Skip to main content

Crate shellhist_forensic

Crate shellhist_forensic 

Source
Expand description

shellhist-forensic — graded anomaly auditor over shell command history.

Consumes shellhist_core::HistoryEntry streams and emits forensicnomicon::report::Findings. Every anomaly is an observation (“consistent with …”); the examiner draws the conclusions. MITRE techniques are narrated as consistency, never as a verdict.

Enums§

HistAnomaly
A graded shell-history anomaly.

Functions§

audit
Audit a history-entry stream for anomalies.
audit_findings
Convenience: audit and convert directly to graded Findings.
source
The Source stamp for findings this analyzer emits.