mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-06 07:57:08 +02:00
docs: add a broad focus example (TUTORIAL 6.2 + engagement.example.yaml)
A copy-paste full-surface focus string (all web classes, prioritise authed surface + subdomains, chain to impact, reproducible receipt) and an objective-vs-focus note; the engagement template now carries the broad focus/objective in its one-file config. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
101eca2700
commit
88255152fe
2 files changed
+26
No files matched your search
+14
@@ -535,6 +535,20 @@ focus on auth, OAuth/OIDC, IDOR/BOLA and business logic on the less-hardened sub
|
|||||||
/run
|
/run
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**A broad focus to cover the whole surface** (paste as `/focus …`, or just type
|
||||||
|
it — any language). Use this when you want maximum breadth rather than a narrow
|
||||||
|
hunt; it complements the default OWASP/ASVS/CWE objective:
|
||||||
|
|
||||||
|
```
|
||||||
|
/focus Cover the full web attack surface and prove impact: map every route/endpoint/parameter from the app and its JS bundles, then test each applicable class — injection (SQL/NoSQL/command/SSTI/LDAP/XPath), XSS (reflected/stored/DOM), access control (IDOR/BOLA/BFLA/privesc/forced browsing), authentication & session (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT alg/kid/jku), SSRF, XXE, insecure deserialization, CSRF, open redirect, CORS, file upload/download & path traversal, business-logic & multi-step flow abuse, mass assignment, request smuggling, info disclosure & security misconfiguration, cryptographic failures, and known-CVE components. Prioritise the authenticated surface and less-hardened subdomains, chain footholds into higher impact, and confirm every finding with a reproducible request/response receipt.
|
||||||
|
```
|
||||||
|
|
||||||
|
> **objective vs focus.** The *objective* (set by default, OWASP/ASVS/CWE) is the
|
||||||
|
> framing — *why* the test runs and what counts as impact. The *focus* steers
|
||||||
|
> *where* effort goes. Neither boxes the run into one class — the agents still
|
||||||
|
> report any class they can prove; these just prioritise. To deliberately narrow
|
||||||
|
> to specific classes, use `/class idor,ssrf,auth`.
|
||||||
|
|
||||||
Other high-value knobs:
|
Other high-value knobs:
|
||||||
|
|
||||||
| Command | When to use |
|
| Command | When to use |
|
||||||
|
|||||||
@@ -54,3 +54,15 @@ soft:
|
|||||||
notes:
|
notes:
|
||||||
- "Authorized under <SOW / contract reference>; owner contact: <email/phone>."
|
- "Authorized under <SOW / contract reference>; owner contact: <email/phone>."
|
||||||
- "Test window: <when>. Notify <contact> before any high-impact test."
|
- "Test window: <when>. Notify <contact> before any high-impact test."
|
||||||
|
|
||||||
|
# --- Optional: define the rest of the engagement in this one file -----------
|
||||||
|
# These top-level keys are read by `/scope-file` (the CLI --scope-file reads only
|
||||||
|
# the scope). All optional. A wildcard target is seeded from its apex.
|
||||||
|
target: "*.client.example"
|
||||||
|
# models:
|
||||||
|
# - anthropic:claude-opus-5-5
|
||||||
|
# - openai:gpt-6-astra
|
||||||
|
# classes: idor, sqli, xss, ssrf, auth # pin specific vuln classes (optional)
|
||||||
|
objective: "Comprehensive black-box web application penetration test following OWASP Top 10 (2021), OWASP ASVS, the OWASP WSTG and CWE."
|
||||||
|
focus: "Cover the full web attack surface and prove impact: map every route/endpoint/parameter from the app and its JS bundles, then test each applicable class — injection (SQL/NoSQL/command/SSTI/LDAP/XPath), XSS (reflected/stored/DOM), access control (IDOR/BOLA/BFLA/privesc/forced browsing), authentication & session (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT alg/kid/jku), SSRF, XXE, insecure deserialization, CSRF, open redirect, CORS, file upload/download & path traversal, business-logic & multi-step flow abuse, mass assignment, request smuggling, info disclosure & security misconfiguration, cryptographic failures, and known-CVE components. Prioritise the authenticated surface and less-hardened subdomains, chain footholds into higher impact, and confirm every finding with a reproducible request/response receipt."
|
||||||
|
authorization: "<SOW / contract reference, or a program URL>"
|
||||||
Reference in new issue
Block a user