Skip to content

[program] External defensive-platform interoperability: Knowledge advisory and Deception engagement planes #83

Description

@01rabbit

Purpose

Evolve Azazel-Knowledge and Azazel-Deception into interoperable defensive
planes that can exchange bounded evidence and advisory context with external
EDR, firewall, router, switch, DNS, NDR, SIEM, asset, and vulnerability systems
while retaining first-class Edge/Nexus integration.

Non-negotiable authority model

External products -> observed telemetry -> Knowledge -> advisory context
                                                |
Edge/Nexus deterministic arbiter ----------------+-> approved bounded decision
                                                |
                                  Deception / approved device adapter
                                                |
                                  observation and evidence only
  • Knowledge ingests, normalizes, correlates, and advises. It never commands an
    endpoint, firewall, network device, or Deception environment.
  • Deception reports capability and materializes only a bounded, approved
    environment. It never chooses an engagement or freely reconfigures a network.
  • Fabric carries descriptive contracts only. A manifest, signature, capability
    report, advisory, or observation cannot be an execution token.
  • Edge-derived deterministic arbitration remains the only Azazel authority for
    autonomous bounded enforcement. External products retain their own approval
    and change-management authority.

Delivery order

  1. Fabric: external observation/advisory/proposed-change contracts and negative
    authority tests.
  2. Knowledge: read-only adapters and evidence-grounded advisory output.
  3. Deception: read-only network-device observability, controlled-exposure
    adapter boundary, and bounded profiles.
  4. Nexus: credential/trust lifecycle, adapter admission, local policy routing,
    audit/lease/rollback integration, and HIL.
  5. Edge/Nexus first-party adapters are reference implementations; third-party
    adapters remain disabled until their declared evidence and safety gates pass.

Explicit non-goals

  • a generic remote-command framework;
  • unrestricted API tokens, shell access, or device configuration templates in
    a shared contract;
  • automatic discovery followed by automatic changes;
  • treating vendor severity, EDR verdict, or an attacker disappearance as proof
    of compromise, containment, or defensive success;
  • cross-tenant data mixing or forwarding raw sensitive telemetry by default.

Program acceptance

  • every connector has a declared source/product identity, schema/version,
    provenance, freshness, tenancy/privacy class, rate/size budget, and failure
    state;
  • every advisory separates source facts, normalized facts, inference,
    limitations, and unknowns;
  • every device-change proposal is non-executable until routed through an
    owning product's approval/lease/rollback process;
  • loss, malformed data, replay, stale state, credential failure, and
    partial-device failure degrade safely and are audit-visible;
  • Edge/Nexus standalone Core remains independent of every external product;
  • HIL proves isolation, emergency withdrawal, and evidence preservation for
    every enabled exposure/redirect adapter.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions