docs: add a broad focus example (TUTORIAL 6.2 + engagement.example.yaml)

A copy-paste full-surface focus string (all web classes, prioritise authed
surface + subdomains, chain to impact, reproducible receipt) and an
objective-vs-focus note; the engagement template now carries the broad
focus/objective in its one-file config.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 07:43:45 -03:00
1 parent 101eca2700
commit 88255152fe
2 files changed
+26

No files matched your search

+14
View File
@@ -535,6 +535,20 @@ focus on auth, OAuth/OIDC, IDOR/BOLA and business logic on the less-hardened sub
/run /run
``` ```
**A broad focus to cover the whole surface** (paste as `/focus …`, or just type
it — any language). Use this when you want maximum breadth rather than a narrow
hunt; it complements the default OWASP/ASVS/CWE objective:
```
/focus Cover the full web attack surface and prove impact: map every route/endpoint/parameter from the app and its JS bundles, then test each applicable class — injection (SQL/NoSQL/command/SSTI/LDAP/XPath), XSS (reflected/stored/DOM), access control (IDOR/BOLA/BFLA/privesc/forced browsing), authentication & session (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT alg/kid/jku), SSRF, XXE, insecure deserialization, CSRF, open redirect, CORS, file upload/download & path traversal, business-logic & multi-step flow abuse, mass assignment, request smuggling, info disclosure & security misconfiguration, cryptographic failures, and known-CVE components. Prioritise the authenticated surface and less-hardened subdomains, chain footholds into higher impact, and confirm every finding with a reproducible request/response receipt.
```
> **objective vs focus.** The *objective* (set by default, OWASP/ASVS/CWE) is the
> framing — *why* the test runs and what counts as impact. The *focus* steers
> *where* effort goes. Neither boxes the run into one class — the agents still
> report any class they can prove; these just prioritise. To deliberately narrow
> to specific classes, use `/class idor,ssrf,auth`.
Other high-value knobs: Other high-value knobs:
| Command | When to use | | Command | When to use |
+12
View File
@@ -54,3 +54,15 @@ soft:
notes: notes:
- "Authorized under <SOW / contract reference>; owner contact: <email/phone>." - "Authorized under <SOW / contract reference>; owner contact: <email/phone>."
- "Test window: <when>. Notify <contact> before any high-impact test." - "Test window: <when>. Notify <contact> before any high-impact test."
# --- Optional: define the rest of the engagement in this one file -----------
# These top-level keys are read by `/scope-file` (the CLI --scope-file reads only
# the scope). All optional. A wildcard target is seeded from its apex.
target: "*.client.example"
# models:
# - anthropic:claude-opus-5-5
# - openai:gpt-6-astra
# classes: idor, sqli, xss, ssrf, auth # pin specific vuln classes (optional)
objective: "Comprehensive black-box web application penetration test following OWASP Top 10 (2021), OWASP ASVS, the OWASP WSTG and CWE."
focus: "Cover the full web attack surface and prove impact: map every route/endpoint/parameter from the app and its JS bundles, then test each applicable class — injection (SQL/NoSQL/command/SSTI/LDAP/XPath), XSS (reflected/stored/DOM), access control (IDOR/BOLA/BFLA/privesc/forced browsing), authentication & session (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT alg/kid/jku), SSRF, XXE, insecure deserialization, CSRF, open redirect, CORS, file upload/download & path traversal, business-logic & multi-step flow abuse, mass assignment, request smuggling, info disclosure & security misconfiguration, cryptographic failures, and known-CVE components. Prioritise the authenticated surface and less-hardened subdomains, chain footholds into higher impact, and confirm every finding with a reproducible request/response receipt."
authorization: "<SOW / contract reference, or a program URL>"