whitehat-security/targets/asm-t08.json

44 lines
1.4 KiB
JSON
Raw Normal View History

{
"schema_version": "whitehat-target/v1",
"target_id": "asm-t08",
"posture_claim": "ASM T-08",
"attacker_model": "reconstructing a privileged mutation from protected evidence and checking emission completeness",
"applicability": "pending",
"applicability_reason": "audit-core is a real E2 target, but reconstruction and emission-completeness are a different attacker model. Needs an authorized synthetic mutation and an emission bound from audit-core or kings-guard. Known-bad design: unlink one required record, and separately suppress an emission while leaving the archive chain intact. This registration does not authorize a probe.",
"approval_classes": [
"asm"
],
"specification": "asm-assurance-targets.v1",
"test_id": "T-08",
"title": "Audit Reconstruction Test",
"claims": [
"INV-10",
"A-12"
],
"oracle": "linked-reconstruction-and-emission-gap-detection",
"surface": [
"access-engine",
"emitters",
"audit-core",
"archive"
],
"result_route": {
"conformance": "gate-house",
"implementation_finding": "risk-nexus",
"specification_finding": "gate-house",
"harness_gap": "whitehat-security"
},
"routes": [],
"identities": {
"count": 0,
"role": "none until the owning surface names a test identity",
"broker_audience": "whitehat-asm/t-08"
},
"abort_telemetry": [
"kill_switch",
"scope_boundary",
"missing_known_bad_calibration",
"secret_value_observed"
]
}