whitehat-security/evidence/README.md
tegwick 6f1ca0bfef Add in-process known-bad fixtures for remaining ASM T-01–T-10
Each Canon test now has a fixture-asm registration that fails known-bad
and passes known-good in-process. Live asm-tNN targets stay pending.
No network, OpenBao, or packet.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-02 13:05:42 +02:00

18 lines
950 B
Markdown

# Evidence
This directory stores sanitized run artifacts. `offline-calibration.json`,
`offline-e3-calibration.json`, `offline-capacity-calibration.json`, and
`offline-asm-t01-calibration.json``offline-asm-t10-calibration.json` are
generated from repository-created fixtures and prove only that the harness
distinguishes known-good from known-bad behavior. They are not target
assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
is an abort record (`evidence_class: abort`), not an E2 pass or finding.
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A
run-local digest is allowed; it must not be reusable across runs as a data
oracle.