Merge commit 'd803bfe2b1fe7f5e219e50ac20d6801a0a58ac75' as 'vendor/ruvector'

This commit is contained in:
ruv
2026-02-28 14:39:40 -05:00
7854 changed files with 3522914 additions and 0 deletions
@@ -0,0 +1 @@
{"version":3,"file":"index.d.ts","sourceRoot":"","sources":["index.ts"],"names":[],"mappings":"AAAA;;;;;;;;GAQG;AAEH,OAAO,EAAE,YAAY,EAAE,MAAM,QAAQ,CAAC;AACtC,OAAO,EAAgB,WAAW,EAAE,gBAAgB,EAAgB,MAAM,yBAAyB,CAAC;AAEpG;;GAEG;AACH,MAAM,MAAM,qBAAqB,GAAG,UAAU,GAAG,MAAM,GAAG,QAAQ,GAAG,KAAK,GAAG,MAAM,CAAC;AAEpF;;GAEG;AACH,MAAM,MAAM,iBAAiB,GACzB,eAAe,GACf,KAAK,GACL,MAAM,GACN,KAAK,GACL,gBAAgB,GAChB,uBAAuB,GACvB,sBAAsB,GACtB,KAAK,GACL,wBAAwB,GACxB,kBAAkB,CAAC;AAEvB;;GAEG;AACH,MAAM,WAAW,qBAAqB;IACpC,EAAE,EAAE,MAAM,CAAC;IACX,IAAI,EAAE,iBAAiB,CAAC;IACxB,QAAQ,EAAE,qBAAqB,CAAC;IAChC,WAAW,EAAE,MAAM,CAAC;IACpB,MAAM,EAAE,MAAM,CAAC;IACf,OAAO,EAAE,MAAM,CAAC;IAChB,cAAc,EAAE,MAAM,CAAC;IACvB,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,IAAI,CAAC,EAAE,MAAM,CAAC;CACf;AAED;;GAEG;AACH,MAAM,WAAW,gBAAgB;IAC/B,SAAS,EAAE,IAAI,CAAC;IAChB,KAAK,EAAE,OAAO,GAAG,MAAM,GAAG,SAAS,GAAG,OAAO,GAAG,UAAU,CAAC;IAC3D,MAAM,EAAE,MAAM,CAAC;IACf,SAAS,EAAE,MAAM,CAAC;IAClB,OAAO,EAAE,MAAM,CAAC;IAChB,EAAE,CAAC,EAAE,MAAM,CAAC;IACZ,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,OAAO,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,OAAO,CAAC,CAAC;CACnC;AAED;;GAEG;AACH,MAAM,WAAW,cAAc;IAC7B,EAAE,EAAE,MAAM,CAAC;IACX,IAAI,EAAE,aAAa,GAAG,WAAW,GAAG,mBAAmB,GAAG,iBAAiB,GAAG,oBAAoB,CAAC;IACnG,UAAU,EAAE,MAAM,CAAC;IACnB,UAAU,EAAE,MAAM,EAAE,CAAC;IACrB,iBAAiB,EAAE,MAAM,EAAE,CAAC;IAC5B,QAAQ,EAAE,IAAI,EAAE,CAAC;CAClB;AAED;;GAEG;AACH,MAAM,WAAW,uBAAuB;IACtC,EAAE,EAAE,MAAM,CAAC;IACX,IAAI,EAAE,MAAM,CAAC;IACb,SAAS,EAAE,MAAM,CAAC;IAClB,YAAY,EAAE,MAAM,CAAC;IACrB,YAAY,EAAE,MAAM,CAAC;IACrB,KAAK,EAAE,KAAK,CAAC;QACX,IAAI,EAAE,MAAM,CAAC;QACb,MAAM,EAAE,MAAM,CAAC;QACf,IAAI,CAAC,EAAE,MAAM,CAAC;QACd,OAAO,CAAC,EAAE,MAAM,CAAC;QACjB,eAAe,EAAE,MAAM,CAAC;KACzB,CAAC,CAAC;IACH,eAAe,EAAE,MAAM,EAAE,CAAC;IAC1B,WAAW,EAAE,MAAM,EAAE,CAAC;CACvB;AAED;;GAEG;AACH,MAAM,WAAW,qBAAsB,SAAQ,OAAO,CAAC,WAAW,CAAC;IACjE,WAAW,CAAC,EAAE,MAAM,EAAE,CAAC;IACvB,eAAe,CAAC,EAAE,OAAO,CAAC;IAC1B,cAAc,CAAC,EAAE,qBAAqB,EAAE,CAAC;IACzC,SAAS,CAAC,EAAE,MAAM,GAAG,QAAQ,GAAG,QAAQ,CAAC;CAC1C;AAED;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;GAuCG;AACH,qBAAa,wBAAyB,SAAQ,YAAY;IACxD,OAAO,CAAC,KAAK,CAAe;IAC5B,OAAO,CAAC,MAAM,CAAwB;IACtC,OAAO,CAAC,wBAAwB,CAA+B;IAC/D,OAAO,CAAC,aAAa,CAA0B;IAC/C,OAAO,CAAC,iBAAiB,CAAwB;gBAErC,MAAM,GAAE,qBAA0B;IAuB9C;;OAEG;IACG,uBAAuB,CAAC,OAAO,GAAE;QACrC,KAAK,CAAC,EAAE,MAAM,CAAC;QACf,KAAK,CAAC,EAAE,iBAAiB,EAAE,CAAC;QAC5B,QAAQ,CAAC,EAAE,qBAAqB,CAAC;KAC7B,GAAG,OAAO,CAAC,gBAAgB,CAAC,qBAAqB,CAAC,CAAC;IA0DzD;;OAEG;IACG,oBAAoB,CAAC,OAAO,GAAE;QAClC,KAAK,CAAC,EAAE,MAAM,CAAC;QACf,SAAS,CAAC,EAAE,IAAI,CAAC;QACjB,OAAO,CAAC,EAAE,IAAI,CAAC;QACf,gBAAgB,CAAC,EAAE,OAAO,CAAC;QAC3B,OAAO,CAAC,EAAE,MAAM,EAAE,CAAC;KACf,GAAG,OAAO,CAAC,gBAAgB,CAAC,gBAAgB,CAAC,CAAC;IAqDpD;;OAEG;IACG,uBAAuB,CAAC,OAAO,GAAE;QACrC,MAAM,CAAC,EAAE,MAAM,CAAC;QAChB,UAAU,CAAC,EAAE,OAAO,GAAG,cAAc,GAAG,UAAU,CAAC;QACnD,SAAS,CAAC,EAAE,MAAM,CAAC;KACf,GAAG,OAAO,CAAC,uBAAuB,CAAC;IA6CzC;;OAEG;IACG,eAAe,CAAC,IAAI,CAAC,EAAE,gBAAgB,EAAE,GAAG,OAAO,CAAC,cAAc,EAAE,CAAC;IAmC3E;;OAEG;IACH,aAAa,IAAI;QACf,oBAAoB,EAAE,MAAM,CAAC;QAC7B,aAAa,EAAE,MAAM,CAAC;QACtB,SAAS,EAAE,MAAM,CAAC;QAClB,YAAY,EAAE,MAAM,CAAC;QACrB,oBAAoB,EAAE,MAAM,CAAC,qBAAqB,EAAE,MAAM,CAAC,CAAC;KAC7D;IAsBD;;OAEG;IACH,UAAU,CAAC,MAAM,GAAE,MAAM,GAAG,KAAc,GAAG,MAAM;IAoBnD;;OAEG;IACH,KAAK,IAAI,IAAI;IAQb;;OAEG;YACW,eAAe;IAgB7B;;OAEG;IACH,OAAO,CAAC,aAAa;IASrB;;OAEG;IACH,OAAO,CAAC,UAAU;CAGnB;AAED;;GAEG;AACH,wBAAgB,8BAA8B,CAAC,MAAM,CAAC,EAAE,qBAAqB,GAAG,wBAAwB,CAEvG"}
File diff suppressed because one or more lines are too long
@@ -0,0 +1,501 @@
/**
* Security Testing Generator - Penetration testing and vulnerability data
*
* Generates realistic security testing scenarios, vulnerability data, attack patterns,
* and log analytics for testing security systems, training ML models, and conducting
* security research.
*
* @packageDocumentation
*/
import { EventEmitter } from 'events';
import { AgenticSynth, SynthConfig, GenerationResult, EventOptions } from '@ruvector/agentic-synth';
/**
* Vulnerability severity levels
*/
export type VulnerabilitySeverity = 'critical' | 'high' | 'medium' | 'low' | 'info';
/**
* Common vulnerability types
*/
export type VulnerabilityType =
| 'sql-injection'
| 'xss'
| 'csrf'
| 'rce'
| 'path-traversal'
| 'authentication-bypass'
| 'privilege-escalation'
| 'dos'
| 'information-disclosure'
| 'misconfiguration';
/**
* Vulnerability test case
*/
export interface VulnerabilityTestCase {
id: string;
type: VulnerabilityType;
severity: VulnerabilitySeverity;
description: string;
target: string;
payload: string;
expectedResult: string;
cwe?: string; // Common Weakness Enumeration ID
cvss?: number; // CVSS score (0-10)
}
/**
* Security log entry
*/
export interface SecurityLogEntry {
timestamp: Date;
level: 'debug' | 'info' | 'warning' | 'error' | 'critical';
source: string;
eventType: string;
message: string;
ip?: string;
user?: string;
details?: Record<string, unknown>;
}
/**
* Anomaly detection pattern
*/
export interface AnomalyPattern {
id: string;
type: 'brute-force' | 'port-scan' | 'data-exfiltration' | 'privilege-abuse' | 'suspicious-traffic';
confidence: number; // 0-1
indicators: string[];
affectedResources: string[];
timeline: Date[];
}
/**
* Penetration testing scenario
*/
export interface PenetrationTestScenario {
id: string;
name: string;
objective: string;
targetSystem: string;
attackVector: string;
steps: Array<{
step: number;
action: string;
tool?: string;
command?: string;
expectedOutcome: string;
}>;
successCriteria: string[];
mitigations: string[];
}
/**
* Security testing configuration
*/
export interface SecurityTestingConfig extends Partial<SynthConfig> {
targetTypes?: string[]; // Types of systems to target
includePayloads?: boolean; // Include actual exploit payloads
severityFilter?: VulnerabilitySeverity[]; // Filter by severity
logFormat?: 'json' | 'syslog' | 'custom';
}
/**
* Security Testing Generator for penetration testing and vulnerability research
*
* Features:
* - Vulnerability test case generation
* - Penetration testing scenarios
* - Security log analytics data
* - Anomaly detection patterns
* - Attack simulation data
* - CVSS scoring and CWE mapping
*
* @example
* ```typescript
* const generator = new SecurityTestingGenerator({
* provider: 'gemini',
* apiKey: process.env.GEMINI_API_KEY,
* includePayloads: true,
* severityFilter: ['critical', 'high']
* });
*
* // Generate vulnerability test cases
* const vulns = await generator.generateVulnerabilities({
* count: 20,
* types: ['sql-injection', 'xss', 'rce']
* });
*
* // Generate security logs
* const logs = await generator.generateSecurityLogs({
* count: 1000,
* startDate: new Date('2024-01-01'),
* includeAnomalies: true
* });
*
* // Create penetration test scenario
* const scenario = await generator.generatePentestScenario({
* target: 'web-application',
* complexity: 'advanced'
* });
* ```
*/
export class SecurityTestingGenerator extends EventEmitter {
private synth: AgenticSynth;
private config: SecurityTestingConfig;
private generatedVulnerabilities: VulnerabilityTestCase[] = [];
private generatedLogs: SecurityLogEntry[] = [];
private detectedAnomalies: AnomalyPattern[] = [];
constructor(config: SecurityTestingConfig = {}) {
super();
this.config = {
provider: config.provider || 'gemini',
apiKey: config.apiKey || process.env.GEMINI_API_KEY || '',
...(config.model && { model: config.model }),
cacheStrategy: config.cacheStrategy || 'memory',
cacheTTL: config.cacheTTL || 3600,
maxRetries: config.maxRetries || 3,
timeout: config.timeout || 30000,
streaming: config.streaming || false,
automation: config.automation || false,
vectorDB: config.vectorDB || false,
targetTypes: config.targetTypes || ['web', 'api', 'network', 'system'],
includePayloads: config.includePayloads ?? true,
severityFilter: config.severityFilter || ['critical', 'high', 'medium', 'low', 'info'],
logFormat: config.logFormat || 'json'
};
this.synth = new AgenticSynth(this.config);
}
/**
* Generate vulnerability test cases
*/
async generateVulnerabilities(options: {
count?: number;
types?: VulnerabilityType[];
severity?: VulnerabilitySeverity;
} = {}): Promise<GenerationResult<VulnerabilityTestCase>> {
this.emit('vulnerabilities:generating', { options });
try {
const result = await this.synth.generateStructured<{
type: string;
severity: string;
description: string;
target: string;
payload: string;
expectedResult: string;
cwe: string;
cvss: number;
}>({
count: options.count || 10,
schema: {
type: { type: 'string', enum: options.types || ['sql-injection', 'xss', 'csrf'] },
severity: { type: 'string', enum: this.config.severityFilter },
description: { type: 'string' },
target: { type: 'string' },
payload: { type: 'string' },
expectedResult: { type: 'string' },
cwe: { type: 'string' },
cvss: { type: 'number', minimum: 0, maximum: 10 }
}
});
const vulnerabilities: VulnerabilityTestCase[] = result.data.map(v => ({
id: this.generateId('vuln'),
type: v.type as VulnerabilityType,
severity: v.severity as VulnerabilitySeverity,
description: v.description,
target: v.target,
payload: this.config.includePayloads ? v.payload : '[REDACTED]',
expectedResult: v.expectedResult,
cwe: v.cwe,
cvss: v.cvss
}));
// Filter by severity if specified
const filtered = options.severity
? vulnerabilities.filter(v => v.severity === options.severity)
: vulnerabilities;
this.generatedVulnerabilities.push(...filtered);
this.emit('vulnerabilities:generated', { count: filtered.length });
return {
data: filtered,
metadata: result.metadata
};
} catch (error) {
this.emit('vulnerabilities:error', { error });
throw error;
}
}
/**
* Generate security log entries
*/
async generateSecurityLogs(options: {
count?: number;
startDate?: Date;
endDate?: Date;
includeAnomalies?: boolean;
sources?: string[];
} = {}): Promise<GenerationResult<SecurityLogEntry>> {
this.emit('logs:generating', { options });
try {
const eventOptions: Partial<EventOptions> = {
count: options.count || 100,
eventTypes: ['login', 'logout', 'access', 'error', 'warning', 'attack'],
distribution: 'poisson',
timeRange: {
start: options.startDate || new Date(Date.now() - 7 * 24 * 60 * 60 * 1000),
end: options.endDate || new Date()
}
};
const result = await this.synth.generateEvents<{
level: string;
source: string;
eventType: string;
message: string;
ip: string;
user: string;
}>(eventOptions);
const logs: SecurityLogEntry[] = result.data.map(event => ({
timestamp: new Date(),
level: this.parseLogLevel(event.level),
source: event.source || 'system',
eventType: event.eventType,
message: event.message,
ip: event.ip,
user: event.user,
details: {}
}));
// Inject anomalies if requested
if (options.includeAnomalies) {
await this.injectAnomalies(logs);
}
this.generatedLogs.push(...logs);
this.emit('logs:generated', { count: logs.length });
return {
data: logs,
metadata: result.metadata
};
} catch (error) {
this.emit('logs:error', { error });
throw error;
}
}
/**
* Generate penetration testing scenario
*/
async generatePentestScenario(options: {
target?: string;
complexity?: 'basic' | 'intermediate' | 'advanced';
objective?: string;
} = {}): Promise<PenetrationTestScenario> {
this.emit('pentest:generating', { options });
try {
const result = await this.synth.generateStructured<{
name: string;
objective: string;
targetSystem: string;
attackVector: string;
steps: Array<{
step: number;
action: string;
tool: string;
command: string;
expectedOutcome: string;
}>;
successCriteria: string[];
mitigations: string[];
}>({
count: 1,
schema: {
name: { type: 'string' },
objective: { type: 'string' },
targetSystem: { type: 'string' },
attackVector: { type: 'string' },
steps: { type: 'array', items: { type: 'object' } },
successCriteria: { type: 'array', items: { type: 'string' } },
mitigations: { type: 'array', items: { type: 'string' } }
}
});
const scenario: PenetrationTestScenario = {
id: this.generateId('pentest'),
...result.data[0]
};
this.emit('pentest:generated', { scenarioId: scenario.id });
return scenario;
} catch (error) {
this.emit('pentest:error', { error });
throw error;
}
}
/**
* Detect anomaly patterns in logs
*/
async detectAnomalies(logs?: SecurityLogEntry[]): Promise<AnomalyPattern[]> {
const targetLogs = logs || this.generatedLogs;
if (targetLogs.length === 0) {
return [];
}
this.emit('anomaly:detecting', { logCount: targetLogs.length });
// Simple pattern detection (in real scenario, use ML models)
const patterns: AnomalyPattern[] = [];
// Detect brute force attempts
const loginAttempts = targetLogs.filter(log =>
log.eventType === 'login' && log.level === 'error'
);
if (loginAttempts.length > 10) {
patterns.push({
id: this.generateId('anomaly'),
type: 'brute-force',
confidence: Math.min(loginAttempts.length / 50, 1),
indicators: ['multiple-failed-logins', 'same-source-ip'],
affectedResources: [...new Set(loginAttempts.map(l => l.user || 'unknown'))],
timeline: loginAttempts.map(l => l.timestamp)
});
}
this.detectedAnomalies.push(...patterns);
this.emit('anomaly:detected', { count: patterns.length });
return patterns;
}
/**
* Get security statistics
*/
getStatistics(): {
totalVulnerabilities: number;
criticalCount: number;
totalLogs: number;
anomalyCount: number;
severityDistribution: Record<VulnerabilitySeverity, number>;
} {
const severityDistribution: Record<VulnerabilitySeverity, number> = {
critical: 0,
high: 0,
medium: 0,
low: 0,
info: 0
};
this.generatedVulnerabilities.forEach(v => {
severityDistribution[v.severity]++;
});
return {
totalVulnerabilities: this.generatedVulnerabilities.length,
criticalCount: severityDistribution.critical,
totalLogs: this.generatedLogs.length,
anomalyCount: this.detectedAnomalies.length,
severityDistribution
};
}
/**
* Export logs to specified format
*/
exportLogs(format: 'json' | 'csv' = 'json'): string {
if (format === 'json') {
return JSON.stringify(this.generatedLogs, null, 2);
}
// CSV format
const headers = ['timestamp', 'level', 'source', 'eventType', 'message', 'ip', 'user'];
const rows = this.generatedLogs.map(log => [
log.timestamp.toISOString(),
log.level,
log.source,
log.eventType,
log.message,
log.ip || '',
log.user || ''
].join(','));
return [headers.join(','), ...rows].join('\n');
}
/**
* Reset generator state
*/
reset(): void {
this.generatedVulnerabilities = [];
this.generatedLogs = [];
this.detectedAnomalies = [];
this.emit('reset', { timestamp: new Date() });
}
/**
* Inject anomalies into log data
*/
private async injectAnomalies(logs: SecurityLogEntry[]): Promise<void> {
// Inject brute force pattern
const bruteForceCount = Math.floor(logs.length * 0.05);
for (let i = 0; i < bruteForceCount; i++) {
logs.push({
timestamp: new Date(Date.now() - Math.random() * 24 * 60 * 60 * 1000),
level: 'error',
source: 'auth',
eventType: 'login',
message: 'Failed login attempt',
ip: '192.168.1.' + Math.floor(Math.random() * 255),
user: 'admin'
});
}
}
/**
* Parse log level string
*/
private parseLogLevel(level: string): 'debug' | 'info' | 'warning' | 'error' | 'critical' {
const lower = level.toLowerCase();
if (lower.includes('crit')) return 'critical';
if (lower.includes('err')) return 'error';
if (lower.includes('warn')) return 'warning';
if (lower.includes('debug')) return 'debug';
return 'info';
}
/**
* Generate unique ID
*/
private generateId(prefix: string): string {
return `${prefix}_${Date.now()}_${Math.random().toString(36).substring(2, 9)}`;
}
}
/**
* Create a new security testing generator instance
*/
export function createSecurityTestingGenerator(config?: SecurityTestingConfig): SecurityTestingGenerator {
return new SecurityTestingGenerator(config);
}