Cupelix Assay

Status: Early, usable. Version 0.1.0, usermode only. Apache-2.0. No public repository yet.

What does this machine actually disclose?

What it is

Cupelix Assay is a standalone auditor that answers exactly one question. Snapshot the
machine, change something, snapshot again, diff the two. It works against any
spoofing tool, including ones with nothing to do with Cupelix.

Why it is separate from the thing it audits

This is the whole pitch. A spoofing suite’s own verifier checks the rows that suite
implements. That is useful, and it is structurally blind: it cannot report a leak nobody wrote
a row for.

Assay enumerates surfaces that exist and reports what each one discloses, with no
opinion about who was supposed to cover it. Auditing our own work with our own tool would
prove less than nothing, so Assay is built not to know whose output it is looking at.

The design rules

  • It never guesses. A surface it cannot read reports UNREADABLE,
    with the reason.
  • A missing component is not a clean result. A kernel-only surface without
    the optional helper driver reports NEEDS-DRIVER, which is explicitly not
    “clean”.
  • Unchanged is not automatically a failure. An unchanged value has three
    possible causes and the tool does not know which was intended, so it does not pretend to.
  • Every knowledge-base entry is a measurement, with a date and an
    observation behind it.

Coverage today

Version 0.1.0 is usermode only. It covers firmware (SMBIOS), storage, network, registry and
PnP container surfaces. Bluetooth and one kernel surface are reported honestly as not yet
read, rather than omitted from the output.