You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Evolve Azazel-Knowledge and Azazel-Deception into interoperable defensive
planes that can exchange bounded evidence and advisory context with external
EDR, firewall, router, switch, DNS, NDR, SIEM, asset, and vulnerability systems
while retaining first-class Edge/Nexus integration.
Knowledge ingests, normalizes, correlates, and advises. It never commands an
endpoint, firewall, network device, or Deception environment.
Deception reports capability and materializes only a bounded, approved
environment. It never chooses an engagement or freely reconfigures a network.
Fabric carries descriptive contracts only. A manifest, signature, capability
report, advisory, or observation cannot be an execution token.
Edge-derived deterministic arbitration remains the only Azazel authority for
autonomous bounded enforcement. External products retain their own approval
and change-management authority.
Delivery order
Fabric: external observation/advisory/proposed-change contracts and negative
authority tests.
Knowledge: read-only adapters and evidence-grounded advisory output.
Deception: read-only network-device observability, controlled-exposure
adapter boundary, and bounded profiles.
Nexus: credential/trust lifecycle, adapter admission, local policy routing,
audit/lease/rollback integration, and HIL.
Edge/Nexus first-party adapters are reference implementations; third-party
adapters remain disabled until their declared evidence and safety gates pass.
Explicit non-goals
a generic remote-command framework;
unrestricted API tokens, shell access, or device configuration templates in
a shared contract;
automatic discovery followed by automatic changes;
treating vendor severity, EDR verdict, or an attacker disappearance as proof
of compromise, containment, or defensive success;
cross-tenant data mixing or forwarding raw sensitive telemetry by default.
Program acceptance
every connector has a declared source/product identity, schema/version,
provenance, freshness, tenancy/privacy class, rate/size budget, and failure
state;
every advisory separates source facts, normalized facts, inference,
limitations, and unknowns;
every device-change proposal is non-executable until routed through an
owning product's approval/lease/rollback process;
loss, malformed data, replay, stale state, credential failure, and
partial-device failure degrade safely and are audit-visible;
Edge/Nexus standalone Core remains independent of every external product;
HIL proves isolation, emergency withdrawal, and evidence preservation for
every enabled exposure/redirect adapter.
Purpose
Evolve Azazel-Knowledge and Azazel-Deception into interoperable defensive
planes that can exchange bounded evidence and advisory context with external
EDR, firewall, router, switch, DNS, NDR, SIEM, asset, and vulnerability systems
while retaining first-class Edge/Nexus integration.
Non-negotiable authority model
endpoint, firewall, network device, or Deception environment.
environment. It never chooses an engagement or freely reconfigures a network.
report, advisory, or observation cannot be an execution token.
autonomous bounded enforcement. External products retain their own approval
and change-management authority.
Delivery order
authority tests.
adapter boundary, and bounded profiles.
audit/lease/rollback integration, and HIL.
adapters remain disabled until their declared evidence and safety gates pass.
Explicit non-goals
a shared contract;
of compromise, containment, or defensive success;
Program acceptance
provenance, freshness, tenancy/privacy class, rate/size budget, and failure
state;
limitations, and unknowns;
owning product's approval/lease/rollback process;
partial-device failure degrade safely and are audit-visible;
every enabled exposure/redirect adapter.