v4.2.4: full Kali sandbox orchestration for recon

Spin Kali up for the engagement, run tool-recon in it, let the LLM refine on top,
tear it down after.

- kali_provision_recon_tools(): installs the recon toolbox (subfinder/httpx/
  katana/gau/waybackurls/nuclei/naabu/dnsx/assetfinder/gf/qsreplace/anew via
  go install + apt) in the Kali sandbox on demand, idempotent, once per run.
- kali_tool_recon(): deterministic tool-recon phase — gau/waybackurls/katana URL
  harvest + targeted nuclei (exposures/misconfig/takeovers, high-signal only) +
  gf-flagged candidate URLs by class — over the live hosts, then folded into the
  recon context so the LLM works on top of the tool output and confirms each.
  Runs in the sandbox (--sandbox) or on host tools via recon_tool().
- Engine autostart: if the container engine is installed but not running, start
  it automatically (colima start / open -a Docker / systemctl start docker /
  podman machine start) and poll until up — a --sandbox run no longer fails just
  because the daemon wasn't started. Clear guidance if it can't be started.
- Teardown: the Kali container is removed at the end of the run (override with
  NEUROSPLOIT_KEEP_SANDBOX=1).

Version 4.2.4 across CLI/clap/web/README/TUTORIAL. 423 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 08:01:29 -03:00
1 parent c258299eb6
commit 94404555aa
9 files changed
+190 -16

No files matched your search

+3 -3
View File
@@ -1,4 +1,4 @@
<h1 align="center">🧠 NeuroSploit v4.2.3</h1>
<h1 align="center">🧠 NeuroSploit v4.2.4</h1>
<p align="center">
<a href="https://github.com/JoasASantos/NeuroSploit/stargazers"><img src="https://img.shields.io/github/stars/JoasASantos/NeuroSploit?style=for-the-badge&logo=github&color=8b5cf6" alt="Stars"></a>
@@ -8,7 +8,7 @@
</p>
<p align="center">
<img src="https://img.shields.io/badge/Version-4.2.3-blue?style=flat-square">
<img src="https://img.shields.io/badge/Version-4.2.4-blue?style=flat-square">
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
<img src="https://img.shields.io/badge/MD%20Agents-479-red?style=flat-square">
@@ -52,7 +52,7 @@ Control TUI**.
### Highlights
> **New in v4.2.3** — **free, LLM-directed exploration**: an exploit agent's named
> **New in v4.2.4** — **free, LLM-directed exploration**: an exploit agent's named
> class is a starting point, not a cage — it maps what the app actually does and
> reports any class it can prove, with **authentication / identity** (login, signup,
> password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and