# OpenCyberSec

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# OpenCyberSec

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenC5ISR |
| Product | OpenC5ISR |
| Release | 0.15.1 |
| Deployment | `openc5isr.bss.dev` |
| Source | `/srv/bss/releases/OpenC5ISR-v0.15.0-20app` |
| Evidence | Catalog intent plus component-scoped static evidence |
| Source fingerprint | `93926e8c834f1ed79c9017a4096f70c76d73ce4f870f104fbd0cf54b2bed50ee` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Purpose

The cybersecurity operations module for asset visibility, findings, incidents, controls, evidence, response workflows and operational cyber context.

## Operational value

Connects cyber observations and response tasks to the same assets, networks, cases and collaboration environment used for operations.

## Differentiators

Cybersecurity is represented as an operational mission function with semantic relationships and taskable effects rather than a disconnected dashboard.

## Platform connections

- OpenNetworks
- OpenIIA
- OpenTask
- OpenKnowledge
- OpenCOP

## Release detection

| Status | Score | Evidence items |
| --- | --- | --- |
| detected | 117 | 12 |

| Evidence type | Source | Match |
| --- | --- | --- |
| path | `OPENCYBERSEC-QUICKSTART.md` | `opencybersec` |
| path | `OPENCYBERSEC.md` | `opencybersec` |
| path | `.opennetworks-backup-20260827T210646Z/ontology/opencybersec.ttl` | `opencybersec` |
| path | `data/opencybersec.json` | `opencybersec` |
| path | `edge/opencybersec/README.md` | `opencybersec` |
| content | `API.md` | `opencybersec` |
| content | `CHANGELOG.md` | `opencybersec` |
| content | `DEPLOY-GODADDY.md` | `opencybersec` |
| content | `OPENCYBERSEC-QUICKSTART.md` | `opencybersec` |
| content | `OPENCYBERSEC.md` | `opencybersec` |
| path | `open-cybersec/app.js` | `open-cybersec` |
| path | `open-cybersec/index.html` | `open-cybersec` |

## Candidate REST/API interfaces

No component-specific REST route was associated by the scanner.

## Candidate real-time interfaces

No component-specific WebSocket endpoint was associated by the scanner.

## Configuration candidates

| Variable | Default | Evidence |
| --- | --- | --- |
| `API` | — | open-cybersec/app.js, public/open-cybersec/app.js, public/open-llm/app.js |
| `BASE` | http://127.0.0.1:3000 | DEPLOY-GODADDY.md, OPENCYBERSEC-QUICKSTART.md, OPENCYBERSEC.md, UPGRADE-v0.14.0.md |
| `CONFIG` | — | drivers/install_openpnt_agent.sh, edge/opencybersec/install.sh, edge/openssa-sensor/install/check-sensor.sh, edge/openssa-sensor/install/install-sensor.sh |
| `DATA_DIR` | path.join(ROOT | OPENCYBERSEC-QUICKSTART.md, OPENCYBERSEC.md, RELEASE-MANIFEST-v0.14.0.json, UPGRADE-v0.14.0.md |
| `ENV_FILE` | — | edge/opencybersec/install.sh |
| `EUID` | $(id -u | drivers/install_openpnt_agent.sh, edge/opencybersec/install.sh, edge/opencybersec/uninstall.sh, edge/openpnt-linuxptp/install-linuxptp.sh |
| `HERE` | — | edge/openpnt-linuxptp/SELF-TEST.sh, edge/openpnt-linuxptp/install-linuxptp.sh, edge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.sh, edge/openssa-sensor/native/uhd_spectrum_engine/build.sh |
| `INSTALL_DIR` | — | edge/opencybersec/install.sh |
| `OPENCYBERSEC_AGENT_TOKEN` | [REDACTED] | OPENCYBERSEC-QUICKSTART.md, OPENCYBERSEC.md, server.js, examples/opencybersec/ingest-examples.sh |
| `OPENCYBERSEC_OPERATOR_TOKEN` | [REDACTED] | OPENCYBERSEC-QUICKSTART.md, OPENCYBERSEC.md, server.js, examples/opencybersec/ingest-examples.sh |
| `OPENSOF_ROOT` | https://wallacecorptech.com/live/opensof | examples/opencybersec/ingest-examples.sh |
| `PATH` | /usr/sbin:/usr/bin:/sbin:/bin | edge/opencybersec/opencybersec_agent.py, lib/openllm/pipeline-engine.js, lib/openllm/util.js, tests/openpnt_agent_smoke_test.py |
| `ROOT` | — | edge/opencybersec/install.sh, edge/openpnt-linuxptp/SELF-TEST.sh, edge/openpnt-linuxptp/install-linuxptp.sh, edge/openssa-sensor/install-demo-sensor.sh |
| `RUN_ID` | — | OPENCYBERSEC.md |
| `SERVICE` | — | edge/opencybersec/install.sh |

## Service candidates

| Service | ExecStart | Source |
| --- | --- | --- |
| opencybersec-agent.service | `/opt/opencybersec-agent/opencybersec_agent.py --config /etc/opencybersec-agent.json` | `edge/opencybersec/systemd/opencybersec-agent.service` |

## External dependencies/endpoints

| Host | URL | Source |
| --- | --- | --- |
| loammhpng4.c36.airoapp.ai | `https://loammhpng4.c36.airoapp.ai/` | `API.md` |
| loammhpng4.c36.airoapp.ai | `https://loammhpng4.c36.airoapp.ai/` | `CHANGELOG.md` |
| openc5isr.bss.dev | `https://openc5isr.bss.dev/` | `data/opencybersec.json` |
| opensof.local | `https://opensof.local/exercise` | `examples/opencybersec/csaf-advisory.json` |
| opensof.local | `https://opensof.local/ontology` | `.opennetworks-backup-20260827T210646Z/ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/ontology` | `ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/ontology/cyber` | `.opennetworks-backup-20260827T210646Z/ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/ontology/cyber` | `ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/ontology/opencybersec` | `.opennetworks-backup-20260827T210646Z/ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/ontology/opencybersec` | `ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/resource/` | `.opennetworks-backup-20260827T210646Z/ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/resource/` | `ontology/opencybersec.ttl` |
| opensof.local | `https://opensof.local/vex/exercise-0001` | `examples/opencybersec/openvex.json` |

## Verification checklist

- Confirm the component is included and enabled in this edition/release.
- Record its authoritative service, process/container, port, base URL and health endpoint.
- Exercise its primary operator workflow and capture expected versus actual results.
- Verify authentication, authorization, audit, error behavior and data handling policy.
- Verify OpenBus/OpenKnowledge relationships and time/provenance metadata where applicable.
- Document known limitations and the release in which they are corrected.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->