File integrity monitor
Track file hashes, modification events, and integrity drift without pretending a hash alone explains intent.
A public HIR/OAM cybersecurity and audit-trail map for file integrity, event provenance, hash-chained logs, HIR triage scoring, tamper detection, and reviewable runtime defense.
This branch is about preserving evidence quality under pressure: what changed, when it changed, who or what triggered it, whether the chain remained intact, and whether the event should be triaged for review.
Track file hashes, modification events, and integrity drift without pretending a hash alone explains intent.
Structured event records preserve timestamps, event type, evidence fields, and reviewable runtime context.
Sequential audit entries can expose tamper breaks, missing links, or discontinuities requiring human review.
Evidence is routed through honesty, integrity, respect, pressure, and risk-framing boundaries before escalation.
Audit output can feed defensive gates, HIR-SPU-style review, or runtime security dashboards.
This Space documents defensive audit concepts only. It contains no bypass, malware, intrusion, or exploitation instructions.
Main source/search target: Primordial_CyberSec_Suite_v0.1_Collin_D_Weber.zip
The Rice-facing inventory describes CyberSec Suite v0.1 as a runnable Python package for file integrity monitoring, process audit, HIR-bridge triage scoring, and JSON audit trails, while explicitly keeping it at prototype status and not certified security software.
Because the CyberSec Suite source ZIP may not be present locally in this chat workspace, this packet also includes relevant audit-chain files extracted from the Primordial OS Runtime Prototype when available.
This is a defensive architecture and public review prototype.
It is not certified security software, not production SIEM, not antivirus, not EDR, not malware analysis automation, not penetration-testing authorization, not compliance certification, not legal advice, and not a guarantee of detection or safety.
No exploitation steps, bypass recipes, malware logic, credential-theft guidance, unauthorized testing instructions, or operational attack playbooks are provided.
Authorized defensive review only. Structural correspondence, not ontological equivalence.