mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 23:47:19 +02:00
docs: add a broad focus example (TUTORIAL 6.2 + engagement.example.yaml)
A copy-paste full-surface focus string (all web classes, prioritise authed surface + subdomains, chain to impact, reproducible receipt) and an objective-vs-focus note; the engagement template now carries the broad focus/objective in its one-file config. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
101eca2700
commit
88255152fe
2 files changed
+26
No files matched your search
@@ -54,3 +54,15 @@ soft:
|
||||
notes:
|
||||
- "Authorized under <SOW / contract reference>; owner contact: <email/phone>."
|
||||
- "Test window: <when>. Notify <contact> before any high-impact test."
|
||||
|
||||
# --- Optional: define the rest of the engagement in this one file -----------
|
||||
# These top-level keys are read by `/scope-file` (the CLI --scope-file reads only
|
||||
# the scope). All optional. A wildcard target is seeded from its apex.
|
||||
target: "*.client.example"
|
||||
# models:
|
||||
# - anthropic:claude-opus-5-5
|
||||
# - openai:gpt-6-astra
|
||||
# classes: idor, sqli, xss, ssrf, auth # pin specific vuln classes (optional)
|
||||
objective: "Comprehensive black-box web application penetration test following OWASP Top 10 (2021), OWASP ASVS, the OWASP WSTG and CWE."
|
||||
focus: "Cover the full web attack surface and prove impact: map every route/endpoint/parameter from the app and its JS bundles, then test each applicable class — injection (SQL/NoSQL/command/SSTI/LDAP/XPath), XSS (reflected/stored/DOM), access control (IDOR/BOLA/BFLA/privesc/forced browsing), authentication & session (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT alg/kid/jku), SSRF, XXE, insecure deserialization, CSRF, open redirect, CORS, file upload/download & path traversal, business-logic & multi-step flow abuse, mass assignment, request smuggling, info disclosure & security misconfiguration, cryptographic failures, and known-CVE components. Prioritise the authenticated surface and less-hardened subdomains, chain footholds into higher impact, and confirm every finding with a reproducible request/response receipt."
|
||||
authorization: "<SOW / contract reference, or a program URL>"
|
||||
Reference in new issue
Block a user