mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-04 06:56:56 +02:00
feat(agents): deep Active Directory suite — 25 host/infra skills + 7 AD chains
Adds robust AD pentest coverage spanning the full kill chain (initial access → enumeration → exploitation → lateral movement → privilege escalation → persistence → pivoting), with concrete tooling, per-technique decision points, benign-proof-only guidance, lockout/state awareness, and chaining hooks. All GENERIC — no lab-specific hosts/IPs/creds/flags; works in any AD environment. New infra/ skills: ad_recon_enum, ad_bloodhound_paths, ad_llmnr_poisoning, ad_ntlm_relay, ad_password_spray, ad_kerberos_delegation, ad_adcs_esc, ad_pth_ptt, ad_coerce_auth, ad_critical_cve (Zerologon/noPac), ad_smb_share_hunt, ad_laps_gmsa_read, ad_gpo_abuse, ad_dpapi_looting, ad_trust_abuse, ad_persistence_review, ad_mssql_abuse. Enriched: ad_kerberoasting, ad_asreproasting, ad_dcsync, ad_acl_privesc, ad_default_creds, windows_priv_esc. New chains/: chain_ad_web_to_forest_root, chain_ad_rbcd_s4u_to_adcs, chain_ad_coerce_relay_adcs, chain_ad_kerberoast_to_domain, chain_ad_mssql_linked_pivot, chain_ad_trust_cross_forest, chain_ad_local_to_domain. attack_graph: map CWE-294/295/1392/269 to OWASP/MITRE/stage + CVSS bands so AD findings grade and place in the kill chain correctly. 473 agents, 421 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
8051464a84
commit
7741290193
32 files changed
+1479
-86
No files matched your search
@@ -11,7 +11,7 @@
|
||||
<img src="https://img.shields.io/badge/Version-4.2.1-blue?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/MD%20Agents-458-red?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/MD%20Agents-473-red?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/Models-19%20providers-success?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/Modes-Black%20%7C%20White%20%7C%20Grey%20%7C%20Host%20%7C%20AI%20%7C%20Mobile%20%7C%20Container-9cf?style=flat-square">
|
||||
<img src="https://img.shields.io/badge/Auth-API%20key%20%7C%20Subscription-orange?style=flat-square">
|
||||
@@ -32,7 +32,7 @@ LLMs** — via **API key** or local **subscription** (Claude Code / Codex / Gemi
|
||||
Grok) — recons the target, **intelligently selects only the agents that match the
|
||||
discovered surface**, runs them in parallel, **chains** findings into deeper
|
||||
impact, and **validates every claim by cross-model voting + tool-receipt
|
||||
grounding** before reporting. It ships **435 markdown agents** and a **Mission
|
||||
grounding** before reporting. It ships **473 markdown agents** and a **Mission
|
||||
Control TUI**.
|
||||
|
||||
### Engagement modes
|
||||
@@ -60,6 +60,8 @@ Control TUI**.
|
||||
> every object identifier it sees (ids, UUIDs, tokens, emails) into a reference
|
||||
> pool and substitutes them across identities and endpoints, the core of
|
||||
> reliable BOLA / IDOR / mass-assignment discovery.
|
||||
>
|
||||
> Also a deep **Active Directory** suite: 25+ host/infra skills and 7 multi-stage AD chains covering the full kill chain — initial access, enumeration (BloodHound), Kerberoasting/AS-REP, NTLM relay + coercion (PetitPotam/PrinterBug), delegation abuse (unconstrained/constrained/RBCD + S4U), AD CS (ESC1-ESC13), MSSQL linked-server pivoting, DCSync, cross-forest trust abuse (SID history/trust keys), and persistence (detect-and-report). Lockout- and state-aware, benign-proof-only.
|
||||
|
||||
> **New in v4.2.0** — **binary / APK / IPA testing**: a new `mobile` mode analyses
|
||||
> a local artifact with 12 reverse-engineering skills (static binary triage,
|
||||
@@ -85,7 +87,7 @@ Control TUI**.
|
||||
> (`--compliance pci-dss,hipaa,soc2`); an **internal-network / AD attack graph**;
|
||||
> a **reasoning-budget governor** (`--budget`); and **TypeSafe System One**
|
||||
> (`--typesafe on|off|auto`) as a calibrated confirmation + adjudication layer.
|
||||
> 27 deterministic per-CWE validators, 446 agents.
|
||||
> 27 deterministic per-CWE validators, 473 agents.
|
||||
|
||||
- 🧠 **POMDP belief + anti-hallucination gate** — findings aren't booleans; a
|
||||
property-graph belief carries probabilities, and `may_assert` refuses to claim
|
||||
@@ -238,7 +240,7 @@ Zero npm dependencies (Node built-ins only).
|
||||
out-of-scope) → Leads (the 435-agent board below) → Model & Run (provider/model picker,
|
||||
API-key vs. subscription toggle, votes/chain-depth/recon) → Review. Every engagement is named
|
||||
up front, so runs are identifiable in history instead of by raw target string.
|
||||
- **Lead board** — all 435 agents auto-categorized (Business Logic, Broken Access Control,
|
||||
- **Lead board** — all 473 agents auto-categorized (Business Logic, Broken Access Control,
|
||||
Injection, LLM Application, Auth & Session, SSRF & Network, Cloud & Infra, …). Toggle a single
|
||||
lead, a whole category (indeterminate when partially selected), or use **Select all / Clear
|
||||
all** — respects the active search filter. Leave everything off to let the harness's own
|
||||
@@ -980,7 +982,7 @@ Every run writes a self-contained folder `runs/ns-<ts>-<target>/`:
|
||||
A reinforcement-learning reward store (`data/rl_state_rs.json`) biases agent
|
||||
selection on future runs.
|
||||
|
||||
## Agent library — `agents_md/` (446)
|
||||
## Agent library — `agents_md/` (473)
|
||||
|
||||
| Category | Count | Purpose |
|
||||
|----------|-------|---------|
|
||||
|
||||
Reference in new issue
Block a user