mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-09 01:22:33 +02:00
v4.2.4: full Kali sandbox orchestration for recon
Spin Kali up for the engagement, run tool-recon in it, let the LLM refine on top, tear it down after. - kali_provision_recon_tools(): installs the recon toolbox (subfinder/httpx/ katana/gau/waybackurls/nuclei/naabu/dnsx/assetfinder/gf/qsreplace/anew via go install + apt) in the Kali sandbox on demand, idempotent, once per run. - kali_tool_recon(): deterministic tool-recon phase — gau/waybackurls/katana URL harvest + targeted nuclei (exposures/misconfig/takeovers, high-signal only) + gf-flagged candidate URLs by class — over the live hosts, then folded into the recon context so the LLM works on top of the tool output and confirms each. Runs in the sandbox (--sandbox) or on host tools via recon_tool(). - Engine autostart: if the container engine is installed but not running, start it automatically (colima start / open -a Docker / systemctl start docker / podman machine start) and poll until up — a --sandbox run no longer fails just because the daemon wasn't started. Clear guidance if it can't be started. - Teardown: the Kali container is removed at the end of the run (override with NEUROSPLOIT_KEEP_SANDBOX=1). Version 4.2.4 across CLI/clap/web/README/TUTORIAL. 423 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
c258299eb6
commit
94404555aa
9 files changed
+190
-16
No files matched your search
+3
-3
@@ -1,7 +1,7 @@
|
||||
#!/usr/bin/env node
|
||||
'use strict';
|
||||
/**
|
||||
* NeuroSploit v4.2.3 — web console backend.
|
||||
* NeuroSploit v4.2.4 — web console backend.
|
||||
*
|
||||
* Zero-dependency Node HTTP server that:
|
||||
* - serves the static SPA in ./public
|
||||
@@ -1487,7 +1487,7 @@ const server = http.createServer(async (req, res) => {
|
||||
}
|
||||
|
||||
if (req.method === 'GET' && p === '/api/meta') {
|
||||
return sendJson(res, 200, { version: "4.2.3", binary: BIN, root: ROOT });
|
||||
return sendJson(res, 200, { version: "4.2.4", binary: BIN, root: ROOT });
|
||||
}
|
||||
|
||||
// ---- providers / API keys (in-memory only, never persisted) ----
|
||||
@@ -1521,7 +1521,7 @@ const server = http.createServer(async (req, res) => {
|
||||
loadPersistedJobs();
|
||||
|
||||
server.listen(PORT, () => {
|
||||
console.log(`NeuroSploit v4.2.3 web console → http://localhost:${PORT}`);
|
||||
console.log(`NeuroSploit v4.2.4 web console → http://localhost:${PORT}`);
|
||||
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
|
||||
console.log(` agents : ${AGENTS_DIR}`);
|
||||
console.log(` runs : ${RUNS_DIR}`);
|
||||
|
||||
Reference in new issue
Block a user