
Authorized social-engineering simulation framework with an isolated loopback lab, synthetic audience generation, pre-flight authorization checks, and offline HTML/Markdown/JSON/CSV reporting.
Severitas is an authorized social-engineering awareness and simulation framework. It is structurally constrained to run exclusively inside isolated laboratory environments against synthetic identities.
Severitas isolates assessment execution logically so that security evaluation doesn't compromise corporate infrastructure or real data.
The codebase separates authorization policy layers from business execution loops:
severitas/
├── src/
│ └── severitas/
│ ├── core/ # Container bootstrapping, configuration, and logging
│ ├── scope/ # Target match gates (Domain, Email, Network ranges)
│ ├── authorization/ # Pre-execution pipeline validation
│ ├── infrastructure/ # Mock DNS, Mail, Web, and Tracking handlers
│ ├── scenarios/ # Phishing, OSINT, QR, Pretexting scenario plugins
│ ├── telemetry/ # Synchronous ordered event bus and analytics engine
│ └── security/ # Structural redaction filters and leak sentinels
Unlike advisory tools, Severitas guarantees compliance metrics structurally:
severitas.scope): Campaigns fail closed unless targets map perfectly to designated synthetic test definitions (*.local, *.test, *.invalid).severitas.security.guards): The submission path counts field names but drops variables entirely before records transition or telemetry is captured.Clone this repository layout and compile your development link in an isolated container instance or local virtualenv:
# Initialize development profile
python3 -m venv .venv
source .venv/bin/activate
# Install in editable mode
pip install -e .
Severitas includes quick terminal utilities to provision lab templates immediately:
# Launch the interactive menu wizard
severitas --menu
# Start the internal mock services bundle
severitas lab start
# Scope out target definitions for synthetic verification checks
severitas scope create --name alpha --domain training.local --email [email protected]
# Run an end-to-end sandbox execution demo to generate mock results
severitas lab demo --targets 25
When compiling analytics output folders, the offline reporting system measures user awareness cohorts using inline charts similar to this format:
Targets simulated ████████████████████████████████████████ 25
Messages simulated ████████████████████████████████████████ 25
Interactions ██████████████████████████ 18
Clicks / visits ████████████████████ 15
Synthetic submissions ██████████████ 9
User reports ████████ 5
This framework is built strictly for authorized educational simulations, infrastructure tracking benchmarks, and training validation exercises. Testing against public hosts or real user populations without explicit Rules of Engagement (ROE) and documented approval is highly prohibited. The code is shipped under the terms of the MIT License.