cmd/

directory
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0

Directories

Path Synopsis
Command seed-detections enrols a fleet agent, registers a detection signing key, and ships a few SIGNED detection batches (real v2 wire contract) so the incident/fleet flow can be demonstrated with data.
Command seed-detections enrols a fleet agent, registers a detection signing key, and ships a few SIGNED detection batches (real v2 wire contract) so the incident/fleet flow can be demonstrated with data.
Command seed-fleet-detections emulates a real EDR agent end-to-end so the incident flow can be demonstrated with genuine (non-mock) data.
Command seed-fleet-detections emulates a real EDR agent end-to-end so the incident flow can be demonstrated with genuine (non-mock) data.
Command synapse-agent is the fleet VM agent (#410, epic #405).
Command synapse-agent is the fleet VM agent (#410, epic #405).
Command synapse-api is the HTTP API server entrypoint.
Command synapse-api is the HTTP API server entrypoint.
Command synapse-assessment-backfill runs the resumable historical singleton-Cycle backfill.
Command synapse-assessment-backfill runs the resumable historical singleton-Cycle backfill.
Command synapse-assessment-integrity runs the read-only Assessment Cycle integrity verifier.
Command synapse-assessment-integrity runs the read-only Assessment Cycle integrity verifier.
Command synapse-assessment-snapshot-backfill projects historical scan evidence into immutable legacy Assessment Snapshots.
Command synapse-assessment-snapshot-backfill projects historical scan evidence into immutable legacy Assessment Snapshots.
Command synapse-ast parses a source tree with language-aware (tree-sitter) grammars and emits structural facts as JSON on stdout.
Command synapse-ast parses a source tree with language-aware (tree-sitter) grammars and emits structural facts as JSON on stdout.
Command synapse-bench produces deterministic reports from supplied observations or the embedded owned SCA corpus.
Command synapse-bench produces deterministic reports from supplied observations or the embedded owned SCA corpus.
Command synapse-callgraph builds a general first-party call graph from Go source (via go/ssa) and emits it as the taintcallgraph wire JSON on stdout.
Command synapse-callgraph builds a general first-party call graph from Go source (via go/ssa) and emits it as the taintcallgraph wire JSON on stdout.
Command synapse-cli runs Synapse's own SCA pipeline from the command line.
Command synapse-cli runs Synapse's own SCA pipeline from the command line.
Command synapse-cluster-agent is the Kubernetes cluster agent (#411/#446, epic #405).
Command synapse-cluster-agent is the Kubernetes cluster agent (#411/#446, epic #405).
Command synapse-cspm is the sandboxed CSPM SDK helper.
Command synapse-cspm is the sandboxed CSPM SDK helper.
synapse-dast-helper owns HTTP clients and authenticated session state outside the API process.
synapse-dast-helper owns HTTP clients and authenticated session state outside the API process.
Command synapse-finding-lineage-backfill projects legacy Findings into versioned Identities and immutable Observations.
Command synapse-finding-lineage-backfill projects legacy Findings into versioned Identities and immutable Observations.
Command synapse-fptriage-blind manages offline blinded human review packets for an existing shadow evaluation report.
Command synapse-fptriage-blind manages offline blinded human review packets for an existing shadow evaluation report.
Command synapse-fptriage-compare validates and compares two deterministic AI false-positive triage shadow reports.
Command synapse-fptriage-compare validates and compares two deterministic AI false-positive triage shadow reports.
Command synapse-fptriage-curate converts explicitly reviewed AI-triage outcomes into an offline evaluation dataset after privacy and label-quality approval.
Command synapse-fptriage-curate converts explicitly reviewed AI-triage outcomes into an offline evaluation dataset after privacy and label-quality approval.
Command synapse-fptriage-drift compares a saved AI-triage observability distribution with a versioned, human-approved baseline.
Command synapse-fptriage-drift compares a saved AI-triage observability distribution with a versioned, human-approved baseline.
Command synapse-fptriage-eval runs the production false-positive triager in shadow mode over a versioned, human-reviewed golden dataset and emits a deterministic machine-readable report.
Command synapse-fptriage-eval runs the production false-positive triager in shadow mode over a versioned, human-reviewed golden dataset and emits a deterministic machine-readable report.
Command synapse-fptriage-release creates an immutable, versioned ledger of independently approved AI-triage promotions and rollbacks.
Command synapse-fptriage-release creates an immutable, versioned ledger of independently approved AI-triage promotions and rollbacks.
Command synapse-mcp exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
Command synapse-mcp exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
Command synapse-migrate applies the embedded PostgreSQL migration set once.
Command synapse-migrate applies the embedded PostgreSQL migration set once.
Command synapse-reachability-authority curates fixed reachability controller assets.
Command synapse-reachability-authority curates fixed reachability controller assets.
Command synapse-reachability-cycle runs the fixed reachability benchmark lifecycle.
Command synapse-reachability-cycle runs the fixed reachability benchmark lifecycle.
Command synapse-release-evidence creates and verifies deterministic release asset manifests.
Command synapse-release-evidence creates and verifies deterministic release asset manifests.
synapse-sandbox-check proves the production sandbox runner's confinement posture.
synapse-sandbox-check proves the production sandbox runner's confinement posture.
Command synapse-sca-archive preserves benchmark evidence in content-addressed storage.
Command synapse-sca-archive preserves benchmark evidence in content-addressed storage.
Command synapse-sca-bench captures one pinned SCA benchmark observation.
Command synapse-sca-bench captures one pinned SCA benchmark observation.
Command synapse-sca-cycle runs fixed SCA benchmark cycles.
Command synapse-sca-cycle runs fixed SCA benchmark cycles.
Command synapse-sca-prepare creates public diagnostic inputs for an SCA benchmark.
Command synapse-sca-prepare creates public diagnostic inputs for an SCA benchmark.
Command synapse-verify-restore verifies a restored PostgreSQL database and evidence bucket without changing either system.
Command synapse-verify-restore verifies a restored PostgreSQL database and evidence bucket without changing either system.
Command synapse-worker is the privileged execution worker: it claims recon jobs the API enqueued to the durable queue and runs them under the SAME gate/audit/evidence invariants as the in-process path, but with the sandbox + kernel egress allowlist (through a narrow root-owned broker on hardened execution hosts).
Command synapse-worker is the privileged execution worker: it claims recon jobs the API enqueued to the durable queue and runs them under the SAME gate/audit/evidence invariants as the in-process path, but with the sandbox + kernel egress allowlist (through a narrow root-owned broker on hardened execution hosts).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL