Skip to content

Adopt an Engage-aligned adversary engagement model across the Azazel System #60

Description

@01rabbit

Summary

Define and adopt a MITRE Engage-aligned adversary engagement model across the Azazel System without weakening deterministic, local-first, advisory-only, bounded-action, and fail-closed guarantees.

This is the system-level doctrine and coordination issue. Product-specific implementation remains in each repository.

Current series responsibility model

  • Azazel defines doctrine, terminology, safety boundaries, naming, and cross-product responsibility.
  • Azazel-Fabric Contract (AZ-05) defines shared engagement and deception-environment contracts and event vocabulary, but no decision logic.
  • Azazel-Edge Gateway (AZ-01) builds engagement candidates, makes the final deterministic decision, controls routing/exposure/budgets, and owns activation, downgrade, and termination authority.
  • Azazel-Deception Host (AZ-06, THEATRE) materializes Edge-approved coherent deception environments, executes only approved finite-state transitions, records outcomes, and resets. Repository: https://github.com/01rabbit/Azazel-Deception
  • Azazel-Gadget Shield (AZ-02) supports only constrained, mode-bound Engage-lite profiles suitable for personal tactical defense.
  • Azazel-Knowledge Advisor (AZ-04) correlates ATT&CK/CTI and attacker reactions, evaluates prior effectiveness, and returns advisory-only posture suggestions.
  • Azazel-Boot Probe (AZ-03) remains observation-first until its repository and safety model exist.

Core rule

Engage expresses intent. Knowledge advises. Fabric describes. Edge decides and enforces. Deception Host materializes, transitions, records, and resets. Gadget executes only bounded local profiles.

Why AZ-06 exists

Delay/throttle/redirect can influence attacker tempo and action, but coherent deception requires an attacker-facing environment whose services, host history, synthetic artifacts, credentials, personas, and staged exposure remain internally consistent. That runtime responsibility does not belong in Edge's deterministic control plane.

AZ-06 therefore provides a separate Engagement Environment Plane while preserving Edge authority and production-path availability.

Required doctrine

  • Define adversary engagement, cyber denial, deception, channeling, collection, materialization, termination, and reset in Azazel terminology.
  • Explain the relationship among ATT&CK, MITRE Engage, Behavioral CTI, delaying action, Edge routing, and AZ-06 deception environments.
  • Preserve the rule that AI may explain or assist preparation but never select or execute core live actions.
  • Explicitly prohibit hack-back, attacker-system compromise, uncontrolled decoy egress, autonomous retaliation, production access from decoys, and unbounded engagement.
  • Require maximum duration, scope, resource limits, production isolation, operator visibility, termination conditions, reset proof, and audit evidence for every engagement-capable profile.
  • Distinguish observed interaction/reaction/outcome from unsupported claims that an attacker believed the deception.
  • Public wording uses Engage-aligned or Engage-informed, not certification/compliance claims.

Cross-repository implementation

Recommended implementation order

  1. Ratify doctrine, naming, AZ-06 boundary, and non-goals — done for AZ-06 bootstrap.
  2. Reconcile Fabric consumer status and release additive Engage/deception contracts.
  3. Adapt AZ-06 bootstrap schemas to canonical Fabric contracts and add signed OCI provenance/golden fixtures.
  4. Implement Edge + AZ-06 shadow/replay integration with live execution disabled.
  5. Prove isolation, resource limits, evidence export, termination, and deterministic reset on ARM64 and AMD64.
  6. Enable one static live reference environment behind an explicit feature flag.
  7. Implement Knowledge outcome ingest/advisory.
  8. Add Gadget's constrained compatible static subset.
  9. Run cross-repository adversarial/failure review before broader live profiles.

Acceptance criteria

  • Responsibilities are explicit for every AZ class.
  • Edge remains the only full engagement activation/transition authority.
  • AZ-06 cannot infer authority from package content, Fabric data, Knowledge advice, or local capability.
  • Safety/non-goal statements are testable.
  • System remains functional when Knowledge or AZ-06 is absent, slow, malformed, unsupported, or wrong.
  • No shared contract carries a directive that bypasses product-local authority.
  • No decoy route or credential can reach protected production assets.
  • Public claims distinguish denial/delay, deception, and measured effectiveness.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions