Liftedbypattern,fromarecordthatisalreadyclosed.
Indicators come out of the transcript the same deterministic way techniques do: addresses, hostnames, paths the session wrote to, tooling it used, and payloads it sent. The extractor is a set of patterns over recorded text, so it is reproducible and it is auditable.
Collected across the whole session
Extraction does not stop at conversion. The behaviour after the swap is frequently the most productive part of the record. Persistence attempts, exfiltration destinations and pivot targets show up there, against backends built to absorb them safely.
Indicators are not verdicts either
An address that appears in a session is an address that appeared in a session. Promoting it to a block list is a rule change, and rule changes go through L8: shadow-tested against recorded benign traffic, then a human.
Payload retention
Payloads are kept because signature candidates are derived from them and because replay needs them. They are attacker-controlled bytes and are treated as such everywhere downstream: stored, never executed, never handed to anything with authority.
Worked against one recorded session
Session sess_7f3a91, 24 observations over 257s. Everything below is generated from that transcript by rule. No model touched any of it.
- 10.0.4.19
- 169.254.169.254
- nc
- find
- grep
- curl
- mysql
- ssh-rsa
- crontab
- /dev/null
- ~/.ssh/authorized_keys
- /tmp/dump.sql
- api.internal
- mysql.internal
- x.sh
- 0a4f7b2c91e6…