)
```
Avantage immédiat : **si on redeploie le lab sur la même machine avec les mêmes secrets, on retrouve exactement le même serial**. C'est important pour la cohérence des données dans DefectDojo — on ne crée pas un nouveau produit à chaque redémarrage.
C'est du crypto de bon sens, pas de la crypto de compétition. Pour un homelab red-team, c'est suffisant.
### Secrets Docker Swarm, pas de variables d'env
On aurait pu passer les clés en variables d'environnement. On ne l'a pas fait. Les quatre secrets sensibles (`postgres_password`, `ptaas_telegram_key`, `ptaas_local_key`, `dojo_api_token`) sont injectés via le mécanisme natif Docker Secrets, montés en `/run/secrets/` dans le container.
```yaml
secrets:
- postgres_password
- ptaas_telegram_key
- ptaas_local_key
- dojo_api_token
```
Ça évite qu'ils apparaissent dans `docker inspect`, dans les logs, ou dans un `ps aux` malencontreux. Bonne hygiène de base.
### Mount du socket Docker
```yaml
volumes:
- /var/run/docker.sock:/var/run/docker.sock
```
C'est ce qui permet au container de labelliser le nœud lui-même via l'API Docker Engine. En pratique, le service appelle quelque chose comme `docker node update --label-add ptaas.serial=<serial> <node_id>`.
**C'est aussi le point le plus sensible de l'architecture.** Un container avec accès au socket Docker a, de facto, les droits root sur l'hôte. On l'accepte ici parce que c'est un service éphémère qui tourne uniquement sur le manager, avec des ressources limitées (`0.2 CPU`, `128M RAM`) et une politique de restart bornée (`max_attempts: 5`).
### Constraint `node.role == manager`
La labellisation des nœuds Swarm nécessite d'être exécutée depuis un manager. Le placement constraint l'impose explicitement, ce qui évite des erreurs d'API cryptiques si le scheduler décide de placer le service ailleurs.
### One-shot avec restart policy borné
```yaml
restart_policy:
condition: on-failure
delay: 10s
max_attempts: 5
```
On ne veut pas que ce service tourne en boucle indéfiniment. Cinq tentatives avec 10 secondes d'intervalle, c'est assez pour absorber un démarrage lent de PostgreSQL ou de DefectDojo. Après ça, si ça échoue encore, il faut regarder les logs manuellement. C'est un choix délibéré : on préfère un échec visible à un retry infini silencieux.
---
## Points d'amélioration honnêtes
### Le stub blockchain
Le commentaire est transparent : `Registers on blockchain (stub)`. C'est une fonctionnalité voulue — l'idée à terme étant de tracer l'enregistrement des nœuds PTaaS sur une chaîne légère (probablement un simple contrat sur une testnet EVM) pour avoir une preuve d'existence immuable du serial. Pour l'instant, c'est un `pass` dans le code Python. On l'assume.
### Idempotence non garantie explicitement
Si le service est redéployé sur un nœud déjà initialisé, le comportement dépend entièrement de la logique applicative (`ptaas-init:latest`). Est-ce qu'on fait un `INSERT OR IGNORE` ou un `UPSERT` en PostgreSQL ? Est-ce que l'API DefectDojo tolère la création d'un produit au même nom ? Ces cas doivent être gérés dans le code, et ce n'est pas visible dans le YAML.
### Pas de healthcheck
Le service n'expose pas de healthcheck Docker. Pour un one-shot, c'est acceptable, mais ça compliquerait l'intégration dans un pipeline CI/CD qui attendrait une confirmation de succès propre.
### Image localhost:5000
On utilise le registry local du lab (`localhost:5000/ptaas-init:latest`). C'est pratique en développement, contraignant en production distribuée. Le flag `--resolve-image never` dans la commande de deploy est d'ailleurs là pour contourner la vérification de digest sur les images locales — un autre détail honnête à documenter.
---
## Ce qu'on a appris en le buildant
Le vrai apprentissage de ce composant, c'est que **l'initialisation d'infrastructure doit être pensée comme une transaction** : tout ou rien. Si la création du produit DefectDojo réussit mais que la persistance PostgreSQL échoue, on se retrouve dans un état incohérent. La version actuelle gère ça par retry global, pas par rollback partiel. C'est le prochain chantier.

View File

@@ -0,0 +1,110 @@
---
title: "Maintenance nocturne dans un lab red-team : anatomie d'une stack Docker Swarm qui se nettoie elle-même"
date: 2026-07-25
draft: false
tags: ["homelab", "docker", "cybersecurity", "build-in-public", "french-tech", "infosec"]
summary: "Décryptage de la stack de maintenance automatisée du Bojemoi Lab : nettoyage Docker, garbage collection du registry, VACUUM Postgres et watchdog DefectDojo — le tout orchestré sous Docker Swarm avec des choix techniques assumés et quelques limitations honnêtes."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
## Le problème que cette stack résout
Un lab red-team tourne en continu. Les outils de scan (Nuclei, ZAP, Metasploit) génèrent des images Docker temporaires, des couches orphelines dans le registry interne, des entrées PostgreSQL en état `running` depuis 3 jours parce qu'un container s'est crashé sans prévenir. Sans hygiène automatisée, le disque sature en deux semaines et les dashboards Prometheus affichent des métriques corrompues par des artefacts de runs passés.
La stack `02-service-maintenance.yml` est la réponse à ça : cinq services qui tournent en arrière-plan, invisibles, et qui font le ménage pendant que le reste du lab scanne des cibles.
---
## Les cinq services en détail
### `docker-cleanup` — Le balayeur global
C'est le service le plus critique en termes de surface d'opération. Il tourne en **mode `global`**, ce qui signifie qu'une instance est déployée sur **chaque nœud** du swarm. C'est le bon pattern ici : le Docker socket est local à chaque nœud, impossible de nettoyer les ressources d'un nœud depuis un autre.
```yaml
command:
- "0 */2 * * * docker container prune -f --filter until=2h"
- "0 3 * * * docker system prune -af --filter until=24h"
```
Deux jobs cron :
- Toutes les 2 heures : purge des containers morts depuis plus de 2h (les runs de scan courts)
- À 3h du matin : `system prune` agressif — images, volumes anonymes, réseaux, build cache
Le `--filter until=24h` sur le prune nocturne est une protection importante : on ne supprime que ce qui a plus de 24h, évitant de tuer des images fraîchement buildées. C'est un détail qui compte quand on fait du CI/CD interne.
**Point de sécurité notable** : le container monte `/var/run/docker.sock`. C'est le compromis classique — socket Docker = root sur le nœud. Dans un lab isolé c'est acceptable, en production ça mérite une réflexion sur Rootless Docker ou un proxy de socket type `tecnativa/docker-socket-proxy`.
### `registry-gc` — Le ramasse-miettes du registry
Ce service a `replicas: 0` par défaut. Il ne tourne pas en permanence — il est déclenché **manuellement** après des séries de rebuilds :
```bash
docker service scale maintenance_registry-gc=1
```
Il exécute le garbage collector natif de la `registry:2` avec `--delete-untagged=true`. La subtilité : le GC du registry Docker nécessite que le registry soit **arrêté ou en lecture seule** pendant l'opération, sinon on risque une corruption. Ici c'est géré par la politique opérationnelle (pas de push pendant le GC), ce qui est une limitation réelle à documenter dans le runbook.
Le `restart_policy: condition: none` est cohérent : un job one-shot qui se relance indéfiniment c'est un anti-pattern.
### `swarm-exporter` — Les métriques Swarm pour Prometheus
Un script Python custom qui expose des métriques sur l'état du swarm (services, tâches, nœuds) au format Prometheus. Il tourne uniquement sur le manager car l'API Swarm n'est accessible que depuis le manager.
Les labels de service sont particulièrement propres :
```yaml
labels:
- prometheus.enable=true
- prometheus.port=9324
- prometheus.path=/metrics
- prometheus.label.team=infrastructure
- prometheus.label.component=swarm-exporter
```
C'est du **label-based service discovery** — Prometheus scrape automatiquement tout service étiqueté `prometheus.enable=true`. Pas besoin de modifier la config Prometheus à chaque ajout de service. Pattern élégant pour un homelab en évolution rapide.
**Limitation honnête** : l'image `localhost:5000/python:latest` avec le tag `latest` c'est une bombe à retardement pour la reproductibilité. En prod on épinglerait un hash ou au minimum une version sémantique.
### `dojo-token-watchdog` — Le gardien du token DefectDojo
Ce service résout un problème concret : les tokens API de DefectDojo ont une durée de vie, et quand ils expirent, tous les outils qui poussent leurs findings vers DefectDojo commencent à échouer silencieusement.
Le watchdog vérifie toutes les 5 minutes (`CHECK_INTERVAL_SECONDS: 300`) que le token stocké en secret Docker est toujours valide, et le renouvelle si nécessaire via l'API DefectDojo.
```yaml
environment:
STARTUP_DELAY: "60"
```
Le délai de démarrage de 60 secondes laisse le temps à DefectDojo de démarrer complètement avant la première tentative. C'est du polling avec backoff implicite — pas élégant, mais ça marche.
**Ce que j'aurais fait différemment** : `pip install` au démarrage du container c'est lent et ça casse si PyPI est inaccessible. Les dépendances devraient être dans l'image de base. C'est du dette technique assumée pour aller vite.
### `db-maintenance` — L'hygiène PostgreSQL
Deux scripts cron injectés dynamiquement dans le container Postgres :
- **Dimanche 4h** : `VACUUM ANALYZE` sur les quatre tables critiques (`hosts`, `services`, `nuclei_scan_log`, `zap_scan_log`)
- **Lundi 5h** : purge des entrées de scan en erreur/timeout vieilles de 7 jours, et des entrées en état `running` depuis plus d'un jour (orphelines de containers crashés)
```sql
DELETE FROM nuclei_scan_log
WHERE status='running' AND scanned_at < now() - interval '1 day';
```
Cette dernière requête est particulièrement importante : sans elle, la table accumule des phantômes de scans qui n'ont jamais terminé, faussant les statistiques de couverture.
**Limitation** : le `VACUUM ANALYZE` cible des tables nommées en dur. Si on ajoute une nouvelle table de scan, il faut penser à mettre à jour ce fichier. Un `VACUUM ANALYZE` sans cible (toute la base) serait plus maintenable, au prix d'un run légèrement plus long.
---
## Patterns architecturaux remarquables
**Cron-in-container** : plutôt qu'un CronJob Kubernetes, tous les jobs périodiques utilisent `crond -f` lancé comme PID 1 (ou presque). Simple, pas de dépendance externe, les logs sortent vers stdout via `/proc/1/fd/1`. C'est le pattern "cron dans Docker" le plus propre que j'aie vu sans surcouche.
**Secrets Docker natifs** : les mots de passe ne transitent jamais en variable d'environnement. Ils sont lus depuis `/run/secrets/` au moment de l'exécution. C'est la bonne pratique Swarm.
**Contraintes manager** : tous les services qui touchent à l

View File

@@ -0,0 +1,157 @@
---
title: "Building Your Own Falcon MCP: ThreatFox + Cross-Reference Against 6 Million Hosts"
date: 2026-08-06T23:30:00+00:00
draft: false
tags: ["threat-intelligence", "cybersecurity", "osint", "infosec", "homelab", "docker-swarm", "docker", "devops", "selfhosted", "opensource", "build-in-public", "cobalt-strike", "c2", "mcp", "red-team"]
summary: "I saw a post describing how Falcon MCP is used to track APT C2 infrastructure. Tonight I replicated it with free sources — and found an active Cobalt Strike C2 in my database."
description: "How to build an MCP server with ThreatFox (abuse.ch) to cross-reference C2 IOCs against a database of 6 million scanned hosts, starting from scratch with free tools."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
Tonight I read a post describing something interesting: someone uses CrowdStrike Falcon via MCP to query their threat intelligence database in natural language — APT12, Calypso, Pegasus, DarkHotel — and get categorized C2 IOC lists by actor.
Falcon costs a fortune. But the concept is simple. And I already had the infrastructure to do the same thing.
This post covers how I built the equivalent in a few hours, using free sources, and what I found.
## What Is MCP?
MCP (Model Context Protocol) is a standard developed by Anthropic that allows an LLM to connect to external tools in real time. When I talk to Claude Code, it can call tools — launch an nmap scan, query my Metasploit database, search for CVEs — because my infrastructure exposes those capabilities through an MCP server.
That's exactly what CrowdStrike did: they plugged their Falcon platform into this protocol. The operator asks "show me active APT12 C2s from this week" and the LLM queries Falcon automatically.
The difference from a regular chatbot: the data is **fresh** and **contextualized to your own infrastructure**.
## My Starting Infrastructure
I have a Docker Swarm homelab with:
- A custom MCP server (`mcp-server`) exposing around thirty tools
- A Metasploit PostgreSQL database with **6.15 million scanned hosts** and their services
- An automated scanning pipeline (masscan → classification → exploit → nuclei)
The MCP server already had `lookup_ip` for querying OTX on a single IP. What was missing: the **feed dimension** — querying threat feeds to find known actors, known C2s, and most importantly cross-referencing that against my own database.
## Free Sources
Two abuse.ch sources, free and well-maintained:
**ThreatFox** — C2 IOC database with confidence scores, malware families, and campaign tags. Requires a free account for the API. Thousands of recent IOCs: Cobalt Strike, Sliver, Metasploit stagers, botnets.
**Feodo Tracker** — botnet C2 list (Emotet, QakBot, IcedID). Completely public, no authentication. Fewer entries but zero friction.
## What We Built
Three functions in a new `bojemoi/cti.py` module:
```python
threatfox_recent(days=7, ioc_type=None, malware=None)
# → Recent IOCs, filterable by type and malware family
threatfox_search(ioc)
# → Is this IP/domain/hash a known C2?
ioc_crossref(days=7, malware=None, min_confidence=50)
# → THE KILLER FEATURE
```
The killer feature is `ioc_crossref`. The logic:
1. Fetch recent `ip:port` IOCs from ThreatFox
2. Extract unique IPs
3. A single SQL query against the 6.15M hosts:
```sql
SELECT host(address::inet), os_name, scan_status, last_scanned
FROM hosts
WHERE host(address::inet) = ANY($1)
```
4. Return matches with context from both sides (what ThreatFox knows + what my scanner saw)
If a host I've already scanned matches a known C2 — I know immediately.
These three functions are also exposed as MCP tools, so Claude can call them directly in conversation:
```
ioc_crossref → cross-reference ThreatFox IOCs vs MSF DB
threatfox_recent → browse recent C2 IOCs by family/type
threatfox_search → look up a specific IP/domain/hash
```
## The Result
First run with `ioc_crossref(days=2)`:
```
Source : threatfox
Unique IOCs : 267
MSF HITS : 1
45.8.159.205 | Cobalt Strike | scan_status: None
```
One hit. `45.8.159.205`, Cobalt Strike C2, port 8596, reported the day before with 75% confidence and tag `drb-ra`.
The IP had been in my database since May 2026 — my masscan sweep had touched it — but with no in-depth scan (status null).
## Manual Confirmation
Nmap scan:
```
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7
8596/tcp open unknown
```
HTTP probe on port 8596:
```
GET / → HTTP/1.1 404 Not Found
Content-Type: text/plain
Content-Length: 0
[no Server header]
OPTIONS / → HTTP/1.1 200 OK
Content-Type: text/html
Allow: OPTIONS,GET,HEAD,POST
```
This is the classic signature of a **Cobalt Strike Malleable C2 HTTP profile**:
- Silent 404 on GET (non-beacon requests silently rejected)
- 200 on OPTIONS (beacon heartbeat)
- No `Server` header (obfuscation)
- Port 50050 closed (teamserver UI not exposed — careful operator)
Ubuntu 18.04 EOL. ASN AS49392 LLC Baxet, Moscow. Tag `drb-ra` is a campaign marker identified in the CTI community.
Finding documented in DefectDojo.
## What This Changes
The cross-reference is the part that interests me most. I'm not trying to check whether an IP *exists* in ThreatFox — I can do that with `lookup_ip`. I want to know if among the millions of hosts I've already scanned, some of them are known C2 infrastructure.
That's a different question, and the answer changes what you do next. A host already in your database with known services is immediately explorable — you already know its open ports, OS, and context.
The natural next step: automate this daily and alert via Telegram when a new match appears. That's now running as a daily cron on the lab:
```bash
0 7 * * * docker exec <mcp-server> python cti_daily.py
```
The script calls `ioc_crossref(days=1)`, and sends a Telegram message — either "0 hits, all clear" or a detailed alert with IP, malware family, and confidence score.
## Reproduce This
Everything you need:
- A Python MCP server (code is on my Gitea)
- A free ThreatFox key (register at threatfox.abuse.ch)
- A database of scanned hosts (or Shodan/Censys if you don't have your own scanner)
The cross-reference logic works with any SQL database. If you have a list of IPs you know about, you can cross-reference it against ThreatFox in a few lines.
---
*Infrastructure: Docker Swarm, Python, PostgreSQL, ThreatFox API, abuse.ch Feodo Tracker*

View File

@@ -0,0 +1,143 @@
---
title: "Construire son propre Falcon MCP : ThreatFox + Cross-Référence sur 6 millions d'hôtes"
date: 2026-08-06T23:00:00+00:00
draft: false
tags: ["threat-intelligence", "cybersecurity", "osint", "infosec", "homelab", "docker-swarm", "docker", "devops", "selfhosted", "opensource", "build-in-public", "french-tech", "apprendre-la-cyber", "debutant-en-cyber", "cobalt-strike", "c2", "mcp", "red-team"]
summary: "J'ai vu un post sur Dread décrivant l'usage des flux Falcon MCP pour tracker des C2 APT. Ce soir, j'ai reproduit ça avec mes propres sources gratuites — et trouvé un C2 Cobalt Strike actif dans ma base."
description: "Comment construire un serveur MCP avec ThreatFox (abuse.ch) pour croiser des IOCs C2 avec une base de 6 millions d'hôtes scannés, en partant de zéro avec des outils gratuits."
author: "Bojemoi"
ShowToc: true
ShowReadingTime: true
---
Ce soir j'ai lu un post qui décrivait quelque chose d'intéressant : quelqu'un utilise les flux CrowdStrike Falcon via MCP pour interroger en langage naturel leur base de threat intelligence — APT12, Calypso, Pegasus, DarkHotel — et obtenir des listes d'IOCs C2 catégorisés par acteur.
Falcon coûte une fortune. Mais le principe est simple. Et j'avais déjà l'infrastructure pour faire pareil.
Ce post raconte comment j'ai construit l'équivalent en quelques heures, avec des sources gratuites, et ce que j'ai trouvé.
## C'est quoi MCP ?
MCP (Model Context Protocol) est un standard développé par Anthropic qui permet à un LLM de se connecter à des outils externes en temps réel. Quand je discute avec Claude Code, il peut appeler des outils — lancer un scan nmap, interroger ma base Metasploit, chercher des CVEs — parce que mon infrastructure expose ces capacités via un serveur MCP.
C'est exactement ce que CrowdStrike a fait : ils ont branché leur plateforme Falcon sur ce protocole. L'opérateur demande "montre-moi les C2 d'APT12 actifs cette semaine" et le LLM interroge Falcon automatiquement.
La différence avec un simple chatbot : les données sont **fraîches** et **contextualisées** à votre infra.
## Mon infrastructure de départ
J'ai un homelab Docker Swarm avec :
- Un serveur MCP maison (`mcp-server`) exposant une trentaine d'outils
- Une base Metasploit PostgreSQL avec **6,15 millions d'hôtes** scannés et leurs services
- Un pipeline de scanning automatique (masscan → classification → exploit → nuclei)
Le serveur MCP avait déjà `lookup_ip` qui interroge OTX pour une IP individuelle. Ce qui manquait : la **dimension flux** — interroger des feeds pour trouver des acteurs, des C2 connus, et surtout croiser ça avec ma propre base.
## Les sources gratuites
Deux sources abuse.ch, gratuites et bien maintenues :
**ThreatFox** — base d'IOCs C2 avec confiance, famille malware, tags de campagne. Nécessite une inscription gratuite pour l'API. Des milliers d'IOCs récents : Cobalt Strike, Sliver, Metasploit stagers, botnets.
**Feodo Tracker** — liste des C2 de botnets (Emotet, QakBot, IcedID). Complètement public, pas d'authentification. Moins d'entrées mais zéro friction.
## Ce qu'on a construit
Trois fonctions dans un nouveau module `bojemoi/cti.py` :
```python
threatfox_recent(days=7, ioc_type=None, malware=None)
# → IOCs récents, filtrables par type et famille malware
threatfox_search(ioc)
# → Est-ce que cette IP/domaine/hash est connue comme C2 ?
ioc_crossref(days=7, malware=None, min_confidence=50)
# → KILLER FEATURE
```
La killer feature c'est `ioc_crossref`. Le principe :
1. Récupérer les IOCs `ip:port` récents de ThreatFox
2. Extraire les IPs uniques
3. Une seule requête SQL sur les 6,15M hosts :
```sql
SELECT host(address::inet), os_name, scan_status, last_scanned
FROM hosts
WHERE host(address::inet) = ANY($1)
```
4. Retourner les matches avec le contexte des deux côtés (ce que ThreatFox sait + ce que mon scanner a vu)
Si un hôte que j'ai scanné correspond à un C2 connu — je le sais immédiatement.
## Le résultat
Premier test avec `ioc_crossref(days=2)` :
```
Source : threatfox
IOCs uniques : 267
HITS MSF : 1
45.8.159.205 | Cobalt Strike | scan_status: None
```
Un hit. `45.8.159.205`, C2 Cobalt Strike, port 8596, signalé la veille avec confiance 75% et tag `drb-ra`.
L'IP était dans ma base depuis mai 2026 — mon scanner masscan l'avait touchée — mais sans scan approfondi (status null).
## Confirmation manuelle
Scan nmap :
```
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7
8596/tcp open unknown
```
Sonde HTTP sur 8596 :
```
GET / → HTTP/1.1 404 Not Found
Content-Type: text/plain
Content-Length: 0
[pas de header Server]
OPTIONS / → HTTP/1.1 200 OK
Content-Type: text/html
Allow: OPTIONS,GET,HEAD,POST
```
C'est la signature classique d'un **Cobalt Strike Malleable C2 HTTP profile** :
- 404 vide sur GET (requêtes non-beacon rejetées silencieusement)
- 200 sur OPTIONS (heartbeat beacon)
- Pas de header `Server` (obfuscation)
- Port 50050 fermé (UI teamserver non exposée — opérateur prudent)
Ubuntu 18.04 EOL. ASN AS49392 LLC Baxet, Moscou. Tag `drb-ra` = marqueur de campagne identifié dans la communauté CTI.
Finding documenté dans DefectDojo.
## Ce que ça change
La cross-référence est la partie qui m'intéresse le plus. Je ne cherche pas à savoir si une IP *existe* dans ThreatFox — je peux faire ça avec `lookup_ip`. Je veux savoir si parmi les millions d'hôtes que j'ai déjà scannés, certains sont de l'infrastructure C2 connue.
C'est une question différente, et la réponse change ce qu'on fait ensuite. Un hôte déjà dans ma base avec des services connus est immédiatement explorable — je connais déjà ses ports ouverts, son OS, son contexte.
La prochaine étape logique : automatiser ce cross-ref quotidiennement et alerter via Telegram quand un nouveau match apparaît.
## Reproduire ça
Tout ce qu'il faut :
- Un serveur MCP Python (le code est sur mon Gitea)
- Une clé ThreatFox gratuite (inscription sur threatfox.abuse.ch)
- Une base de données d'hôtes scannés (ou Shodan/Censys si vous n'avez pas de scanner)
La logique de cross-référence fonctionne avec n'importe quelle base SQL. Si vous avez une liste d'IPs que vous connaissez, vous pouvez la croiser avec ThreatFox en quelques lignes.
---
*Infrastructure : Docker Swarm, Python, PostgreSQL, ThreatFox API, abuse.ch Feodo Tracker*