docs: document web console in README/TUTORIAL, note REPL-backed run

- README: web console section notes the wizard now scripts a real REPL
  session for run/whitebox/greybey so mid-run prompts work
- TUTORIAL.md: new §8 Web console (wizard steps, REPL script, live view,
  links to web/API.md and web/README.md); renumbered §9-17 and §9.1-9.5
- web/README.md: bullet on the REPL-backed run + send-prompt box

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0166e1EFP2JrifYsj5bVugut
This commit is contained in:
CyberSecurityUP
2026-08-24 11:43:20 -03:00
co-authored by Claude Sonnet 5
parent 4fbe608a7a
commit ec53880298
3 changed files with 90 additions and 28 deletions
+5
View File
@@ -17,6 +17,11 @@ binary, never a reimplementation of harness logic.
- **Generative Attack Path Chaining** — findings are grouped into kill-chain columns
(recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings
linked back to their parent, built live as findings stream in.
- **Real REPL underneath run/whitebox/greybox** — the wizard scripts an actual interactive
`neurosploit` session instead of a one-shot CLI call, so it keeps reading stdin while the
engagement streams. The Activity log tab grows a `❭` prompt box to send `/status`, `/stop`,
`/continue`, or a plain-language instruction mid-run. `host`/`aitest`/`skills` stay one-shot
(their onboarding scope picker can't be scripted over piped stdin).
```bash
cd neurosploit-rs && cargo build --release # build the CLI once