Skip to content

Security: Rootless-Ghost/HuntForge

SECURITY.md

Security Policy

Overview

HuntForge is a threat hunting tool designed for authorized use by security professionals. It operates fully offline and does not transmit data externally.

Intended Use

HuntForge is intended for:

  • Authorized penetration testers and red teamers
  • Blue team threat hunters and SOC analysts
  • Security researchers and students in authorized lab environments

Do not use HuntForge playbooks on systems you do not own or have explicit permission to test.

Reporting a Vulnerability

If you discover a security vulnerability in HuntForge, please:

  1. Do not open a public GitHub issue.
  2. Contact the maintainer privately via GitHub security advisories.
  3. Include a description of the vulnerability and steps to reproduce.

We aim to respond within 72 hours and provide a fix within 14 days where feasible.

Supported Versions

Version Supported
1.0.x

Scope

This policy covers the HuntForge source code in this repository. Third-party dependencies are subject to their own security policies.

There aren’t any published security advisories