Prevot reproduces public, known firmware vulnerabilities deterministically against digital twins, and issues a receipt: a signed attestation that anyone can re-verify — without trusting us, without seeing the exploit.
Evidence, not assertion.The security community is drowning in AI-generated reports thatclaimvulnerabilities without proving them. A Prevot receipt is the opposite: a cryptographic proof, re-verifiable by third parties, that the reproduction actually happened.
This repo ships a real receipt — CVE-2018-19988, root command injection on the D-Link DIR-868L rev B router — signed and anchored in the public transparency log Rekor (logIndex 2237342620).
You only need Docker:
cd receipts/examples/dir868l-hnap-19988
docker run --rm -v "$PWD:/w" -w /w \
gcr.io/projectsigstore/cosign:v2.4.1@sha256:b03690aa52bfe94054187142fba24dc54137650682810633901767d8a3e15b31 \
verify-blob --new-bundle-format --bundle statement.cosign.bundle \
--certificate-identity 616124453047-compute@developer.gserviceaccount.com \
--certificate-oidc-issuer https://accounts.google.com \
statement.json
Step-by-step, including the tamper test: guides/verify-a-receipt-in-5-min.md.
It also states what it does not know:
Medium grade, declared. It reproduces deterministically (2/2)and discriminates the injection (we proved the effect is caused by the payload, not by the request). It lacks the patched-version control — that firmware is encrypted — so we donot call it high grade.It corrects a public data point. The CVE is published as exploitablewithout credentials(PR:N
); on the real firmware it requires authentication. We declare itPR:L
. Reproduction against the real artifact overrides the metadata.
A verifier that cannot tell its own grades of certainty apart is not a verifier.
| Piece | What it is |
|---|---|
receipts/schema/ |
|
the receipt schema (in-toto attestation, evidence by sha256 ) |
|
receipts/examples/dir868l-hnap-19988/ |
|
| the signed receipt + its evidence | |
receipts/README.md |
|
| anatomy of the receipt | |
receipts/validate_receipt.py |
|
| optional schema + content-addressing check | |
guides/ |
|
| the 5-minute verification guide |
Signing is keyless (Sigstore/cosign): a short-lived certificate (Fulcio) bound to an identity, anchored in Rekor. No private keys to manage. The bundle is self-contained: it verifies with just this repo and Docker — no access to Prevot's infrastructure.
On the signer.This receipt is signed by amachine identity(the service account that runs the verifier), not a person — honest, since the receipt is produced by automation. A canonical human signature can be added later; Rekor allows multiple signatures over the same receipt.
AGPL-3.0-or-later. (See LICENSE
.)
Signal S1 — first public proof. This is a first brick of a cyber-physical trust seal for firmware under the European regulatory framework (CRA/RED).