ShadowClaw 1.5.0¶
Version 1.5.0 detects agents handing work to other agent sessions through both local files and public transfer surfaces, and replaces sampled macOS connection visibility with streamed process-attributed TCP and QUIC initiation.
Inter-agent shared channels¶
- Local path handoff — correlates a write outside a git working tree with a later read by a different attributed agent session.
- External surface handoff — correlates two sessions reaching the same catalogued paste, file-drop, webhook, object-store, or tunnel service.
- Both are relationship evidence rather than stages one session performed, so they remain outside the ordered kill-chain bonus and map to standalone ATT&CK tactics.
- Findings are emitted against the reader and name the earlier writer/reacher, producing one actionable timeline event rather than two unrelated records.
The feature was validated with real Cursor-to-Codex handoffs. A complete test chain combined credential access, public-surface access, and both shared-channel signals into one critical finding.
Event-driven network visibility¶
On macOS, PKTAP now observes process-attributed connection initiation as it happens:
- outbound TCP SYNs for TCP
- outbound, full-sized QUIC v1/v2 client Initial packets for HTTP/3
- IPv4 and IPv6
lsof remains additive for settled state, duration, listeners, and UDP/TCP
socket inventory. Duplicate PKTAP/lsof evidence is folded by physical
endpoint so one connection remains one observation.
The startup banner distinguishes observed (PKTAP) + polled (lsof) from a
poll-only fallback. A quiet streamed source and a quiet sample are not the same
coverage claim.
A paired live comparison confirmed the intended relationship: PKTAP recovered
brief initiations polling missed, while lsof retained sockets whose packet
metadata carried no process. A real outbound Brave QUIC capture is replayed in
the fixture suite, with repeated Initial packets folded into one flow and zero
kernel drops in the source capture.
More complete protocol coverage¶
- Plane B now includes connected UDP sockets, closing the prior QUIC/HTTP-3 blind spot.
- QUIC capture is outbound-only, constrained to standard HTTPS/HTTP-3 ports, and accepts protocol-valid v1/v2 Initial shapes rather than any UDP packet sharing two header bits.
- DNS answers and catalog candidates sharing one IP are retained rather than collapsed to a single hostname, so a catalogued transfer surface cannot disappear behind its parent CDN hostname. Ambiguous candidates are discounted and cannot establish an inter-agent channel; preserving evidence is not permission to guess which hostname one connection used.
Acquisition reliability¶
Several acquisition paths that could look healthy while yielding no usable evidence were corrected and are now protected by captured-output fixtures:
- macOS Endpoint Security file-event prefiltering
- DNS packet rendering and answer correlation
- local shared-channel write acquisition
- process-attributed packet parsing, including IPv6 and unattributable packets
- real Linux
/procprocess, fd, TCP/UDP, IPv4/IPv6 parsing and inode joins
Health output now separates source liveness from useful output so “running but empty” cannot masquerade as full coverage.
Signal quality¶
- Encoding/packaging is corroboration-gated and no longer supplies a cheap kill-chain stage by itself.
- Explicit payload-transfer commands remain a separate ungated signal.
- Routine configuration reads are no longer labelled credential access; files that contain credentials inline retain or gain full confidence.
- Temporary test/config paths cannot become persistence findings.
- Kernel interfaces such as
/dev/nullcannot become local handoff channels. - Set-ID events are privilege escalation only when the target is root; the event does not carry enough before-state to classify a non-root transition as escalation safely.
Platform work¶
- Linux Plane C combines
cn_procprocess events withfanotifyfile events. - The Linux backend is replay-tested against real captured
/procfiles, including completestatrecords and TCP/UDP sockets over IPv4 and IPv6. - Windows Plane C is implemented to receive race-free argv from a private SystemTraceProvider process stream, with Security 4688 as an independent policy-gated fallback. Runtime health reports argv coverage degraded if that stream is not active, rather than letting command-line-derived signals look quiet. This path is not claimed release-ready until the elevated live acceptance test passes.
Documentation and licensing¶
- The project is released under Apache License 2.0.
- Provenance and Kinetic Trust Protocol attribution are recorded separately from license terms.
- Public documentation includes the new shared-channel, PKTAP, QUIC, UDP, and platform-coverage behavior while continuing to redact evasion-useful thresholds and weights.
Upgrade¶
The macOS launch daemon runs directly from the checked-out repository. After updating:
The status banner should report the DNS sniffer, Endpoint Security streams, and
observed (PKTAP) + polled (lsof) connection coverage.