Add a --report flag to the pcap command that prints one forensic summary of a whole capture (endpoint inventory, fingerprint distribution, intel verdicts, detection alerts, and a coverage section with the TLS miss rate and throughput) instead of the per-event stream, folding in intel and detection automatically when a seeded database is present. Add a tls_handshakes_fingerprinted counter and Counters::tls_miss_rate so truncated and multi-segment ClientHellos the capture clipped are reported rather than mistaken for absence. Add criterion benches over the vendored captures and the parse/hash hot path. Plus frontend landing and asset polish. |
||
|---|---|---|
| .. | ||
| .pnpm-store/v10 | ||
| public | ||
| src | ||
| .dockerignore | ||
| .gitignore | ||
| .npmrc | ||
| .stylelintignore | ||
| biome.json | ||
| index.html | ||
| package.json | ||
| pnpm-lock.yaml | ||
| stylelint.config.js | ||
| tsconfig.app.json | ||
| tsconfig.json | ||
| tsconfig.node.json | ||
| vite.config.ts | ||