record_observation
Record observations not in terminal output—credentials, hypotheses, notes, or corrections—using typed kinds to enrich penetration testing engagement data.
Instructions
Record something the operator saw or concluded that is not in captured terminal output -- a note, a hypothesis, a credential seen inside a GUI, or a correction. kind is one of host, domain, service, identity, credential, auth_attempt, share, artifact, web_endpoint, observation, relationship, note, task, finding_candidate, or correction. Use kind='correction' with data={"separate": ["", ""]} to assert that two identity keys are NOT the same thing; the entities separate on the next rebuild. All writes are attributed to the operator or agent, never to extraction.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | Yes | ||
| kind | Yes | ||
| fact_type | No | ||
| engagement | No | Engagement name; defaults to the bound one. | |
| segment_ids | No |