Each defense engine in the Alaska Sovereign Suite is developed as a modular, standalone pure-Rust library and CLI executable. Zero external C runtime dependencies, zero Python, and zero cloud lock-in.
Automated compliance baseline audit, pre-flight snapshotting, and atomic drift remediation across Windows Registry and Linux sysctl baselines.
RFC 1035 pure-Rust DNS resolver blocking outbound malware C2 beacons, DGA domain generation, and tunneling via mathematical entropy thresholds (H >= 3.75).
Eliminates static long-lived credentials by issuing 15-minute cryptographically signed Ed25519 OpenSSH certificates bound to hardware WebAuthn tokens.
Cryptographically chains Windows Event Logs (EVTX 1102, 4624, 4688) into append-only SHA-256 Merkle trees. Instant tripwire alerting if logs are cleared by malware.
Simulates benign adversary TTPs (T1059, T1078, T1053) in volatile memory to continuously verify EDR readiness with zero residue and zero host damage.
High-speed concurrent subnet scanner auditing open TCP/UDP ports, identifying unmanaged shadow IT, and pinpointing perimeter exposure across enterprise enclaves.
Audits executable binaries (PE/ELF) for ASLR, DEP, SafeSEH, Authenticode signatures, and exports CycloneDX 1.5 Software Bill of Materials (SBOM) for compliance.
Embeds 20+ pre-compiled Sigma threat rules and dynamically translates them into Azure Sentinel KQL, Splunk SPL, PowerShell, and Grep queries on the fly.
Deobfuscates malicious scripts and payloads in pure Rust: multi-layer Base64, UTF-16LE, XOR key brute-forcing, defanging, and Shannon entropy analysis.
Inspects active process trees for parent-child spoofing (e.g. Word spawning PowerShell), Living-off-the-Land binary abuse, and high-entropy command lines.
Instantly severs all inbound and outbound network connectivity using native Windows Filtering Platform (WFP) while preserving sovereign telemetry and auto-release timers.
Provides offline contextual threat analysis for MITRE TTPs and regulatory gaps. Zero cloud calls, running entirely on local CPU tensors via Hugging Face Candle.
Manages forensic incident investigations, seals evidentiary artifacts into encrypted vaults, and produces court-admissible chain-of-custody verification logs.