Skip to content

Operator guides

Use these guides after reviewing the platform architecture. They follow the work in order: place AIT explicitly, establish an inert baseline, operate one bounded exchange, compare a close control, read evidence, and leave the target clean.

Use the guide that matches the moment

Before target contact Map the sender, receiver, protocol, routing change, safe mutation, proof source, and cleanup. Plan a real engagement
At the interception screen Recognize direction, correlation, parse state, pending decisions, and the structured diff. Open the interception field guide
While operating Manage listeners, queues, edits, batch order, shadow endpoints, and shutdown. Open the Cockpit guide
At evidence handoff Separate delivery from processing and effect; export only what the result can support. Open the evidence guide

Core operating set

Guide Use it for
How the tool works understand direct interception, peer tools, and data flow
Direct interception configure and run a listener or wrapper
Interception field guide read every operator-facing field and decision
Local control plane manage the broader local workspace
Operator Cockpit operate the one-screen browser workflow
Reading evidence scope delivery, receiver, behavior, and effect claims
Real engagements plan placement, safety, validation, and cleanup
Troubleshooting diagnose routing, listener, parse, queue, correlation, and shutdown faults

Framework-shaped communication

Framework adapters change where messages are emitted and how lifecycle state is represented; they do not remove the need to identify the protocol boundary and proof source.

Advanced peer tools

Use ait advanced when the direct workflow is insufficient:

  • Seam decodes and rewrites advanced in-path traffic.
  • meshmapper turns discovered communication into trust-path hypotheses.
  • Assay runs external-oracle cases and statistical validation.

They are optional components, not prerequisites for interception. All supported placements are explicit. AIT is not a transparent TLS interception tool.