Expand description
peripheral-forensic — graded anomaly auditor over external-device
connections.
Consumes peripheral_core::DeviceConnection records and emits
forensicnomicon::report::Findings. Every anomaly is an observation
(“consistent with …”); the examiner draws the conclusions. MITRE techniques
are narrated as consistency, never as a verdict.
Enums§
- Device
Anomaly - A graded external-device anomaly.
Functions§
- audit
- Audit a slice of
DeviceConnections into a typedDeviceAnomalystream. - audit_
findings - Convenience: audit and convert directly to graded
Findings. - source
- The
Sourcestamp for findings this analyzer emits.