You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Index of the knowledge/ clean-room knowledge base. Entries are grouped
by domain and tagged with their source_type for provenance. See
knowledge/README.md for the full
licensing policy.
The knowledge base is APTWatcher's grounding surface. When the agent needs
context — "what does a DCSync event look like in Security.evtx?", "what
scheduled-task names are commonly used for masquerading?" —
knowledge_search() is what it calls. Every entry is author-attributable,
every source type is declared, and nothing from proprietary sources is
present. See clean-room policy for the
absolute rules.
This index is generated from the committed corpus: 32 entries, all
source_type: author-original (attribution: "APTWatcher team (clean-room)").
The schema permits other source types (see knowledge/README.md), but none
are currently in use.