docs(tutorial): add 6.2 'Get the most out of a run' — recommended potent setup

A copy-paste recipe (cross-model jury, /ua browser, /recon 4, scope-file +
authorization, natural-language focus on the high-value surface, /run) plus a
table of high-value knobs and an honest benchmark reality-check, so people run
NeuroSploit more effectively against real targets.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 01:00:09 -03:00
1 parent 0446bc4b5d
commit c2c6de1c3f
1 file changed
+54
+54
View File
@@ -21,6 +21,8 @@ the autonomous, multi-model penetration-testing harness.
- [Grey-box (code + live app)](#53-grey-box-code--live-app)
- [Host / Infra (Linux / Windows / AD)](#54-host--infra-linux--windows--ad)
6. [The interactive REPL](#6-the-interactive-repl)
- [Scope — three ways](#61-scope--three-ways-from-quick-to-a-full-config)
- [Get the most out of a run](#62-get-the-most-out-of-a-run-recommended-potent-setup)
7. [Mission Control TUI](#7-mission-control-tui)
8. [Web console](#8-web-console)
9. [Credentials (`creds.yaml`)](#9-credentials-credsyaml)
@@ -500,6 +502,58 @@ neurosploit run "*.client.com" --scope-file examples/scopes/engagement.example.y
> `NEUROSPLOIT_CAPABILITY_KEY`) is a separate, *optional* layer for when a lead
> must hand a tester a scope they cannot widen. Everyday engagements don't need it.
### 6.2 Get the most out of a run (recommended potent setup)
A black-box run against a real, hardened target (behind a WAF/CDN) is only as
good as how you set it up. This is the recipe that gives the strongest,
most-reproducible results — paste it into the REPL before `/run`:
```
# 1) A cross-model jury — the finder AND independent validators. The single
# biggest quality lever: one model validating its own findings is weak.
/model anthropic:claude-opus-5-5, openai:gpt-6-astra
# (one model is fine too; two+ enables real cross-validation and voting)
# 2) A realistic browser User-Agent — a self-declaring scanner UA gets
# blocked/challenged by a WAF/CDN and causes FALSE NEGATIVES. Attribution
# stays in the X-NeuroSploit-Scan header.
/ua browser
# 3) Deep recon — more rounds, active enumeration, subdomain discovery inside
# the wildcard scope (1 quick · 2 standard · 3 deep · 4 exhaustive).
/recon 4
# 4) Scope + authorization in one step (see §6.1). For a program, record it:
/scope-file examples/scopes/engagement.example.yaml
/authorization https://hackerone.com/<program> # context only, never widens scope
# 5) Point the hunt — in ANY language. Steers the LLM to the high-value surface
# (it is NOT boxed in one vuln class; this focuses WHERE it spends effort).
focus on auth, OAuth/OIDC, IDOR/BOLA and business logic on the less-hardened subdomains
# 6) Go — runs in the background; watch it with /status, /logs, /finding.
/run
```
Other high-value knobs:
| Command | When to use |
|---------|-------------|
| `/class idor,sqli,ssrf,auth` | Force a run onto specific vuln classes (pins the matching agents). |
| `/chain 3` | More post-exploitation chaining rounds (pivot a foothold into deeper impact). |
| `/votes 2` | Require 2 models to agree before a finding is **confirmed** (fewer false positives; needs ≥2 models). |
| `/proxy http://127.0.0.1:8080` | Route all traffic through Burp/ZAP to inspect & replay. |
| `/creds creds.yaml` | Authenticated testing — the authenticated surface is where the high-impact bugs live. |
| `/research` | Whitebox/greybox: hunt a **novel, CVE-reportable** bug (dedup + patch-diff). |
| `/quick` | The opposite — a fast, cheap, low-token pass. |
> **Reality check.** A mature external surface (a big publisher behind Cloudflare)
> mostly yields hygiene/info-disclosure findings on black-box — that's the target
> being hardened, not a tool failure. The high/critical bugs live on the
> **authenticated** surface and **less-hardened subdomains**; point recon and your
> focus there. For a *measurable* benchmark, run against a seeded lab (OWASP Juice
> Shop, crAPI, VAmPI) where "found X of Y known bugs" is countable.
---
## 7. Mission Control TUI