Skip to content

Feat/credential stuffing - #15

Merged
raymondproguy merged 7 commits into
mainfrom
feat/credential-stuffing
Sep 13, 2026
Merged

raymondproguy merged 7 commits into
mainfrom
feat/credential-stuffing

Conversation

@raymondproguy

Copy link
Copy Markdown
Contributor

No description provided.

Extends item 8's AnomalyStore rather than tracking attempts twice:
CountTargetsForIP reads the same rows and partial index, so no
migration. Known and unknown targets are counted separately because
the attempted email is never stored — unknowns can only be attempts.
Runs on failures (where a spray is visible) and on successes (where a
spray that landed is visible), both after the attempt is recorded so
the burst includes it. Cooldown keeps a sustained attack to a few
audit events instead of one per failed attempt. Report-only, nil-safe.
The wiring tests are the point: one IP failing against many accounts is
flagged, one account hammered repeatedly is not, a success from a
spraying IP is flagged against its account, and a broken store or a
zero TargetAccounts degrades to no detection rather than no logins.
Runs the spray, the unknown-address variant, the one-account-hammered
case that must NOT flag, cooldown suppression, and both off switches
against an in-memory engine. No database required.
Covers the spray, the unknown-address variant, the one-account case that
must not flag, cooldown behaviour, both off switches, and the per-IP
blind spot a botnet-distributed spray leaves.
Item 9 removed from NEXT.md and its remaining items renumbered, per that
file's convention. CURRENT-STATE.md records the branch, why it was cut
from feat/anomaly-detection instead of main, and the assumptions.
@raymondproguy
raymondproguy merged commit f36c78f into main Sep 13, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant