2026-08-21 22:52:37 +02:00
|
|
|
# Scope
|
|
|
|
|
|
|
|
|
|
## One-liner
|
|
|
|
|
|
|
|
|
|
`whitehat-security` is NetKingdom's authorization-bound offensive-security
|
|
|
|
|
tooling for producing adversarial evidence about security claims.
|
|
|
|
|
|
|
|
|
|
## Core idea
|
|
|
|
|
|
|
|
|
|
The repository turns stated security properties into dated, reproducible attack
|
|
|
|
|
attempts. It remains separate from the systems it tests, reports findings
|
|
|
|
|
without grading their severity, and never treats a passing probe as proof that a
|
|
|
|
|
boundary always holds.
|
|
|
|
|
|
|
|
|
|
## In scope
|
|
|
|
|
|
|
|
|
|
- Attacker models for tenant isolation, credential confinement, noisy-neighbour
|
|
|
|
|
behavior and erasure verification.
|
|
|
|
|
- Differential probes that compare behavior across controlled tenant contexts.
|
|
|
|
|
- Known-bad and known-good fixtures that demonstrate every probe can fail.
|
|
|
|
|
- Rules of engagement, target authorization, engagement records, abort
|
|
|
|
|
controls and evidence minimization.
|
|
|
|
|
- Probe cadence and the resulting assurance/exposure window.
|
|
|
|
|
- Delivery of findings and passing-run evidence to `risk-nexus`.
|
|
|
|
|
|
|
|
|
|
## Out of scope
|
|
|
|
|
|
|
|
|
|
- Fixing defects in target repositories.
|
|
|
|
|
- Assigning severity, disclosure policy or remediation deadlines.
|
|
|
|
|
- Replacing mechanical checks owned by a target repository's CI.
|
|
|
|
|
- Defining the estate's security model or publishing permanent policy.
|
|
|
|
|
- Probing any target without the authorization and engagement records required
|
|
|
|
|
by [the rules of engagement](docs/rules-of-engagement.md).
|
|
|
|
|
- Blocking build-mode delivery without a separately recorded decision.
|
|
|
|
|
|
|
|
|
|
## Safety invariants
|
|
|
|
|
|
2026-08-21 23:09:22 +02:00
|
|
|
- The rules of engagement are accepted, but their acceptance authorizes no live
|
|
|
|
|
target. Without a complete approved engagement record, only documentation
|
|
|
|
|
and non-networked fixture design may proceed.
|
2026-08-21 22:52:37 +02:00
|
|
|
- No live target is authorized by this scope document.
|
|
|
|
|
- Every live run names its authorization, target, owner, window, technique,
|
|
|
|
|
credential lane, rate ceiling, abort contact and finding destination.
|
|
|
|
|
- A probe stops at the recorded boundary and never follows an adjacent system.
|
|
|
|
|
- Evidence records response shape and counts, never real tenant row values or
|
|
|
|
|
credentials.
|
|
|
|
|
- Findings leave this repository; repairs do not enter it.
|
|
|
|
|
|
|
|
|
|
## Relevant when
|
|
|
|
|
|
|
|
|
|
- A service claims a Tenancy Posture evidence level that requires adversarial
|
|
|
|
|
rather than mechanical evidence.
|
|
|
|
|
- A boundary must be tested using a leaked runtime credential or hostile tenant
|
|
|
|
|
context.
|
|
|
|
|
- The estate needs to know when a probe last ran, what attacker it modeled, and
|
|
|
|
|
whether it was proven against a known-bad fixture.
|
|
|
|
|
|
|
|
|
|
## Not relevant when
|
|
|
|
|
|
|
|
|
|
- A repository needs unit, schema or provisioning tests for its own code.
|
|
|
|
|
- A finding needs triage, severity or disclosure handling; use `risk-nexus`.
|
|
|
|
|
- Permanent policy needs publication; use `policy-nexus`.
|
|
|
|
|
- The desired activity falls outside an approved engagement boundary.
|
|
|
|
|
|
|
|
|
|
## Current state
|
|
|
|
|
|
|
|
|
|
- Repository status: active.
|
2026-08-23 00:42:31 +02:00
|
|
|
- Active plan: `WHITEHAT-WP-0001`. Meantime polish: `WHITEHAT-WP-0002` through
|
|
|
|
|
`WHITEHAT-WP-0005` (Railiance WP-0025 custody adapter and fail-closed
|
|
|
|
|
admission).
|
2026-08-21 23:09:22 +02:00
|
|
|
- `T01` is complete: the rules of engagement were accepted on 2026-08-21.
|
|
|
|
|
- `T02` is complete: the per-axis attacker model is recorded in
|
|
|
|
|
`docs/attacker-model.md`.
|
2026-08-23 00:42:31 +02:00
|
|
|
- `T03` is complete for currently applicable E2 targets: `audit-core` has
|
|
|
|
|
dated pass `WH-ENG-20260822-AUDIT-E2-03`; `tenant-engine` remains
|
|
|
|
|
`not_applicable`. `flex-auth` is still pending. `-01` and `-02` are
|
|
|
|
|
terminal without E2 evidence.
|
2026-08-22 00:44:21 +02:00
|
|
|
- `T04` is complete for every applicable E2 probe: generic and audit-core
|
|
|
|
|
shaped fixtures fail known-bad and pass known-good in-process.
|
2026-08-22 09:40:27 +02:00
|
|
|
- `T05` is in progress: 24-hour cadence, offline evaluator and in-process
|
2026-08-22 20:20:38 +02:00
|
|
|
calibration exist; `platform-pg` is `not_applicable` for the requested
|
|
|
|
|
runtime identity.
|
2026-08-22 09:40:27 +02:00
|
|
|
- `T06` is in progress: the characterization evaluator is calibrated
|
|
|
|
|
in-process; `shared-substrate` is pending a live window and ceiling.
|
2026-08-23 00:42:31 +02:00
|
|
|
- `T07` is complete: the `-03` sanitized pass was delivered to `risk-nexus`
|
|
|
|
|
as `40e3f825-fc70-4091-96d2-9ab01d42184a`.
|
2026-08-22 00:44:21 +02:00
|
|
|
- `T08` is the governed test plane contract. Cluster provisioning is outside
|
|
|
|
|
this repository.
|
2026-08-23 00:42:31 +02:00
|
|
|
- `-03` is terminal. A later live run needs a new engagement ID, plane
|
|
|
|
|
admission, and approvals. `flex-auth` and P1/P2 remain unrun.
|
2026-08-21 22:52:37 +02:00
|
|
|
|
|
|
|
|
## Relationships
|
|
|
|
|
|
|
|
|
|
- Owner and security canon: `net-kingdom`.
|
|
|
|
|
- Finding intake, severity and disclosure: `risk-nexus`.
|
|
|
|
|
- Permanent publication: `policy-nexus`.
|
|
|
|
|
- Initial proposed target owners: `tenant-engine`, `audit-core` and
|
|
|
|
|
`flex-auth`.
|
|
|
|
|
|
|
|
|
|
## Getting oriented
|
|
|
|
|
|
|
|
|
|
1. Read [`INTENT.md`](INTENT.md) for the durable purpose and ownership model.
|
|
|
|
|
2. Read [the rules of engagement](docs/rules-of-engagement.md) before any probe
|
|
|
|
|
design or execution.
|
|
|
|
|
3. Read [`WHITEHAT-WP-0001`](workplans/WHITEHAT-WP-0001-cross-tenant-evidence.md)
|
|
|
|
|
for active tasks and sequencing.
|