CORE v1.0 · MODULE 05

ARGUS7 / CYBER INFRASTRUCTURE & ATTACK PATH

Cyber

Collegare dominio, IP, ASN, host, servizio, software, vulnerabilità, artefatto e IOC senza confondere esposizione e compromissione.

INPUTSOURCEMODULE ANALYSISEVIDENCEHUMAN REVIEWOUTPUT

01 / CYBER INFRASTRUCTURE & ATTACK PATH

Every visual element is derived from the case dataset.

Zoom, pan, filters, selection and details expose entities, relationships, Source IDs and Evidence IDs. No automatic rotation or random data.

100%
Node depth = analytical distance from public source Verified / corroborated Derived / synthetic5 / 5 NODES · 4 RELATIONSPan: drag · Zoom: controls · No automatic rotation

02 / MODULE SPECIFICATION

Purpose, responsibility and operational boundaries.

This page preserves the names, agents, routing and dependencies of the ARGUS7 baseline.

PURPOSE

Collegare dominio, IP, ASN, host, servizio, software, vulnerabilità, artefatto e IOC senza confondere esposizione e compromissione.

PROTOTYPE
AINPUTS

INPUTS

  • Asset autorizzati
  • Advisory e CVE
  • Log e telemetria
  • IOC contestualizzati
BPROCESS

PROCESS

  • Exposure analysis
  • Attack-path mapping
  • Defensive hunt
  • Incident triage
  • Mitigation mapping
CACTIVATED AGENTS

ACTIVATED AGENTS

  • Cyber Intelligence Agent
  • Local AI via Ollama / LM Studio
  • Forensic HITL
DTOOLS / SOURCES

TOOLS / SOURCES

  • CISA / NVD / vendor advisory
  • SIEM / EDR
  • Threat feeds
  • Memory / RAG
EVALIDATION / EVIDENCE

VALIDATION / EVIDENCE

  • Telemetria primaria
  • Owner e timestamp
  • IOC / behavior correlation
  • HITL sulla compromissione
FOUTPUT

OUTPUT

  • Infrastructure graph
  • Exposure matrix
  • Defensive hunt package
  • Incident decision
CONNECTED MODULES / COMPONENTS
IntelForensicsGraphInvestigationsStrategy

03 / ADVERSARY ACTIVITY ↔ DEFENSIVE RESPONSE

Adversary activity and defensive response, without operationally abusable content.

Publicly documented TTPs are described for detection, triage and mitigation. Exploits, payloads and executable offensive procedures are not published.

ADVERSARY ACTIVITY
  • Known exploitation
  • Living-off-the-land
  • Documented artifacts
  • Credential abuse
DEFENSIVE RESPONSE
  • Exposure validation
  • Telemetry-based hunt
  • Preservation
  • Vendor mitigation

04 / CONNECTED CASES

The module does not operate in isolation.

The same case studies traverse multiple modules, using one data model and one evidence chain.