CyberCLI
← The Guild

Knight

Chapter · Detection

Front-Line Verifier · First responder · verifier

Ship status
Doctrine · v1.x L2-L3
Charter
Summary

Verifies a triaged alert via low-blast playbooks — sandbox re-detonation, EDR query, IOC match — and returns a TRUE_POSITIVE / FALSE_POSITIVE / INDETERMINATE verdict with calibrated confidence.

Charter

Charge the front line first to verify. On a fresh detection, run signed verification playbooks — pull the artifact, re-detonate, query EDR for live-fire evidence, confirm or refute the alert — and attach a verdict (TP / FP / INDETERMINATE) plus evidence to the case before Shield is dispatched. Knight may run pre-approved low-blast containment (host isolation, file quarantine, URL block) only when verification confirms a true positive and the action is within current trust ceiling.

Skill enhancements

Knight keeps its job — it just gets sharper when you equip an optional AI Skill (bring your own provider key; we never resell one). Equip one and it earns a title; equip more and it ascends.

Knight Rune Knight (one intel skill) Divine Rune Knight (hash + IP reputation)
Hash Reputation live VirusTotal

Looks up a file hash's reputation against a threat-intel provider — engine detections, and whether the binary is signed by the real vendor.

How it enhances: Resolves the trusted-tool masquerade: a signed, provider-clean hash is a benign false positive (add an exclusion); an unsigned, N-engine-malicious hash wearing a vendor's name is a real threat. Knight rules on evidence, not the file name.

IP Reputation live GreyNoise Community + AbuseIPDB

Checks a public IP against GreyNoise (is it just benign internet noise — scanners, search engines, common business services?) and AbuseIPDB (community abuse confidence + report volume).

How it enhances: The false-positive killer on network and IDS alerts: auto-dismiss the benign-scanner flood, confirm known-bad infrastructure. Equip this alongside Hash Reputation and Knight ascends to Divine Rune Knight.

Trust ceiling

L3 default: pre-approved low-blast verification playbooks (sandbox / EDR query / IOC match) and signed low-blast containment playbooks. Higher-blast and multi-action containment is Marshal-sequenced + Paladin-executed under the Bridge.

Executes via

AuthorityBridge for verification + signed low-blast playbooks (each with its own audit row). Higher-blast containment hands off to Marshal + Paladin.

Never does

Never executes higher-blast or multi-action containment. Never elevates its own ceiling. Never bypasses the Bridge.

Engine wiring

Engine Relationship Note
Beacons Read Reads the case + the signals Warden assembled.
AuthorityBridge Propose Verification playbooks pass through the Bridge with their own audit row.
Escalates to

Paladin · Marshal

Escalates from

Warden · Marshal · Seeker

Honesty
  • Engine status: Doctrine · v1.x
  • Model lane: Local 8B / 14B abliterated (verification reasoning).
  • Training: QLoRA queued after Warden; needs verification-specific synthetic data (sandbox results, EDR shape).
  • Status: Doctrine · v1.1. Charter published; routed in v1.1 multi-pass orchestration. The Pro tier unlocks Knight verification when v1.1 ships. Trained LoRA in the autotrain queue.

Go deeper