[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"project-92708":3},{"id":4,"name":5,"fullName":6,"owner":7,"repo":5,"description":8,"homepage":9,"htmlUrl":9,"language":10,"languages":9,"totalLinesOfCode":9,"stars":11,"forks":12,"watchers":13,"openIssues":14,"contributorsCount":14,"subscribersCount":14,"size":14,"stars1d":14,"stars7d":14,"stars30d":15,"stars90d":14,"forks30d":14,"starsTrendScore":14,"compositeScore":16,"rankGlobal":9,"rankLanguage":9,"license":9,"archived":17,"fork":17,"defaultBranch":18,"hasWiki":19,"hasPages":17,"topics":20,"createdAt":9,"pushedAt":9,"updatedAt":21,"readmeContent":22,"aiSummary":23,"trendingCount":14,"starSnapshotCount":14,"syncStatus":15,"lastSyncTime":24,"discoverSource":25},92708,"XORCISM","XORCISM-AI\u002FXORCISM","XORCISM-AI","XORCISM is a cybersecurity project for an open unified platform for cyber exposure management, and tools",null,"TypeScript",56,27,53,0,2,41.54,false,"main",true,[],"2026-07-22 04:02:06","# XORCISM — Open Unified Cybersecurity Management Platform\n\n> **Global Cyber Risk Exposure.** One self-hosted platform to manage assets,\n> configuration, vulnerabilities, threats, compliance and incidents — and turn\n> them into a single, continuously-recomputed enterprise risk score.\n\n![TypeScript](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FTypeScript-5-3178C6?logo=typescript&logoColor=white)\n![Node.js](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FNode.js-20_LTS-339933?logo=node.js&logoColor=white)\n![Express](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FExpress-4-000000?logo=express&logoColor=white)\n![SQLite](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FSQLite-better--sqlite3-003B57?logo=sqlite&logoColor=white)\n![PostgreSQL](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FPostgreSQL-portable-4169E1?logo=postgresql&logoColor=white)\n![MySQL](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FMySQL%2FMariaDB-portable-4479A1?logo=mysql&logoColor=white)\n![Python](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FPython-3.11+-3776AB?logo=python&logoColor=white)\n![Docker](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FDocker-Compose-2496ED?logo=docker&logoColor=white)\n![MITRE ATT&CK](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FMITRE-ATT%26CK%20%C2%B7%20D3FEND%20%C2%B7%20CAPEC-C8102E)\n![EBIOS RM](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FEBIOS-Risk%20Manager-0055A4)\n![STIX\u002FTAXII](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FSTIX%2FTAXII-2.1-6f42c1)\n![Self-hosted](https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FSelf--hosted-✔-success)\n\n**🇬🇧 English · [🇫🇷 Français](README.fr.md)**\n\n**🌐 [xorcism.ai](https:\u002F\u002Fxorcism.ai) · 📖 [Installation](SETUP.MD) · 🧩 [Requirements](REQUIREMENTS.MD) · ▶ [YouTube channel](https:\u002F\u002Fwww.youtube.com\u002Fchannel\u002FUCk6OWxMBg1H4gHTZdpZGAhA)**\n\n---\n\n## 🎯 Overview\n\nSecurity teams juggle a dozen disconnected tools — a CMDB here, a vulnerability\nscanner there, a GRC spreadsheet, a CTI feed, a ticketing system, a risk\nregister — and spend most of their time reconciling them instead of reducing\nrisk. XORCISM unifies the whole **cyber-exposure lifecycle** behind one\nschema-driven application and one identity model, so every asset, CVE, control,\nthreat actor and incident lives in the same place and feeds the same risk score.\n\nAnd it doesn't stop at inventory: a built-in **offensive-to-defensive loop**\nchains recon and exploitation tools, prioritizes what is *truly* exploitable,\nvalidates the attack paths to your crown jewels, quantifies the dollar impact,\nand proves your controls — continuously, from OSINT to the boardroom.\n\nIt is **fully self-hosted**: a Node.js\u002FTypeScript server over a family of SQLite\ndatabases (zero-config by default, **portable to PostgreSQL \u002F MySQL \u002F MariaDB** —\nsee [§ Database backends](docs\u002FDATABASE_BACKENDS.md)), with optional Python importers\nand connectors. No SaaS, no telemetry, your data never leaves your infrastructure.\n\n### Who it is for\n\n| Profile | How they use XORCISM |\n|---|---|\n| **CISO \u002F RSSI** | Enterprise risk score, executive dashboard, compliance posture, EBIOS RM studies |\n| **VOC \u002F Vulnerability analyst** | Asset inventory, CVE\u002FKEV\u002FEPSS triage, connector-driven scan ingestion |\n| **GRC \u002F Auditor** | Policies & controls, audits, evidence, findings workflow, OCIL questionnaires |\n| **CTI \u002F Threat analyst** | STIX entities, ATT&CK\u002FD3FEND\u002FA3M matrices, hunts, hypotheses, threat graph |\n| **Red \u002F Purple team** | Tool-chaining attack playbooks (OSINT→exploit, Metasploit), attack-path & choke-point analysis, purple-team detection coverage, **BAS\u002FAEV** adversary emulation (a curated, safe-by-design atomic-test library — 61 tests \u002F 58 MITRE ATT&CK techniques — run by the endpoint agent), bug-bounty programs |\n| **SOC \u002F Blue team** | Alert & incident management, ticketing, detection-to-response |\n\n### Why XORCISM\n\n- **One risk model.** Assets, vulnerabilities and value combine into a per-asset\n  `RiskScore` and a per-tenant `EnterpriseRiskScore`, recomputed every 30 s.\n- **Closed-loop exposure management.** One continuous flow — **discover** (OSINT\n  chain + auto-inventory) → **prioritize** (exploitability fusion) → **validate**\n  (attack paths & purple-team) → **quantify** ($ ransomware impact) → **defend**\n  (detection coverage, D3FEND) → **comply** (controls proven live from telemetry).\n  No tool-stitching, no spreadsheets in between.\n- **Schema-driven explorer.** Every table gets a generated form & grid; add a\n  table to the database and it appears in the UI after a restart — no code.\n- **Standards built in.** MITRE ATT&CK \u002F ATLAS \u002F D3FEND \u002F CAPEC, STIX\u002FTAXII 2.1,\n  Sigma, OVAL, OCIL, EBIOS Risk Manager, CVE\u002FKEV\u002FEPSS, and GRC frameworks (ISO\n  27001, NIST CSF\u002F800-53, CIS, NIS2, DORA, CRA, SOC 2).\n- **Extensible by drop-in.** A searchable, filterable catalogue of **1,200+ security\n  connectors** and a remote-worker model; add one with a `connector.json`\n  manifest — no rebuild.\n- **Runs on your database.** Zero-config **SQLite** out of the box, and the data\n  layer is **portable to PostgreSQL \u002F MySQL \u002F MariaDB** (`XORCISM_DB_ENGINE` +\n  `tools\u002Fmigrate_db.py`) — see [§ Database backends](docs\u002FDATABASE_BACKENDS.md).\n- **Continuously fresh.** The NVD **CVE importer runs hourly** and every new CVE is\n  **auto-matched to the assets it affects** (by CPE + technology tags), raising\n  *\"New CVEs for ASSET\"* notifications — no manual triage to discover new exposure.\n- **Multi-tenant & RBAC.** Row-level tenant scoping and role-based access, with\n  passkey (WebAuthn) and optional OIDC sign-in.\n- **10 UI languages.** EN, FR, DE, IT, ES, PT, 中文, 日本語, العربية (RTL), Русский.\n\n---\n\n## ✨ Features\n\n### 🗂️ Exposure management (VOC \u002F CTEM)\n\n- **Asset Management** — inventory, owners, business\u002Ffinancial value, tags,\n  exposure; per-asset risk scoring with history.\n- **Attack-surface graph** — an asset-centric force-directed map linking each\n  asset to its applications, CPEs, vulnerabilities, owners, threats and incidents\n  (`\u002Fattack-surface`, reachable from the ASSET form; focus one asset or the whole\n  tenant, filter by entity type, deep-link back to any form).\n- **Configuration Management** — CPE naming, **OVAL** definitions and audits.\n- **Vulnerability Management** — CVE with **KEV**, **CVSS** and **EPSS**; CIRCL &\n  OSV lookups; **Exploit-DB search** (SearchSploit index, CVE→public-exploit lookup\n  on the VULNERABILITY form with one-click \"mark exploitable\"); SOCRadar IOC-Radar\n  deep-link for CVE references; **bug-bounty** program & submission tracking.\n- **Vulnerability Operations Center (VOC)** — `\u002Fvoc` — run remediation as an\n  **operations function**: a configurable remediation-**SLA policy**, operational KPIs\n  (SLA compliance, MTTR, aging, velocity), a risk-ranked worklist, remediation campaigns\n  with burndown, and a formal **risk-acceptance \u002F exception** register.\n- **VM Executive Report** — `\u002Fvm-report` — vulnerability **risk & SLA posture over time**\n  (is risk actually going *down*?): trend charts (risk-weighted exposure, backlog, KEV, SLA\n  compliance, MTTR, coverage), a board-ready executive summary, and a **\"myths vs reality\"**\n  section that debunks common VM misconceptions with your *own* live numbers. Print \u002F PDF.\n- **CTEM — exposure taxonomy** — `\u002Fctem` — support for the **ctem.org** (SecureCoders)\n  standardized exposure-identifier standard (a *\"CVE\u002FCWE for exposures\"*: 29 identifiers\n  across 8 categories, the 3-stage **Discover → Prioritize → Remediate** program); classify\n  observed exposures, track them by stage, and discover them from internet-exposed assets.\n- **Adversary Opportunity Index (AOI)** — `\u002Fadversary-opportunity` — the attacker's-eye\n  *\"threat debt\"* top-line: one 0–1000 number for the true adversary opportunity (every gap on a\n  viable **attack path** to a crown jewel, weighted by exploitability, adversary use and business\n  impact, **net of the controls you can prove**), with STOCK\u002FFLOW history, an exact item-level\n  paid-down\u002Faccrued **ledger**, a choke-point\u002Fsource\u002Ffinding **\"price the fix\"** worklist, a CROC\n  **agentic paydown loop** and a bidirectional **CTEM** bridge. On the dashboard, board report,\n  REST (`\u002Fapi\u002Fv1\u002Fadversary-opportunity`), the MCP server and ChatOps.\n- **Cyber Insurance Readiness** — `\u002Finsurance-readiness` — the insurer's view: the standard\n  ransomware-supplemental control checklist (MFA, backups, EDR\u002FSIEM, PAM, patching, tested IR,\n  segmentation…) scored from your **live signals**, plus a **policy** record with **coverage\n  adequacy** (limit vs. the FAIR-modeled ransomware loss) and a renewal countdown.\n- **Attack paths & choke points** — a reachability graph (`\u002Fattack-path`) over the\n  asset estate: edges from **same-subnet adjacency** + **BIA dependencies**, entry\n  nodes = internet-exposed assets, crown jewels = high business value, traversal cost\n  weighted by each node's **fusion exploitability**. Fusion-weighted Dijkstra maps the\n  **easiest attack path** from the internet to every crown jewel, and ranks the\n  **choke point** — the single node on the most paths, i.e. the one fix that severs\n  the most attack routes (the XM Cyber \u002F BloodHound move, open and asset-graph-native).\n- **Top exposures (fusion score)** — one **exploitability & relevance score** per\n  vulnerability (`\u002Fexposure`) fusing EPSS + CVSS + **CISA KEV** + **public exploits\n  (Exploit-DB)** + **in-the-wild CTI** + **blast radius** (affected assets × business\n  value), ranked into a prioritized \"fix this first\" worklist with a transparent\n  per-signal breakdown.\n- **Ransomware-to-$ scenario** — replay a real ATT&CK **ransomware group's TTPs**\n  (`\u002Fransomware`) across your asset estate and quantify the **dollar impact** with a\n  transparent FAIR-style model: **SLE** (primary loss = value at risk + ransom +\n  recovery), **ALE** (× an ARO bumped by internet exposure & KEV), and the **residual\n  with controls** (offline backups + segmentation). Shows the kill-chain phases the\n  group covers, the blast-radius assets with per-asset $, and the **D3FEND\n  countermeasures** that break the chain — the security-to-business bridge for the board.\n- **Continuously-proven compliance** — control objectives evaluated **live from your\n  security telemetry** (`\u002Fassurance`), not annual screenshots: detection coverage\n  (Sigma), KEV\u002Fexploit exposure, asset classification, internet exposure, pentest\n  recency, finding closure and **threat-informed defense (ATT&CK\u002FD3FEND)** — each\n  mapped to **ISO 27001 \u002F NIST CSF** with a proven\u002Fpartial\u002Fgap status and an honest\n  \"attestation required\" where telemetry genuinely can't decide. Compliance that\n  re-proves itself on every page load.\n- **CTI that acts** — `\u002Fcti-watch` cross-references live intel (**CISA KEV** +\n  ingested threat reports) against your asset inventory and surfaces **only what\n  affects you**, with one-click **auto-ticketing** (XTICKET). Threat intel that does\n  something, not a feed.\n- **Attack-surface drift** — `\u002Fdrift` snapshots your external surface and diffs\n  consecutive captures: assets that **appeared, vanished, or newly became\n  internet-exposed**. Pairs with the OSINT discovery chain to make discovery continuous.\n- **Content hub** — `\u002Fcontent` shares\u002Freuses content as portable files: **attack\n  playbooks** (import community recipes), the **Sigma rule bundle**, and an\n  **OpenVEX** document (which CVEs affect your products vs false-positive\u002Ffixed).\n- **Executive Dashboard** — a holistic **Enterprise RiskScore** (asset hygiene + open\n  risk-register residual + live incidents + compliance debt − assurance credits) shown with a\n  **contributor breakdown**, a **security-program maturity radar** (detection \u002F mitigation \u002F\n  validation \u002F compliance \u002F crisis-readiness \u002F risk-treated), a **risk heatmap** (residual\n  probability × impact), vulnerability breakdown, financial value, **risk exposure = risk ×\n  value**, asset tag cloud and incident trends (Chart.js) — plus a **security-posture KPI strip**\n  spanning the governance modules (assets, identities, incidents, compliance, risk register,\n  **Threat-Informed Defense** and **Crisis Management**).\n\n### 🛡️ Governance, Risk & Compliance (GRC)\n\n- **Compliance** — policies, standards & procedures lifecycle; audits, evidence,\n  readiness; **findings workflow**; **CRQ \u002F FAIR** quantitative risk on the\n  register. Frameworks: ISO 27001, NIST CSF, NIST 800-53, CIS Controls, NIS2,\n  DORA, CRA, SOC 2.\n- **Policies & Documents** — one governance view over the documented-information\n  estate: policy **lifecycle** (draft → in review → approved → published →\n  retired) and a controlled-**document register**, with a per-policy governance\n  score and a worklist of overdue reviews, unpublished\u002Funowned policies, missing\n  versions and expired documents. Ships a seedable baseline of **ISO\u002FIEC\n  42001:2023 (AI Management System) policies in English & French**.\n- **Crisis Management & Tabletop Exercises** — run **tabletop exercises (TTX)** against a\n  seeded library of **crisis scenarios** (ransomware, data breach, DDoS, insider,\n  supply-chain, cloud account, BEC). A tabletop exercise is an audit of type *Tabletop\n  Exercise*, so its observations become **improvement actions** and its **after-action\n  report** a linked document; on top, scenario templates carry **timed injects** and\n  exercises track **participants\u002Froles**. One click launches an exercise from a scenario\n  (copying its injects), and a **crisis-readiness score** blends exercise completion with\n  scenario coverage. The worklist surfaces overdue actions, scenarios never exercised and\n  exercises with no after-action report.\n- **Risk Register** — one governance view over the risk register: every risk's\n  **inherent → current → residual** level, its **treatment** (strategy, plan, owner, review) and\n  its **CRQ\u002FFAIR** quantification (*Annualized Loss Expectancy*), with a 0-100 priority score per\n  risk and a worklist of the gaps that matter — **high\u002Fcritical residual risks left untreated**,\n  risks **accepted without justification**, **overdue reviews**, treatments **past their target\n  date**, and **unowned** risks. Mirrors the asset\u002Fidentity\u002Fcompliance governance pages.\n- **PQCMM — Quantum Readiness** — the PKI Consortium's **Post-Quantum Cryptography Maturity\n  Model**: assess every product, service or asset that relies on cryptography against the **6\n  PQCMM levels** (0 None → 5 Optimized), track **current vs target** maturity, and roll up your\n  organisation's quantum-readiness posture — what's still **quantum-vulnerable** (Level 0),\n  **production-ready** with PQC (≥ 2) or fully **managed** (CBOM + zero-legacy, ≥ 4) — with a\n  maturity score and a below-target worklist. Get ahead of \"harvest-now-decrypt-later.\"\n- **SCA — Software Composition Analysis** — know what your software is made of. Import a\n  **Software Bill of Materials** in the two most widely used standards — **CycloneDX** (OWASP) and\n  **SPDX** (Linux Foundation) — and XORCISM persists every component with its **version, PURL, CPE,\n  license, supplier and hash**, links CPE-bearing components back to the asset's exposure inventory\n  (`CPEFORASSET`), and maps the **dependency graph**. The worklist surfaces **known-vulnerable\n  components**, **license-compliance gaps** and **unpinned versions**; any SBOM can be **exported**\n  back out in either standard (CycloneDX 1.5 \u002F SPDX 2.3). Breakdowns by component type, license and\n  supplier, plus an interactive composition graph.\n- **FAIR-MAM Materiality** — the FAIR Institute's **Materiality Assessment Model**: decompose a\n  cyber loss event's single-loss magnitude across the **10 standardized cost categories**\n  (incident response, cyber extortion, business interruption, asset restoration, privacy\u002Fsecurity\n  liability, network-security liability, communications & media, regulatory, PCI, reputation),\n  each estimated as a **PERT** range (min \u002F most-likely \u002F max). An interactive calculator computes\n  the expected single-loss, the **primary vs secondary** (and first- vs third-party) split, and a\n  **materiality verdict** against your threshold (e.g. an SEC materiality figure) — the detailed\n  breakdown of the risk register's *Single Loss Expectancy*.\n- **Configuration Management** — one governance view over the secure-configuration\n  content library (OVAL\u002FSCAP): the compliance-class **hardening baselines** are the\n  configuration items, with a per-baseline **health score** and a worklist of\n  **deprecated** content, baselines **never verified by a scan**, interim-status\n  checks and missing **CCE** mappings — verification fed by the OVAL agent scans.\n- **EBIOS Risk Manager** — the full 5-workshop ANSSI method (framing & security\n  baseline, risk sources, strategic & operational scenarios, treatment) with an\n  **Express mode**, business values, supporting assets, feared events (DICT),\n  risk sources and an **ecosystem of stakeholders with auto-computed threat\n  levels & zones**.\n- **NIST SP 800-30** — the US federal **Guide for Conducting Risk Assessments**, the\n  EBIOS-RM counterpart: threat sources (adversarial & non-adversarial), threat events,\n  vulnerabilities & predisposing conditions, and risk determination as **likelihood ×\n  impact** on the 800-30 scale (Very Low → Very High, Appendix I Table I-2), with a\n  cockpit dashboard and a guided-create flow (`\u002Fnist-800-30`).\n- **TPRM** — third-party \u002F supplier risk assessments and questionnaires.\n- **OCIL questionnaires** — OCIL 2.0-compatible authoring, XML import\u002Fexport and\n  an optional AI \"suggest answer\".\n- **Business Impact Analysis (BIA)** — audits & entries with editable asset\n  datalists, plus a **dependency graph**: a force-directed map of the BIA\n  entries (coloured by criticality) and their dependencies, with **impact\n  propagation** — click an entry to see everything that fails if it goes down,\n  the tightest RTO, and the worst impacted criticality.\n\n### 🔭 Threat & detection\n\n- **Threat Management (CTI)** — STIX entities (actors, malware, tools, campaigns,\n  indicators, observables) with OpenCTI-style common properties (Confidence,\n  TLP, Labels, Score), **sightings** and **relationships**.\n- **Threat feeds & reports** — a curated **CTI RSS reader** (33 feeds) and threat\n  reports with **automatic IOC extraction** (IPs, domains, URLs, hashes, CVEs)\n  into the `IOC` table; per-report **CVE enrichment**, **watchlists with\n  alerting**, priority-intelligence requirements (**PIR**) and a local-AI **intel\n  brief builder**.\n- **Threat hunting & detection** — hunts, hypotheses and an IOC\u002Ftechnique\n  overview with a local-AI **hunt assistant**; **3,750+ Sigma detection rules**\n  browsable and linked to ATT&CK techniques.\n- **MITRE matrices** — **ATT&CK** (Enterprise \u002F Mobile \u002F ICS \u002F **ATLAS**),\n  **D3FEND** defensive countermeasures (mapped to ATT&CK and `XORCISM.CONTROL`),\n  and **A3M — Agentic AI Attack Matrix**.\n- **LLM ATT&CK Navigator (Anthropic)** — an AI-enablement **overlay layer** on the\n  ATT&CK matrix: the techniques AI-enabled threat actors actually use, shaded by\n  prevalence (% of banned accounts), from Anthropic's 2026 analysis. Toggle it on\n  `\u002Fattack` alongside the BAS coverage layer.\n- **Kill chain graph** — the ATT&CK tactics as the ordered phases of the kill\n  chain (Reconnaissance → Impact); overlay any adversary (ATT&CK group) to map\n  the techniques it uses per phase and reveal its **coverage and progression**\n  (e.g. APT29: 13\u002F15 phases). `\u002Fkill-chain`.\n- **Adversary emulation (BAS\u002FAEV)** — emulation plans, atomic tests & executors, and\n  an **ATT&CK coverage heatmap** overlaid on the matrix. A **curated XORCISM test library**\n  ships (61 tests \u002F 58 ATT&CK techniques, 7 scenarios, **safe by design**: localhost targets,\n  reversible cleanup, destructive techniques as safe simulations or `manual`) — imported with\n  `import_atomics.py --xorcism` and run by the endpoint agent (`xor_agent.py --scan emulate\n  --scenario N`, opt-in per host). See [`agent\u002FREADME.md`](agent\u002FREADME.md).\n- **Pentesting** — engagements modeled as **AUDITs (type Pentest)** scoped to\n  assets: launch tool connectors (nmap, nuclei, nikto, whatweb, wpscan, sqlmap,\n  OpenVAS, Metasploit) against the scope under an enforced **ROE**, then collect\n  **AUDITFINDINGs** and the **VULNERABILITYs** found on the in-scope assets\n  (promote a vuln to a finding in one click), then print a client-ready\n  **PDF report** (executive summary, scope, findings, vulnerabilities). Scan\n  launch is capability-gated.\n- **Attack chaining (playbooks)** — seed a target and let XORCISM mimic a full\n  engagement: a tool runs (e.g. **nmap**), its result is parsed into *facts*\n  (open ports \u002F services \u002F detected tech \u002F vulns), and rules auto-launch the\n  right follow-on tool — a web scanner on 80\u002F443 (**WhatWeb, Nikto, Nuclei**),\n  **WPScan** when WordPress is detected, **sslyze** on TLS — recursively, until\n  no rule matches. The run is drawn as a **live tree** and its findings roll up\n  to the engagement. Ships with a **predefined library** of playbooks — full\n  external pentest, web-app assessment, network recon, subdomain web-recon\n  (subfinder → httpx fan-out per host), **External exploitation (Metasploit)**,\n  **Internal AD\u002FSMB sweep (Metasploit + CrackMapExec)**, TLS\u002FSSL hardening, and\n  **External recon → attack surface (OSINT)** — a passive‑first attacker journey\n  from a domain (subfinder · theHarvester · Shodan · HIBP → probe → web scan) that\n  in **Live** mode **auto‑populates the asset inventory** with discovered hosts\n  (continuous attack‑surface discovery). Playbooks **import\u002Fexport** as portable\n  JSON. Two backends: **Simulate**\n  (safe, no real scanning — design & demo playbooks) and **Live** (real connector\n  jobs, in-scope only, ROE-enforced). Localized across all 10 UI languages.\n- **Purple-team detection coverage** — turn any attack-chain run into an\n  **evidence-based** ATT&CK coverage report (`\u002Fpurple-team`): each tool is mapped to\n  the technique it exercises, then checked against your **Sigma rule library** (3,750+\n  rules) — techniques with a rule are \"detected\", the rest are gaps, and a gap can be\n  closed by **generating the missing Sigma rule** (local AI, with a deterministic\n  skeleton fallback). Coverage you can defend, not \"we own a tool\".\n- **Threat-Informed Defense cockpit** (`\u002Fthreat-informed-defense`) — the capstone that\n  operationalises MITRE's TID loop across the whole platform. For every ATT&CK\n  technique it weighs **adversary use** (ecosystem prevalence from ATT&CK groups,\n  boosted ×3 by your local CTI & hunts) against your three defensive pillars —\n  **detect** (Sigma), **mitigate** (D3FEND + ATT&CK mitigations) and **test** (Atomic\n  Red Team) — and produces a single **threat-weighted program score**, per-tactic\n  kill-chain coverage, and a **prioritised gap worklist** (the highest-threat\n  techniques with the weakest defence, each linking to where you close it). As you\n  import your own CTI (the connectors feed `INTELEXCHANGE → ATT&CK`) the priorities\n  sharpen to *your* threat model. One click **closes the validation gap**: *Build\n  validation plan* turns the top untested high-threat techniques into a scheduled\n  **BAS emulation scenario** (Atomic Red Team injects); *Run on agent* then has the\n  **XOR agent execute** those injects and report real outcomes (Prevented \u002F Executed \u002F\n  Skipped) into `EMULATIONRESULT` — so a technique moves from *test defined* to *test\n  executed\u002Fvalidated*, and the cockpit shows a distinct **executed** rate, not just\n  *defined*. Agent execution is opt-in and safety-gated (only read-only recon is auto-run).\n  The agent then **attributes detection** — correlating each executed inject with the host's\n  telemetry (Defender \u002F Sysmon \u002F PowerShell-ScriptBlock \u002F Security-audit) to record\n  *Detected* \u002F *Logged* \u002F *Executed (ran undetected)*. The cockpit surfaces the sharpest\n  finding of all: a technique whose **Sigma rule exists but whose emulation ran undetected**\n  — **false coverage**, where you *thought* you'd detect it but the test proved the rule\n  never fired. And it closes the loop: every detection gap (no rule, exposed, or false\n  coverage) gets a **✨ draft Sigma** button that **generates a detection rule with the\n  local AI** (deterministic skeleton fallback) and saves it to the library as\n  *experimental* — adding capability you then **re-validate** by re-running the plan, so a\n  draft only graduates to \"proven\" once the emulation confirms it fires. The draft is\n  **procedure-tuned**: the generator is fed the exact command\u002Ftelemetry the emulation ran,\n  so the rule detects *that* procedure (e.g. the precise `systeminfo` \u002F `whoami`\n  command-line the test executed) rather than a generic technique guess. And *Schedule\n  weekly* puts the whole thing on a **cadence** — the cron scheduler re-queues the\n  validation emulation on the agent automatically, so drafted detections get re-proven (and\n  regressions caught) without anyone clicking a button. And when a detection that *used* to fire\n  stops firing on a later re-validation, the cockpit flags **detection drift** (a distinct `D↓`\n  state, separate from \"never fired\") and raises a **Defender-aligned alert** (`XINCIDENT.ALERT`,\n  de-duplicated) the moment the regression is observed — so a silently-broken rule (an edit, a\n  dead log source, a sensor change) pages you instead of rotting unnoticed. The whole program also **exports to a\n  MITRE ATT&CK Navigator layer** (one click, *⬇ ATT&CK Navigator layer*) — score = adversary\n  prevalence, colour = defence status (red = false-coverage\u002Fexposed, amber = partial, green =\n  covered) — so it opens straight in the official ATT&CK Navigator.\n- **STIX relationship graph** — interactive graph linking hunts ↔ techniques ↔\n  actors; nodes deep-link back to their forms.\n- **Threat Modeling** — STRIDE scope, assets, threats and controls.\n- **Incident Management & Ticketing** — alerts, incidents, tasks, comments and\n  attachments.\n\n### 🔌 Integrations & automation\n\n- **1,200+ connectors** — a **searchable, filterable catalogue** (search + category \u002F\n  type filters, like the tool catalogue): curated tool-runners (nmap,\n  nuclei, nikto, sqlmap, whatweb, wpscan, WPProbe, w3af, OpenVAS) and API imports\n  (Nessus, Qualys, Rapid7, Caldera, Dependency-Track, OSV-Scanner, depx, Wiz,\n  Lacework, Sysdig, Aikido, Burp Suite, Metasploit, Splunk, Elastic Security,\n  Microsoft Sentinel, QRadar, SAINT, **OpenCVE**, **Microsoft Entra ID**), plus a\n  large **OSINT tool-runner** set and a **YARA** scanner. See [§ Connectors](#-connectors).\n- **Continuous CVE → asset matching** — the NVD CVE importer **runs every hour**\n  (`XSCHEDULE`, incremental); each newly-imported or OpenCVE-pulled CVE is **auto-linked\n  to the assets it affects** — matched by the asset's **CPE inventory** and free-text\n  **technology tags** (`ASSETTAG`) — and every affected asset gets a **\"New CVEs for\n  ASSET\" notification**. Runs after each import, hourly, and on demand (the *Match CVEs*\n  button on Asset Management).\n- **Identity & device sync (Microsoft Entra ID)** — the `entra-id` connector pulls\n  users (human identities), service principals & managed identities (non-human \u002F NHI)\n  and registered devices (assets) from the **Microsoft Graph API** into `IDENTITY` +\n  `ASSET` (app-only OAuth2; feeds the IAM orphaned-NHI \u002F stale \u002F MFA-gap worklist).\n- **CTI platform connectors** — pull threat intelligence and detection content from\n  **MISP** (events → `INTELEXCHANGE`, galaxies → ATT&CK\u002Factor\u002Fmalware tags), **OpenCTI**\n  (reports via GraphQL or a STIX 2.1 bundle → `INTELEXCHANGE`) and **SOC Prime**\n  (Sigma detection rules → `SIGMARULE` *and* `INTELEXCHANGE`, boosting the Threat-Informed\n  Defense *detect* pillar). Each works live (API + env credentials) or fully offline (saved\n  export) — stdlib-only, idempotent.\n- **Remote workers** — run connectors on a separate host (e.g. a Kali VM) over a\n  worker token; normalized results import centrally.\n- **Recurring agent scans** — schedule OVAL\u002FSCAP scans on a cadence from Configuration\n  Management (hourly\u002Fdaily\u002Fweekly\u002Fmonthly via `XSCHEDULE`); the scheduler queues an agent\n  job each cycle and the XOR agent runs it at check-in. See the agent [SETUP](agent\u002FSETUP.md).\n- **Live forensics (DFIR triage)** — the XOR agent's `--scan forensics` collects a\n  **read-only** live-response snapshot (processes, network connections, persistence\u002Fautoruns,\n  logon sessions, recent files, ARP\u002FDNS\u002Froutes, drivers, event-log summary) with conservative\n  triage **flags** → `XAGENT.FORENSICTRIAGE`; collection never modifies the host.\n- **Endpoint EDR & YARA (XOR agent)** — `--scan yara` runs the local **YARA** engine using\n  rules from XORCISM's `YARARULE` store (served to the agent) and reports matches as events; and\n  the **Rustinel EDR bridge** (`--scan rustinel`) tails [Rustinel](https:\u002F\u002Fgithub.com\u002FKarib0u\u002Frustinel)'s\n  kernel-level **ETW \u002F eBPF \u002F Endpoint-Security** alerts (Sigma + YARA + IOC) into XORCISM —\n  kernel-grade detection without a custom agent core. Both are read-only and part of `--scan full`.\n- **Memory acquisition (XOR agent)** — `--scan memdump` captures a full **RAM image** for forensics\n  (winpmem\u002Favml); the image stays on the endpoint for **chain of custody** and only the manifest\n  (tool \u002F path \u002F size \u002F **SHA-256**) is shipped → `XAGENT.MEMORYDUMP`.\n- **AI log hunting (XOR agent)** — `--scan loghunt` collects Sysmon \u002F PowerShell \u002F Security logs and\n  the **local AI** hunts them for threats, mapping to **MITRE ATT&CK** and spawning a hunt when\n  suspicious; no host data leaves the box.\n- **Honeypot (XOR agent)** — `--scan honeypot` runs a bounded **deception sensor** on decoy ports;\n  every connection attempt is logged and the attacker IPs become IOCs.\n- **AI-agent guardrails management** (`\u002Fai-guardrails`) — the agent's `--scan aiguard` **discovers**\n  the LLM apps \u002F autonomous AI agents on each host (LangChain, CrewAI, Ollama, MCP servers, exposed\n  keys), **scores** them against a **12-control AI Guardrail Baseline** (OWASP AI Exchange \u002F Google\n  SAIF \u002F ISO 42001 \u002F OWASP LLM Top 10 \u002F MITRE ATLAS \u002F NIST AI RMF), and **monitors** their traces\n  with the local AI for prompt injection \u002F jailbreak \u002F exfiltration \u002F excessive agency → spawned\n  hunts. Inline enforcement is delegated to a guardrail gateway (NeMo \u002F LLM Guard \u002F Llama Guard \u002F\n  Lakera) whose block telemetry is imported.\n- **TAXII 2.1 server** — publish\u002Fconsume STIX feeds.\n- **Local AI (Ollama)** — fully-offline assistants: **\"Ask the threat model\"**\n  (RAG over your XORCISM data), an **intel brief builder**, a\n  **vulnerability-triage agent** (KEV\u002FEPSS + affected-asset blast radius), a\n  **hunt assistant**, OCIL answer suggestions, and **red\u002Fblue copilots** — an\n  **AI attack-chain analyst** (read-out of a tool-chaining run: critical path,\n  findings, next offensive steps + defenses\u002FATT&CK·D3FEND) and an **AI exposure\n  briefing** (CISO-level read-out of the fusion worklist + attack paths). Every\n  copilot degrades gracefully to a deterministic data summary when the local AI\n  is offline, so nothing ever blocks; no data leaves the machine.\n- **Python importers** — load reference data: ATT&CK, D3FEND, CAPEC, CVE\u002FNVD,\n  KEV, ISO 27001, NIST 800-53, CCE, OVAL, MAEC, Atomic Red Team, A3M, **Sigma\n  rules**, hunts, **threat reports & IOCs**, **OSINT tools**.\n\n### 🔐 Security & identity\n\n- Session-based auth; **passkeys (WebAuthn)** verified server-side (ES256\u002FRS256);\n  optional **OIDC** SSO.\n- **RBAC** (`userCan`) + **per-tenant row scoping** (multi-tenant by design).\n- **Field-encryption vault** (passphrase-wrapped data key, one-time recovery key).\n- **Anti-automation** guard on the authenticated app; hidden admin-only tables.\n\n### 🌐 UX & accessibility\n\n- **10 UI languages** with strict key parity; **RTL** layout for Arabic.\n- Theme system (CSS variables + `data-theme`), dark themes.\n- Schema-driven forms with FK pickers, \"+ create\" inline records, date pickers,\n  static datalists, checkbox columns, Excel import, rich-text fields.\n\n---\n\n## 📸 Screenshots\n\n> English UI, with demo data. Full-resolution images in [`docs\u002Fscreenshots\u002F`](docs\u002Fscreenshots).\n\n| | | |\n|---|---|---|\n| ![Domain launcher](docs\u002Fscreenshots\u002F01_landing_cards.png)\u003Cbr>**Domain launcher** — pick a security domain | ![Asset management](docs\u002Fscreenshots\u002F02_asset_management.png)\u003Cbr>**Asset management** — inventory, governance worklist & per-asset risk score | ![Configuration \u002F OVAL](docs\u002Fscreenshots\u002F03_configuration_oval.png)\u003Cbr>**Configuration** — OVAL definitions |\n| ![Compliance \u002F GRC](docs\u002Fscreenshots\u002F04_compliance_audit.png)\u003Cbr>**Compliance** — audits, findings & evidence | ![TPRM](docs\u002Fscreenshots\u002F05_tprm_dashboard.png)\u003Cbr>**TPRM** — third-party risk | ![EBIOS overview](docs\u002Fscreenshots\u002F06_ebios_dashboard.png)\u003Cbr>**EBIOS RM** — study overview |\n| ![EBIOS stakeholders](docs\u002Fscreenshots\u002F07_ebios_stakeholders.png)\u003Cbr>**EBIOS** — stakeholders & threat zones | ![EBIOS feared events](docs\u002Fscreenshots\u002F08_ebios_feared_events.png)\u003Cbr>**EBIOS** — feared events (DICT) | ![Vulnerability management](docs\u002Fscreenshots\u002F09_vulnerability_mgmt.png)\u003Cbr>**Vulnerabilities** — CVE\u002FKEV\u002FCVSS\u002FEPSS · SSVC |\n| ![Threat intelligence](docs\u002Fscreenshots\u002F10_threat_mgmt.png)\u003Cbr>**Threat intelligence (CTI)** — actors & TTPs | ![Threat modeling](docs\u002Fscreenshots\u002F11_threat_modeling.png)\u003Cbr>**Threat modeling** — STRIDE | ![Incident management](docs\u002Fscreenshots\u002F12_incident_mgmt.png)\u003Cbr>**Incident management** |\n| ![Ticketing](docs\u002Fscreenshots\u002F13_ticketing.png)\u003Cbr>**Ticketing** — tasks & comments | ![Connectors](docs\u002Fscreenshots\u002F14_xposure_connectors.png)\u003Cbr>**Connectors** — nmap, nuclei, Nessus, SBOM… | ![OSINT](docs\u002Fscreenshots\u002F15_osint_tools.png)\u003Cbr>**OSINT** toolbox |\n| ![ATT&CK](docs\u002Fscreenshots\u002F16_matrix_attack.png)\u003Cbr>**MITRE ATT&CK** — with BAS coverage heatmap | ![D3FEND](docs\u002Fscreenshots\u002F17_matrix_d3fend.png)\u003Cbr>**MITRE D3FEND** — defensive matrix | ![A3M](docs\u002Fscreenshots\u002F18_matrix_a3m.png)\u003Cbr>**A3M** — Agentic AI Attack Matrix |\n| ![Dashboard](docs\u002Fscreenshots\u002F19_dashboard.png)\u003Cbr>**Executive dashboard** — risk, exposure, trends | ![BIA](docs\u002Fscreenshots\u002F20_bia_audit.png)\u003Cbr>**Business Impact Analysis (BIA)** | ![STIX graph](docs\u002Fscreenshots\u002F21_stix_graph.png)\u003Cbr>**STIX graph** — hunts ↔ ATT&CK techniques |\n| ![Threat hunting](docs\u002Fscreenshots\u002F22_threat_hunting.png)\u003Cbr>**Threat hunting** — HUNT · IOC · ATT&CK, local-AI assistant | ![Ask the threat model](docs\u002Fscreenshots\u002F23_ask_ai.png)\u003Cbr>**Ask the threat model** — local-AI RAG | ![Connectors](docs\u002Fscreenshots\u002F24_connector_search.png)\u003Cbr>**Connectors** — searchable catalogue (1,200+) |\n| ![Threat feeds](docs\u002Fscreenshots\u002F25_threat_feeds.png)\u003Cbr>**Threat feeds** — curated CTI RSS reader (newest first) | ![Attack-surface graph](docs\u002Fscreenshots\u002F26_attack_surface.png)\u003Cbr>**Attack-surface graph** — asset-centric force map | ![Attack-surface focus](docs\u002Fscreenshots\u002F27_attack_surface_focus.png)\u003Cbr>**Attack surface** — focused on one asset |\n| ![Pentesting](docs\u002Fscreenshots\u002F28_pentest.png)\u003Cbr>**Pentesting** — engagements, scope, tooling, findings & vulns | ![LLM ATT&CK](docs\u002Fscreenshots\u002F31_llm_attack.png)\u003Cbr>**LLM ATT&CK** — AI-enabled technique overlay (Anthropic) | ![BIA dependency graph](docs\u002Fscreenshots\u002F33_bia_graph.png)\u003Cbr>**BIA dependency graph** — impact propagation |\n| ![Kill chain graph](docs\u002Fscreenshots\u002F34_kill_chain.png)\u003Cbr>**Kill chain graph** — ATT&CK phases + adversary TTPs | ![Attack chain](docs\u002Fscreenshots\u002F35_attack_chain.png)\u003Cbr>**Attack chain** — tool-chaining playbook run (nmap → web scanners → WPScan) | ![Attack chain card](docs\u002Fscreenshots\u002F36_pentest_chain_card.png)\u003Cbr>**Attack chain** — launch a playbook from an engagement |\n| ![Web-recon chain](docs\u002Fscreenshots\u002F37_attack_chain_recon.png)\u003Cbr>**Web-recon chain** — subfinder → httpx fan-out per subdomain → web scanners | ![Metasploit chain](docs\u002Fscreenshots\u002F39_attack_chain_metasploit.png)\u003Cbr>**Metasploit chain** — nmap → MS17-010 → Meterpreter session (playbook library) | ![Exploit-DB search](docs\u002Fscreenshots\u002F40_exploitdb_search.png)\u003Cbr>**Exploit-DB search** — keyword\u002FCVE search of the SearchSploit index |\n| ![OSINT attacker journey](docs\u002Fscreenshots\u002F42_attack_chain_osint.png)\u003Cbr>**OSINT chain** — domain → subfinder\u002FtheHarvester → Shodan\u002FHIBP → web scan (auto-inventory) | ![Top exposures](docs\u002Fscreenshots\u002F43_top_exposures.png)\u003Cbr>**Top exposures** — exploitability fusion score, prioritized worklist | ![Attack paths](docs\u002Fscreenshots\u002F44_attack_paths.png)\u003Cbr>**Attack paths** — easiest routes to crown jewels + choke-point analysis |\n| ![AI exposure brief](docs\u002Fscreenshots\u002F45_ai_exposure_brief.png)\u003Cbr>**AI copilots** — red\u002Fblue chain analyst + CISO exposure briefing (local Ollama) | ![Purple-team coverage](docs\u002Fscreenshots\u002F46_purple_coverage.png)\u003Cbr>**Purple-team** — chain → ATT&CK detection coverage (Sigma) + rule generation | ![Ransomware $ impact](docs\u002Fscreenshots\u002F47_ransomware_impact.png)\u003Cbr>**Ransomware $** — group TTPs → SLE\u002FALE dollar impact + D3FEND controls | ![Control assurance](docs\u002Fscreenshots\u002F48_control_assurance.png)\u003Cbr>**Control assurance** — compliance proven live from telemetry (ISO\u002FNIST) | ![CTI watch](docs\u002Fscreenshots\u002F49_cti_watch.png)\u003Cbr>**CTI watch** — KEV\u002Freports matched to your inventory + auto-ticket |\n| ![Surface drift](docs\u002Fscreenshots\u002F50_surface_drift.png)\u003Cbr>**Surface drift** — snapshot & diff the external attack surface | ![Content hub](docs\u002Fscreenshots\u002F51_content_hub.png)\u003Cbr>**Content hub** — export\u002Fimport playbooks, Sigma, OpenVEX | ![Identities & IAM](docs\u002Fscreenshots\u002F54_identities.png)\u003Cbr>**Identities & IAM** — human + non-human (NHI) inventory, governance worklist & risk score |\n| ![SSVC calculator](docs\u002Fscreenshots\u002F55_ssvc_calculator.png)\u003Cbr>**SSVC** — CISA Stakeholder-Specific Vulnerability Categorization calculator (Track \u002F Track\\* \u002F Attend \u002F Act) | ![Incident management](docs\u002Fscreenshots\u002F56_incidents.png)\u003Cbr>**Incident management** — queue, governance worklist, SLA\u002FRTO breach & priority score | ![Compliance & GRC](docs\u002Fscreenshots\u002F57_compliance.png)\u003Cbr>**Compliance & GRC** — audit inventory, remediation worklist & posture score |\n| ![Policies & Documents](docs\u002Fscreenshots\u002F58_policy_management.png)\u003Cbr>**Policies & Documents** — policy lifecycle & controlled-document register, governance worklist & per-policy score (ISO 42001 AIMS policies seeded EN\u002FFR) | ![Configuration Management](docs\u002Fscreenshots\u002F60_configuration_management.png)\u003Cbr>**Configuration Management** — secure-configuration content library (OVAL hardening baselines), scan-verification coverage & per-baseline health score | ![Threat-Informed Defense](docs\u002Fscreenshots\u002F61_threat_informed_defense.png)\u003Cbr>**Threat-Informed Defense** — per ATT&CK technique, adversary use vs detect (Sigma) \u002F mitigate (D3FEND) \u002F test (Atomic) coverage, threat-weighted program score & prioritised gap worklist |\n\n---\n\n## 🚀 Quick start\n\nThe web app **creates all databases on first start**, so a fresh setup is just:\n\n```powershell\ncd xorcism_ts\nnpm install\nnpm run build                                       # build:server (tsc) + build:client (esbuild)\n$env:DB_DIR = \"C:\\Users\\$env:USERNAME\\XORCISM_databases\"   # keep databases OUTSIDE OneDrive\nnpm start                                           # node dist\u002Fserver\u002Findex.js\n# → open http:\u002F\u002Flocalhost:9292\u002Flogin\n```\n\nOn the **very first** start (no users yet) the server prints a one-time admin\naccount to the console:\n\n```\n  COMPTE ADMIN INITIAL CRÉÉ\n    Email        : admin@xorcism.local\n    Password     : \u003Crandom temp password, shown ONCE>\n    (change it at first login)\n```\n\nSign in with that account; you'll be forced to set a new password.\n\n### Quick start (Docker)\n\n```bash\ndocker compose up -d --build\n# → http:\u002F\u002Flocalhost:9292\u002Flogin\n```\n\nSQLite databases persist in the `xorcism-data` volume (`DB_DIR=\u002Fdata`). To use\nyour existing databases, bind-mount them instead — e.g.\n`- C:\u002FUsers\u002Fyou\u002FXORCISM_databases:\u002Fdata` in [`docker-compose.yml`](docker-compose.yml).\n\n> **⚠️ Windows \u002F OneDrive.** The code tree can live under OneDrive, but the\n> **SQLite databases must live OUTSIDE OneDrive** — OneDrive replaces files under\n> open handles and corrupts WAL journals. Default `DB_DIR` is\n> `C:\\Users\\\u003Cyou>\\XORCISM_databases`.\n\n---\n\n## 📦 Detailed installation\n\nThe full, step-by-step guide is in **[SETUP.MD](SETUP.MD)**; dependency versions\nare in **[REQUIREMENTS.MD](REQUIREMENTS.MD)**. Summary of components:\n\n| Component | Folder | Runtime | Mandatory |\n|---|---|---|---|\n| **Web application** (main) | `xorcism_ts\u002F` | Node.js 20 + TypeScript | ✅ Yes |\n| **Databases** | `databases\u002F` → `DB_DIR` | SQLite (better-sqlite3) | ✅ auto-created |\n| **Python tooling \u002F importers** | `xorcism_python\u002F` | Python 3.11+ + SQLAlchemy 2 | ⬜ Optional |\n| **Connectors \u002F workers** | `connectors\u002F` | Python | ⬜ Optional |\n| **TAXII 2.1 server** | `taxii\u002F` | Python + Flask | ⬜ Optional |\n\n### Prerequisites\n\n| Tool | Min version | Notes |\n|---|---|---|\n| **Node.js** | 20.x LTS (`>=20 \u003C23`) | or the bundled portable runtime at `tools\u002Fnodejs\u002Fnode.exe` |\n| **sqlite3 CLI** | 3.x | bundled at `tools\u002Fsqlite3.exe` (only for the DB-generation script) |\n| **Python** | 3.11+ | importers \u002F connectors \u002F TAXII (optional) |\n| **PowerShell** | 5.1+ | the setup scripts are PowerShell |\n| **Browser** | modern | Chrome, Edge, Firefox |\n\n> **better-sqlite3 is a native module.** It must run on **Node 20** (prebuilt\n> binaries); Node 23+\u002F24 break the ABI. On Windows without a system Node, use the\n> portable runtime at `tools\u002Fnodejs\u002Fnode.exe`.\n\n### Environment variables (common)\n\n```powershell\n$env:DB_DIR = \"C:\\Users\\$env:USERNAME\\XORCISM_databases\"  # SQLite location (must be outside OneDrive)\n$env:PORT   = \"9292\"                                       # HTTP port (default)\n# $env:XORCISM_ALLOW_REGISTER = \"0\"                        # disable public self-registration\n# $env:XORCISM_DB_DIR  → same path as DB_DIR, for the Python tooling\n# --- Optional: run the Python data layer on a server DB (see docs\u002FDATABASE_BACKENDS.md) ---\n# $env:XORCISM_DB_ENGINE   = \"postgresql\"   # sqlite (default) | postgresql | mysql | mariadb\n# $env:XORCISM_DB_HOST     = \"db.internal\"  # + XORCISM_DB_PORT \u002F _USER \u002F _PASSWORD \u002F _PREFIX\n# --- Optional: hourly NVD CVE import + CVE→asset matching ---\n# $env:NVD_API_KEY   = \"...\"                # higher NVD rate limit (hourly importer)\n# $env:XOR_PYTHON    = \"python\"             # python used by the in-process CVE importer\n# $env:XOR_CVE_IMPORT = \"0\"                 # disable the hourly CVE import schedule\n# $env:XOR_CVE_MATCH  = \"0\"                 # disable the hourly CVE→asset matcher\n```\n\nSee [SETUP.MD](SETUP.MD) §4–§9 for connectors, TAXII, forum and the encryption\nvault, and [REQUIREMENTS.MD](REQUIREMENTS.MD) for the full env-var table.\n\n---\n\n## 🔧 Local development\n\n```powershell\ncd xorcism_ts\nnpm install\nnpm run dev    # tsc --watch (server) + esbuild --watch (client) + nodemon\n```\n\n### npm scripts\n\n| Script | Action |\n|---|---|\n| `npm run build` | `build:server` + `build:client` |\n| `npm run build:server` | `tsc -p tsconfig.server.json` → `dist\u002Fserver\u002F` (CommonJS) |\n| `npm run build:client` | `node esbuild.config.js` → `dist\u002Fclient\u002Fjs\u002F` (one bundle per page) |\n| `npm start` | `node dist\u002Fserver\u002Findex.js` (port 9292) |\n| `npm run dev` | watch-compile server + client and hot-restart with nodemon |\n\n> Builds run with any Node; **the runtime needs Node 20** (better-sqlite3 ABI).\n\n### Contributing\n\nSee **[CONTRIBUTING.md](CONTRIBUTING.md)** for the full guide — including how to **write a connector**\n(turn a tool's output into XORCISM data in ~40 lines) and how to **write an importer** (bulk-load a\nframework \u002F dataset, idempotently). The golden rule: verify DB-writing code against a **copy** of the\ndatabases (`DB_DIR` \u002F `XORCISM_DB_DIR`), never the live ones.\n\n---\n\n## 🏗️ Architecture\n\n```\nXORCISM\u002F\n├── xorcism_ts\u002F                 # Main web application (Node + TypeScript)\n│   ├── server\u002F\n│   │   ├── index.ts            # Express entry (port 9292), page routes, boot-time table setup\n│   │   ├── db.ts               # SQLite pool + all query\u002Faggregation logic + derived-value hooks\n│   │   ├── auth.ts             # sessions, RBAC (userCan), tenant scoping, hidden-table rules\n│   │   ├── cron.ts agents.ts   # background scheduler, agent endpoints\n│   │   └── routes\u002F             # explorer, bia, ocil, notifications, auth, oidc, vault, admin,\n│   │       │                   #   connectors, feedback, agent, circl, osv, pentest, ai, ebios…\n│   │       └── …\n│   ├── client\u002F\n│   │   ├── *.html              # explorer, dashboard, bia, attack, d3fend, stix-graph, tprm,\n│   │   │                       #   ebios, hunting, ask, threat-feeds, admin, connectors, login…\n│   │   └── ts\u002F\n│   │       ├── app.ts          # schema-driven forms & grids (the explorer engine)\n│   │       ├── dashboard.ts attack.ts d3fend.ts stix-graph.ts bia.ts ebios.ts tprm.ts\n│   │       ├── i18n.ts theme.ts api.ts rte.ts\n│   │       └── locales\u002F        # de it es pt zh ja ar ru (fr + en are inline in i18n.ts)\n│   ├── esbuild.config.js  tsconfig*.json  package.json  start.ps1\n│\n├── databases\u002F                  # Canonical SQLite DDL (XORCISM, XVULNERABILITY, XTHREAT, …)\n├── xorcism_python\u002F             # SQLAlchemy models + importers\u002F (engine-agnostic: config.py)\n├── tools\u002Fmigrate_db.py         # SQLite → PostgreSQL \u002F MySQL \u002F MariaDB migration (see docs\u002FDATABASE_BACKENDS.md)\n├── connectors\u002F                 # 1,200+ connectors (connector.json + run.py) + runner.py\n├── taxii\u002F                      # TAXII 2.1 server (Flask)\n├── docs\u002F                       # Documentation + screenshots\u002F\n├── tools\u002Fnodejs\u002F               # Portable Node 20 runtime (better-sqlite3 ABI)\n├── Dockerfile  docker-compose.yml\n└── SETUP.MD  REQUIREMENTS.MD  README.md\n```\n\n### Tech stack\n\n| Layer | Technology |\n|---|---|\n| Server | Node.js 20 + Express 4 + TypeScript (compiled to CommonJS) |\n| Database | Node: better-sqlite3 (synchronous, no ORM) — a family of SQLite files. Python\u002FSQLAlchemy data layer is **portable to PostgreSQL \u002F MySQL \u002F MariaDB** (`XORCISM_DB_ENGINE`, `tools\u002Fmigrate_db.py`); see [docs\u002FDATABASE_BACKENDS.md](docs\u002FDATABASE_BACKENDS.md) |\n| Client | TypeScript bundled with esbuild (one entry per page) |\n| Charts | Chart.js (dashboard) |\n| Export | SheetJS \u002F XLSX |\n| Auth | session cookies, passkeys (WebAuthn ES256\u002FRS256), optional OIDC |\n| i18n | custom dictionary system, 10 languages, RTL support |\n| Tooling | Python 3.11 + SQLAlchemy 2 (importers), Flask (TAXII) |\n| Local AI | Ollama (optional, offline RAG) |\n| Deployment | Docker + Compose, or portable Node 20 |\n\n### How the explorer works\n\nThe UI is **schema-driven**: the server auto-discovers databases and tables in\n`DB_DIR`, and the client generates a form and a grid for each table from its\nschema. Configuration maps keyed `\"TABLE.Column\"` (FK pickers, datalists, grid\ncolours, checkbox columns, date pickers, read-only computed fields) layer\nbehaviour on top — so adding a table makes it appear after a restart with no code.\n\n### Derived values & background jobs\n\nComputed columns are filled by hooks in `db.ts` before persistence (e.g. asset\n`RiskScore`, EBIOS stakeholder `ThreatLevel`\u002F`Zone`). The Node server runs its own\ntimers — **no external cron**:\n\n- **RiskScore loop** (30 s): per-asset `RiskScore` + per-tenant\n  `EnterpriseRiskScore` (Dashboard headline), with history.\n- **Connector scheduler** (30 s): fires due scheduled connector jobs into `XJOB`.\n- **Session purge** (hourly): removes expired sessions.\n\n---\n\n## 🧭 Modules\n\n| Module | Route | What it covers |\n|---|---|---|\n| **Domain launcher** | `\u002F` | Card grid; entry into every module |\n| **Asset Management** | explorer | Inventory, owners, value, tags, exposure, risk scoring |\n| **Configuration Management** | explorer | CPE naming, OVAL definitions & audits |\n| **Vulnerability Management** | explorer | CVE\u002FKEV\u002FCVSS\u002FEPSS, CIRCL\u002FOSV, bug bounty |\n| **Exploit-DB search** | `\u002Fexploitdb` | Search the local SearchSploit index by keyword\u002FCVE; CVE→public-exploit lookup on the VULNERABILITY form |\n| **Top exposures** | `\u002Fexposure` | Exploitability & relevance fusion score — prioritized \"fix first\" worklist (EPSS+KEV+exploit+CTI+blast radius) |\n| **VOC — Vuln Operations** | `\u002Fvoc` | Remediation as an ops function: SLA policy, MTTR\u002Faging\u002Fvelocity, campaigns, risk-acceptance register |\n| **VM Executive Report** | `\u002Fvm-report` | Vuln risk & SLA posture over time + board-ready myth-busting summary (Print\u002FPDF) |\n| **CTEM** | `\u002Fctem` | ctem.org exposure-identifier taxonomy (29 ids \u002F 8 categories), 3-stage program, discover-from-assets |\n| **Attack paths** | `\u002Fattack-path` | Reachability graph entry→crown-jewel (subnet + BIA edges, fusion-weighted) + choke-point analysis |\n| **Detection coverage** | `\u002Fpurple-team` | Purple-team: chain tools → ATT&CK → Sigma-library coverage + generate the missing rule |\n| **Ransomware $ impact** | `\u002Fransomware` | Replay a ransomware group's TTPs → SLE\u002FALE dollar impact, blast radius, D3FEND controls |\n| **Control assurance** | `\u002Fassurance` | Continuously-proven compliance — controls evaluated live from telemetry, mapped to ISO 27001 \u002F NIST CSF |\n| **CTI watch** | `\u002Fcti-watch` | \"CTI that acts\" — KEV + threat reports matched to your inventory + one-click auto-ticketing |\n| **Surface drift** | `\u002Fdrift` | Attack-surface snapshot & diff — what appeared\u002Fvanished\u002Fnewly-exposed since last time |\n| **Content hub** | `\u002Fcontent` | Export\u002Fimport portable content — attack playbooks, Sigma rule bundle, OpenVEX |\n| **Compliance (GRC)** | explorer | Policies, controls, audits, evidence, findings, CRQ\u002FFAIR |\n| **EBIOS Risk Manager** | `\u002Febios` | 5 ANSSI workshops, business values, feared events, ecosystem |\n| **TPRM** | `\u002Ftprm` | Third-party \u002F supplier risk assessments & questionnaires |\n| **Threat Management (CTI)** | explorer | STIX entities, OpenCTI properties, sightings, watchlists, PIR; **lossless STIX retention + FTS search** + content-addressed object store for large files ([docs\u002FCTI_STORAGE.md](docs\u002FCTI_STORAGE.md)) |\n| **Threat hunting** | `\u002Fhunting` | Hunts, hypotheses, IOC\u002Ftechnique overview, Sigma rules, local-AI hunt assistant |\n| **Threat feeds** | `\u002Fthreat-feeds` | Curated CTI RSS reader; reports with IOC extraction & CVE enrichment |\n| **Ask the threat model** | `\u002Fask` | Local-AI RAG assistant over your XORCISM data |\n| **Threat Modeling** | explorer | STRIDE scope, assets, threats, controls |\n| **Incident Management** | explorer | Alerts → incidents → response |\n| **Ticketing** | explorer | Tasks, comments, attachments |\n| **Xposure \u002F Connectors** | `\u002Fconnectors` | Tool-runners & API imports, scheduled jobs, workers |\n| **OSINT** | explorer | Open-source intelligence toolbox |\n| **Dashboard** | `\u002Fdashboard` | Enterprise risk, vulnerabilities, value, **risk×value**, tags, incidents |\n| **BIA** | `\u002Fbia` | Business Impact Analysis audits & entries |\n| **BIA dependency graph** | `\u002Fbia-graph` | Force graph of BIA entries & dependencies, with impact propagation |\n| **ATT&CK** | `\u002Fattack` | Enterprise \u002F Mobile \u002F ICS \u002F ATLAS + BAS coverage & **LLM-enabled (Anthropic)** overlays |\n| **D3FEND** | `\u002Fd3fend` | Defensive countermeasures mapped to ATT&CK & controls |\n| **A3M** | `\u002Fa3m` | Agentic AI Attack Matrix |\n| **Kill chain** | `\u002Fkill-chain` | ATT&CK tactics as ordered kill-chain phases + adversary TTP overlay |\n| **STIX graph** | `\u002Fstix-graph` | Relationship graph; nodes link back to forms |\n| **Attack-surface graph** | `\u002Fattack-surface` | Asset-centric force graph — apps, CPEs, vulns, orgs, persons, threats, incidents, tags |\n| **Pentesting** | `\u002Fpentest` | Engagements (AUDIT type=Pentest) scoped to assets; run tool connectors; findings & vulnerabilities |\n| **Attack chain** | `\u002Fpentest\u002Fchain` | Tool-chaining playbook run — live tree of tool steps (nmap → web scanners → WPScan), facts-driven, findings roll-up |\n| **SOC Operations** | `\u002Fsoc` | Analyst shifts\u002Fon-call, MTTD\u002FMTTA\u002FMTTR, escalation, NIST 800-61 IR playbooks |\n| **SOC-CMM** | `\u002Fsoc-cmm` | SOC capability-maturity assessment |\n| **CERT \u002F DFIR** | `\u002Fcert-ops` | Forensic cases, evidence & chain of custody (NIST 800-86 \u002F ISO 27037) |\n| **Team Operations** | `\u002Fteam-ops` | Purple\u002FRed\u002FBlue VECTR-style ATT&CK exercises — prevention\u002Fdetection\u002Fvisibility\u002FMTTD |\n| **Governance** | `\u002Fgovernance` | NIST CSF 2.0 **Govern (GV)** register |\n| **Workforce** | `\u002Fworkforce` | NICE + ENISA ECSF roles around PERSON |\n| **AI Threat Advisor** | `\u002Fai-threat-advisor` | OWASP AI Exchange agentic-threat catalogue + advisor |\n| **AI Guardrails** | `\u002Fai-guardrails` | AI-agent guardrails management — discover LLM apps\u002Fagents, score vs a 12-control baseline (OWASP AI Exchange \u002F SAIF \u002F ISO 42001 \u002F LLM Top 10 \u002F ATLAS \u002F NIST AI RMF), local-AI runtime violation monitoring, gateway block telemetry |\n| **EASM** | `\u002Feasm` | External Attack Surface Management — internet-facing assets, exposed services\u002Fports, TLS posture, external KEV, shadow exposure, surface drift |\n| **Frameworks** | `\u002Fframeworks` | Compliance\u002Fsecurity framework catalogue + map each framework to a VOCABULARY (controls catalogue) |\n| **Network sessions** | `\u002Fnetwork-sessions` | NetFlow\u002FIPFIX around assets (Obserae) — services, sessions, top talkers |\n| **Compliance journeys** | `\u002Fcompliance-journeys` | Guided multi-framework wizards (ISO \u002F SOC 2 \u002F NIST \u002F DORA \u002F NIS2 \u002F GDPR …) |\n\n---\n\n## 🔌 Connectors\n\nConnectors live in `connectors\u002F\u003Cid>\u002F` with a `connector.json` manifest\n(auto-discovered under **Connectors** — no rebuild) and a `run.py`. Results are\nnormalized into findings (project → `ASSET`, vuln → `VULNERABILITY` \u002F\n`ASSETVULNERABILITY`). The catalogue holds **1,200+** connectors and is\n**searchable and filterable** (by category & type) in the UI.\n\n| Type | Connectors |\n|---|---|\n| **Network \u002F web scanners** (tool-runners) | nmap, nuclei, nikto, sqlmap, whatweb, wpscan, WPProbe, w3af, OpenVAS |\n| **Vulnerability \u002F posture (API)** | Nessus, Qualys, Rapid7, Wiz, Lacework, Sysdig, Aikido |\n| **CVE intelligence** | **OpenCVE** (CVE monitoring → `VULNERABILITY`) |\n| **SCA \u002F supply chain** | Dependency-Track, OSV-Scanner, **depx** (malicious-package audit) |\n| **Offensive \u002F BAS** | Caldera, Metasploit, Metasploit-scan, Burp Suite, SAINT |\n| **SIEM \u002F detection \u002F EDR** | Splunk, Elastic Security, Microsoft Sentinel, QRadar, **Rustinel** (ETW\u002FeBPF), **YARA** |\n| **Identity (API)** | **Microsoft Entra ID** (users \u002F NHI \u002F devices → `IDENTITY` + `ASSET`) |\n| **OSINT** (tool-runners) | 1,000+ reconnaissance \u002F OSINT tools from the searchable catalogue |\n\n- **Tool-runners** need the named binary on `PATH` on the runner host.\n- **API connectors** are configured **only** via environment variables (never in\n  the UI) — e.g. `CALDERA_URL` + `CALDERA_API_KEY`, `QUALYS_API_URL`\u002F`_USER`\u002F`_PASSWORD`,\n  `DTRACK_URL` + `DTRACK_API_KEY`.\n- **Remote workers**: `python connectors\u002Frunner.py --remote https:\u002F\u002Fhost:9292 --token \u003Ct> --name kali-01 --capabilities nmap,nuclei`.\n\nAdding a connector = drop a folder with `connector.json` + `run.py`. See\n[docs\u002FCONNECTORS.md](docs\u002FCONNECTORS.md) and\n[`connectors\u002Fmanifest.schema.json`](connectors\u002Fmanifest.schema.json).\n\n**Assisted pentesting** — how to configure XORCISM to drive real tools (workers,\ncredentials, RBAC) and run AI-assisted engagements end-to-end (scope\u002FROE, attack-chain\nplaybooks, simulate vs live, findings → exposure): see **[docs\u002FPENTESTING.md](docs\u002FPENTESTING.md)**.\n\n---\n\n## 🗄️ Databases\n\nXORCISM uses a **family of SQLite databases**, auto-created on first start in\n`DB_DIR`. Schema DBs are built from the committed `databases\u002F*_sqlite.sql`;\noperational DBs are created in code.\n\n| Database | Purpose |\n|---|---|\n| `XORCISM` | Core: assets, applications, controls, persons, tags, risk scores |\n| `XVULNERABILITY` | CVE\u002FKEV\u002FCVSS\u002FEPSS, vulnerability domains, bug bounty |\n| `XCOMPLIANCE` | GRC: audits, evidence, OCIL, TPRM, EBIOS, regulator notifications |\n| `XTHREAT` | ATT&CK \u002F ATLAS \u002F D3FEND \u002F A3M, CTI\u002FSTIX, hunts, hypotheses, BAS, Sigma rules, feeds, reports & IOCs |\n| `XATTACK` | CAPEC attack patterns |\n| `XINCIDENT` | Incidents & alerts |\n| `XOVAL` | OVAL definitions |\n| `XMALWARE` | MAEC \u002F malware |\n| `XWINDOWS` | Windows configuration data |\n| `XID` | Users, roles, tenants, sessions, passkeys (operational) |\n| `XTICKET` · `XJOB` · `XAGENT` | Ticketing · connector queue · agents (operational) |\n\nCanonical DDL: [`databases\u002F`](databases) (`*_sqlite.sql`). New tables show up in\nthe explorer after a restart with no code change.\n\n---\n\n## 📥 Reference-data importers\n\nReference-data loaders live in\n[`xorcism_python\u002Fimporters\u002F`](xorcism_python\u002Fimporters) (stdlib `sqlite3` \u002F\nSQLAlchemy + `requests`; DB paths from `xorcism_python\u002Fconfig.py`):\n\n| Importer | Source → target |\n|---|---|\n| `import_attack.py` | MITRE ATT&CK STIX (Enterprise\u002FMobile\u002FICS\u002F**ATLAS**) → `XTHREAT.ATTACK*` |\n| `import_d3fend.py` | MITRE D3FEND + mappings → `XTHREAT.D3FEND*` **and** `XORCISM.CONTROL` |\n| `import_capec.py` | MITRE CAPEC XML → `XATTACK` |\n| `import_a3m.py` | Agentic AI Attack Matrix → `XTHREAT` |\n| `import_atomics.py` | Atomic Red Team → BAS tables in `XTHREAT` |\n| `import_llm_attack.py` | Anthropic LLM ATT&CK Navigator → `XTHREAT.LLMATTACKTECHNIQUE` |\n| `import_hunts.py` · `import_hypotheses.py` | Threat hunts & hypotheses → `XTHREAT` |\n| `import_sigma.py` | SigmaHQ detection rules → `XTHREAT.SIGMARULE` |\n| `import_threat_reports.py` | CTI reports + extracted IOCs → `XTHREAT.THREATREPORT` \u002F `IOC` |\n| `import_osint_tools.py` | OSINT tools catalogue → `XORCISM.TOOL` |\n| `import_nvd_cve.py` · `import_vulnerabilities.py` · `import_KEV.py` · `import_cisa_kev.py` | CVE \u002F KEV → `XVULNERABILITY` |\n| `import_iso27001.py` · `import_nist800-53.py` · `import_controls.py` · `import_cce.py` | Control frameworks → `XORCISM.CONTROL` |\n| `import_oval.py` · `import_maec.py` · `import_threatevent.py` · `import_vulnerabilitydomains.py` | OVAL \u002F MAEC \u002F threat events \u002F domains |\n\n```powershell\npy -3 xorcism_python\\importers\\import_attack.py --domain atlas\npy -3 xorcism_python\\importers\\import_d3fend.py\npy -3 xorcism_python\\importers\\import_sigma.py                 # SigmaHQ detection rules\npy -3 xorcism_python\\importers\\import_threat_reports.py        # CTI reports + IOCs\npy -3 xorcism_python\\importers\\import_threat_reports.py --url https:\u002F\u002F...\u002Freport   # one report\n.\\import_nvd_cve.ps1\n```\n\n---\n\n## 🌐 Internationalization\n\n10 UI languages with **strict key parity** (every dictionary holds the same keys):\n\n| Code | Language | | Code | Language |\n|---|---|---|---|---|\n| `en` | English | | `pt` | Português |\n| `fr` | Français | | `zh` | 中文 |\n| `de` | Deutsch | | `ja` | 日本語 |\n| `it` | Italiano | | `ar` | العربية (RTL) |\n| `es` | Español | | `ru` | Русский |\n\n`en` + `fr` are inline in `client\u002Fts\u002Fi18n.ts`; the other eight are in\n`client\u002Fts\u002Flocales\u002F*.ts`. Language is stored in `localStorage[\"xorcism_lang\"]`,\nwith `t(key)` falling back `LANG → en → fr → key`. To add a language: copy a\nlocale file, translate all keys, register it in `i18n.ts`.\n\n---\n\n## 👥 Roles & multi-tenancy\n\nXORCISM is multi-tenant: most tables carry a `TenantID` and are **row-scoped**\nautomatically. Access is governed by **RBAC** (`userCan`) plus DB-level\nread\u002Fwrite per role.\n\n- **Admin** — belongs to the **System** tenant, super-admin (sees all tenants),\n  user & broadcast management.\n- **User** — assigned to a tenant; read\u002Fwrite within scope; admin-only tables are\n  hidden.\n\nSign-in supports **password**, **passkeys (WebAuthn)** and optional **OIDC** SSO.\n\n---\n\n## 🧩 REST API\n\nA read-only, tenant-scoped REST API exposes the platform's data (assets,\nincidents, exposures, SLA\u002FRTO posture, enterprise risk score) for SIEMs,\ndashboards, CI pipelines and automation.\n\n- **Base URL:** `\u002Fapi\u002Fv1` · **Spec:** `GET \u002Fapi\u002Fv1\u002Fopenapi.json` (OpenAPI 3)\n- **Interactive docs:** **`\u002Fapi-docs`** · **Manage keys:** **`\u002Fapi-keys`**\n- **Auth:** API key (`Authorization: Bearer xor_…` or `X-API-Key: xor_…`); a key\n  acts as its owning user with the same RBAC + tenant scope. SHA-256 stored only.\n  Keys hold **scopes** (`read`\u002F`write` or granular like `incidents:write`) and an\n  optional **expiry**.\n- **Webhooks:** register HTTPS endpoints at **`\u002Fwebhooks`** to receive an HMAC-signed\n  (`X-XORCISM-Signature`) JSON `POST` on `incident.created` \u002F `incident.updated` \u002F `asset.updated`.\n\n| Method | Path | Description |\n|---|---|---|\n| `GET` | `\u002Fapi\u002Fv1\u002Fhealth` | Liveness probe (no auth) |\n| `GET` | `\u002Fapi\u002Fv1\u002Fme` | Identity behind the key |\n| `GET` · `PATCH` | `\u002Fapi\u002Fv1\u002Fassets` · `\u002Fassets\u002F{id}` | Asset inventory (paginated); set SLA\u002Fvalue fields |\n| `GET` · `POST` · `PATCH` | `\u002Fapi\u002Fv1\u002Fincidents` · `\u002Fincidents\u002F{id}` | List \u002F create \u002F update incidents |\n| `GET` | `\u002Fapi\u002Fv1\u002Fincident-sla` | Incident durations vs asset SLAs & BIA RTOs |\n| `GET` | `\u002Fapi\u002Fv1\u002Fexposures` | Top exposures (fusion exploitability score) |\n| `GET` | `\u002Fapi\u002Fv1\u002Frisk` | Enterprise risk score |\n\n```bash\nexport XORCISM_API_KEY=xor_…\ncurl -s https:\u002F\u002Fyour-host\u002Fapi\u002Fv1\u002Fincident-sla -H \"Authorization: Bearer $XORCISM_API_KEY\" | jq '.summary'\n```\n\nFull reference, examples and the roadmap: **[API.md](API.md)**.\n\n## 🛠️ Troubleshooting\n\n| Symptom | Cause \u002F fix |\n|---|---|\n| `better-sqlite3` `ERR_DLOPEN_FAILED` \u002F wrong `NODE_MODULE_VERSION` | Running on Node 23+\u002F24. Use **Node 20** (`tools\u002Fnodejs\u002Fnode.exe`). |\n| `Unknown database: X` | `DB_DIR` is wrong or the `*.db` is missing. |\n| Stale reads \u002F WAL corruption | Databases are inside OneDrive\u002Fa synced folder — move `DB_DIR` out. |\n| `Cannot POST \u002Fapi\u002F...` returns HTML | Server build is stale — `npm run build` and restart. |\n| Port 9292 busy | Set `$env:PORT` before `npm start`. |\n| `better-sqlite3` build error on `npm install` | Use Node 20 LTS (prebuilt) or install MSVC Build Tools + Python for node-gyp. |\n| Lost the seeded admin password | Fresh install only: delete `DB_DIR\\XID.db` and restart to re-seed. |\n\nMore in [SETUP.MD § 11](SETUP.MD).\n\n---\n\n## 🤝 Contributing\n\nIssues and pull requests are welcome.\n\n1. Branch off `main`.\n2. Build both sides — `npm run build` (server `tsc` + client `esbuild`) must pass.\n3. If you touch UI strings, **add the key to all 10 dictionaries** (`i18n.ts`\n   inline `en`\u002F`fr` + the 8 `locales\u002F*.ts`) and keep parity.\n4. New tables that hold tenant data must be added to the tenant-scoped set so\n   they are row-scoped.\n5. Keep code comments in **English**.\n6. Open a PR with a clear description.\n\n---\n\n## 📄 License & disclaimers\n\nXORCISM is an **open-source** cybersecurity platform — see\n[xorcism.ai](https:\u002F\u002Fxorcism.ai) for licensing terms (add a `LICENSE` file to the\nrepository to make the terms explicit).\n\n> **Trademarks & frameworks.** XORCISM integrates and references third-party\n> standards and frameworks — **MITRE ATT&CK®, D3FEND™, CAPEC™** (MITRE\n> Corporation), **EBIOS Risk Manager** (ANSSI), **STIX\u002FTAXII** (OASIS), **OVAL**,\n> **OCIL**, **CVE\u002FKEV\u002FCVSS\u002FEPSS**. XORCISM is **not affiliated with, endorsed by,\n> or sponsored by** MITRE, ANSSI, OASIS or any framework owner. All trademarks\n> belong to their respective holders.\n\n> **No warranty.** Provided \"as is\", without warranty of any kind. You are\n> responsible for how you deploy and use it, and for obtaining authorization\n> before running any offensive\u002Fscanning connector against a target.\n\n---\n\n**Learn more → [xorcism.ai](https:\u002F\u002Fxorcism.ai) · [YouTube channel](https:\u002F\u002Fwww.youtube.com\u002Fchannel\u002FUCk6OWxMBg1H4gHTZdpZGAhA)**\n","XORCISM 是一个开源、自托管的网络安全暴露面统一管理平台，旨在整合资产、配置、漏洞、威胁、合规与事件数据，持续计算企业级网络风险评分。其核心功能包括基于统一数据模型的全生命周期暴露面管理、内置攻防闭环（支持OSINT采集、攻击路径验证与可利用性优先级排序）、多源扫描数据接入（兼容Nessus、OpenVAS等）、STIX\u002FTAXII 2.1 原生集成，以及对 EBIOS RM、MITRE ATT&CK 等主流框架的原生支持。平台采用 TypeScript\u002FNode.js 构建，支持 SQLite（默认）、PostgreSQL 和 MySQL 后端，适用于中大型组织的安全运营中心（SOC）、GRC 团队及 CISO 办公室开展自主化、合规驱动的风险量化与协同治理。","2026-07-10 02:30:12","CREATED_QUERY"]