[Feature Request] Add domain exemption or context awareness for legitimate security engineering workflows
Bug Description
False positive on legitimate security engineering work.
Domain: I build Cirrus Erase, a certified secure data sanitisation product for the ITAD industry — IT asset disposal. It is undergoing ADISA Product Assurance certification and implements IEEE 2883-2022 and NIST SP 800-88 Rev.2.
The work necessarily involves language and commands that a classifier could reasonably misread as malicious:
- ATA SECURITY ERASE UNIT, SECURITY SET PASSWORD, SECURITY DISABLE
- NVMe Sanitize (block erase, crypto erase), Format NVM
- HPA / DCO / AMAX detection and removal — deliberately un-hiding concealed drive capacity
- TCG Opal PSID revert
- Destroying encryption keys, overwriting full drive surfaces, defeating firmware that lies about erasure
All of this is the legitimate and certified purpose of the product: proving that data on decommissioned drives has been destroyed, to an auditable standard, so equipment can be resold or recycled safely.
Impact: sessions are long, technical and stateful. Being switched mid-session interrupts work that depends on accumulated context, and it happens repeatedly.
Request: consider that "erase", "destroy", "hidden space", "bypass the freeze lock" and similar are the normal vocabulary of certified data sanitisation, not of attack tooling.
Intelligent Lifecycle Solutions and its subsidiary Intelligent Storage Solutions have been undertaking secure erasure services for major corporations and government for 20 years. Refer to www.lifecyclesolutions.net for more information or contact me.
Environment Info
- Platform: darwin
- Terminal: iTerm.app
- Version: 2.1.226
- Feedback ID: f2f18dc2-371f-4521-9c69-0ed0cac95166
Errors
[]