v4.2.4: full Kali sandbox orchestration for recon

Spin Kali up for the engagement, run tool-recon in it, let the LLM refine on top,
tear it down after.

- kali_provision_recon_tools(): installs the recon toolbox (subfinder/httpx/
  katana/gau/waybackurls/nuclei/naabu/dnsx/assetfinder/gf/qsreplace/anew via
  go install + apt) in the Kali sandbox on demand, idempotent, once per run.
- kali_tool_recon(): deterministic tool-recon phase — gau/waybackurls/katana URL
  harvest + targeted nuclei (exposures/misconfig/takeovers, high-signal only) +
  gf-flagged candidate URLs by class — over the live hosts, then folded into the
  recon context so the LLM works on top of the tool output and confirms each.
  Runs in the sandbox (--sandbox) or on host tools via recon_tool().
- Engine autostart: if the container engine is installed but not running, start
  it automatically (colima start / open -a Docker / systemctl start docker /
  podman machine start) and poll until up — a --sandbox run no longer fails just
  because the daemon wasn't started. Clear guidance if it can't be started.
- Teardown: the Kali container is removed at the end of the run (override with
  NEUROSPLOIT_KEEP_SANDBOX=1).

Version 4.2.4 across CLI/clap/web/README/TUTORIAL. 423 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 08:01:29 -03:00
1 parent c258299eb6
commit 94404555aa
9 files changed
+190 -16

No files matched your search

+2 -2
View File
@@ -3,7 +3,7 @@
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>NeuroSploit v4.2.3 — Console</title>
<title>NeuroSploit v4.2.4 — Console</title>
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 100 100%22><text y=%22.9em%22 font-size=%2290%22>🧠</text></svg>">
<link rel="stylesheet" href="/vendor/xterm.css" />
<link rel="stylesheet" href="/style.css" />
@@ -33,7 +33,7 @@
<div class="sb-groups" id="sbGroups"><!-- populated by app.js --></div>
<div class="sb-bottom">
<span class="sb-version" id="sbVersion">v4.2.3</span>
<span class="sb-version" id="sbVersion">v4.2.4</span>
<div class="sb-bottom-actions">
<button class="icon-btn" id="btnOpenAuth" title="Auth &amp; API keys">🔑</button>
<button class="icon-btn" id="btnOpenRepl" title="Open terminal (Ctrl+`)">❭_</button>
+3 -3
View File
@@ -1,7 +1,7 @@
#!/usr/bin/env node
'use strict';
/**
* NeuroSploit v4.2.3 — web console backend.
* NeuroSploit v4.2.4 — web console backend.
*
* Zero-dependency Node HTTP server that:
* - serves the static SPA in ./public
@@ -1487,7 +1487,7 @@ const server = http.createServer(async (req, res) => {
}
if (req.method === 'GET' && p === '/api/meta') {
return sendJson(res, 200, { version: "4.2.3", binary: BIN, root: ROOT });
return sendJson(res, 200, { version: "4.2.4", binary: BIN, root: ROOT });
}
// ---- providers / API keys (in-memory only, never persisted) ----
@@ -1521,7 +1521,7 @@ const server = http.createServer(async (req, res) => {
loadPersistedJobs();
server.listen(PORT, () => {
console.log(`NeuroSploit v4.2.3 web console → http://localhost:${PORT}`);
console.log(`NeuroSploit v4.2.4 web console → http://localhost:${PORT}`);
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
console.log(` agents : ${AGENTS_DIR}`);
console.log(` runs : ${RUNS_DIR}`);