Problem
Individual components (Linux containers, Windows VMs, TLS termination, Validator) have been built and tested separately. AC-1 and AC-2 need to run as complete anchor cases to surface integration issues.
Scope
- Define AC-1 scenario: Windows workstations + TLS + data exfiltration attack
- Define AC-2 scenario: Linux server + TLS termination + external attack with campaign
- Run both scenarios end to end through the full pipeline (Generator → Bundle → Validator)
- Fix any integration gaps discovered (timing issues, path mismatches, missing cross-references)
Out of Scope
- AC-3 (HTTPS proxy decryption)
- Performance optimization
- New attack tools beyond what M1-M3 already support
Done when
- AC-1 and AC-2 both produce reproducible bundles
- Both bundles pass Validator L1-L4
- Scenarios are committed as reference cases
Dependencies
Problem
Individual components (Linux containers, Windows VMs, TLS termination, Validator) have been built and tested separately. AC-1 and AC-2 need to run as complete anchor cases to surface integration issues.
Scope
Out of Scope
Done when
Dependencies