mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 20:41:51 +02:00
New `mobile` engagement mode: `neurosploit mobile <app.apk|app.ipa|binary>` reverse-engineers a local artifact with a dedicated `mobile` agent set, all headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker, Frida, apktool/jadx, radare2). Twelve original, generic skills (agents_md/mobile/, English): static binary triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping, root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug detection + bypass, obfuscation analysis & deobfuscation, code-integrity / tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and mobile network traffic analysis. Findings are proven from the artifact (decompilation or Frida trace), non-destructively. - agents.rs: new `mobile` Library category (loaded, counted). - pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and headless tooling doctrine; exported from the crate. - CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI. - README + TUTORIAL document the new test type; engagement-modes badge + table updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace. 383 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
55 lines
3.2 KiB
Markdown
55 lines
3.2 KiB
Markdown
# NeuroSploit v4.2.0 — web console
|
|
|
|
A browser UI for the `neurosploit` CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
|
|
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
|
|
graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual
|
|
CLI binary, never a reimplementation of harness logic.
|
|
|
|
- **Asset** — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
|
|
- **Scope & Auth** — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
|
|
- **Leads** — the categorized agent picker (435 agents auto-classified) + custom leads.
|
|
- **Model & Run** — pick a provider/model from the live catalog, API-key vs. subscription auth
|
|
mode, votes/chain-depth/recon intensity.
|
|
- **Review** — confirm the plan, then `Start Exploitation` spawns the real CLI.
|
|
- **Auth & Keys** (one menu, 🔑 in the sidebar) — target auth header + named roles for
|
|
IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and
|
|
an explicit `creds.yaml` path override.
|
|
- **Generative Attack Path Chaining** — findings are grouped into kill-chain columns
|
|
(recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings
|
|
linked back to their parent, built live as findings stream in.
|
|
- **Terminal dock (xterm.js)** — `❭_` in the sidebar, the topbar button, or `Ctrl+\`` opens a
|
|
docked terminal running a real `neurosploit` REPL session. Its stdout is streamed **unstripped**,
|
|
so the harness's own colour and box-drawn panels render as they do in a local shell. Line
|
|
editing (echo, ←/→, history, `Tab` slash-command completion, `Ctrl+C`/`L`/`U`/`A`/`E`) is local
|
|
because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target
|
|
picker in its header switches between a standalone session and the **running engagement**, so
|
|
mid-run instructions go to the same process that is doing the testing.
|
|
- **Real REPL underneath run/whitebox/greybox** — the wizard scripts an actual interactive
|
|
`neurosploit` session instead of a one-shot CLI call, so it keeps reading stdin while the
|
|
engagement streams. The Activity log tab grows a `❭` prompt box to send `/status`, `/stop`,
|
|
`/continue`, or a plain-language instruction mid-run. `host`/`aitest`/`skills` stay one-shot
|
|
(their onboarding scope picker can't be scripted over piped stdin).
|
|
|
|
```bash
|
|
cd neurosploit-rs && cargo build --release # build the CLI once
|
|
node web/server.js # → http://localhost:4173
|
|
```
|
|
|
|
Zero npm dependencies (Node ≥18, built-ins only: `http`, `child_process`, `events`, `fs`).
|
|
|
|
API reference: [`API.md`](./API.md).
|
|
|
|
## Layout
|
|
|
|
```
|
|
web/
|
|
├── server.js backend: static server + agents_md/runs reader + CLI process manager
|
|
├── public/
|
|
│ ├── index.html SPA shell
|
|
│ ├── style.css lead-board / live-run / terminal-dock styling
|
|
│ ├── app.js client logic (fetch + EventSource + terminal, no framework)
|
|
│ └── vendor/ xterm.js + fit addon (vendored; nothing is fetched at runtime)
|
|
├── API.md
|
|
└── package.json
|
|
```
|