Skip to content

Adopt an Engage-aligned adversary engagement model across the Azazel System #60

Description

@01rabbit

Summary

Define and adopt a MITRE Engage-aligned adversary engagement model across the Azazel System without weakening the existing deterministic, local-first, advisory-only, and bounded-action guarantees.

This is a system-level doctrine and coordination issue. Product-specific implementation remains in each repository.

Why

Azazel already implements the core operational ideas behind adversary engagement: delaying action, controlled friction, selective redirection, deception, observation, and auditable local decisions. MITRE Engage provides a useful vocabulary and planning structure for expressing the intent behind those actions.

The objective is not to claim formal MITRE certification or to turn Azazel into an offensive or autonomous platform. The intended description is Engage-aligned or Engage-informed.

System responsibility model

  • Azazel defines doctrine, terminology, safety boundaries, and cross-product responsibility.
  • Azazel-Fabric (AZ-05) defines shared engagement contracts and event vocabulary, but no decision logic.
  • Azazel-Edge (AZ-01) builds engagement candidates, makes the final deterministic decision, executes bounded actions, and records outcomes.
  • Azazel-Gadget (AZ-02) supports only constrained, mode-bound engagement profiles suitable for a personal tactical gateway.
  • Azazel-Knowledge (AZ-04) correlates ATT&CK/CTI and attacker reactions, evaluates prior effectiveness, and returns advisory-only posture suggestions.
  • Azazel-Boot (AZ-03) remains observation-first until a repository and explicit safety model exist.

Core rule

Engage expresses intent. Knowledge advises. Fabric describes. Edge decides and executes. Gadget executes only bounded profiles.

Required doctrine additions

  • Define adversary engagement, cyber denial, deception, channeling, collection, and termination in Azazel terminology.
  • Explain the relationship among ATT&CK, MITRE Engage, Behavioral CTI, delaying action, and the Cyber Scapegoat Gateway.
  • Preserve the existing rule that AI may explain or suggest but never select or execute core actions.
  • Explicitly prohibit hack-back, attacker-system compromise, uncontrolled outbound traffic from decoys, autonomous retaliation, and unbounded engagement.
  • Require maximum duration, scope, resource limits, production isolation, operator visibility, termination conditions, and audit evidence for every engagement-capable profile.
  • Define external wording and claim boundaries for documentation, CFPs, papers, and demonstrations.

Cross-repository implementation issues

Recommended implementation order

  1. Ratify doctrine and non-goals in this repository.
  2. Reconcile current Fabric consumer versions and release the additive shared contract.
  3. Implement Knowledge ingest/advisory and Edge shadow/replay consumers against golden fixtures.
  4. Enable Edge candidate evaluation in feature-disabled/shadow mode.
  5. Add Gadget mode-bound profiles after the Fabric contract is stable.
  6. Run cross-repository adversarial, failure, replay, and isolation review before enabling live profiles by default.

Acceptance criteria

  • A doctrine document clearly assigns responsibilities to every AZ class.
  • Safety and non-goal statements are explicit and testable.
  • All child issues link back to this issue.
  • The design remains functional when Knowledge is absent, slow, malformed, or wrong.
  • No shared contract can carry a directive that bypasses a product-local decision authority.
  • Public descriptions use Engage-aligned or Engage-informed, not unsupported compliance or certification claims.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions