mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-08-26 03:12:30 +02:00
impact and business_impact often carry identical text (both ending with the reporter's 'Identified and validated by NeuroSploit...' footer), and the modal concatenated them verbatim — the boilerplate line rendered twice, and whenever the two fields matched, so did the whole paragraph. - Strip the attribution sentence out of impact/business_impact/remediation/ evidence wherever it appears; surface it once, at the bottom of the modal, instead of embedded per field. - Skip business_impact entirely when it's identical to impact (the common case) instead of printing the same paragraph twice. - Split rendering into codeBlock() (endpoint/payload — monospace, looks like what it is: a request/curl) and proseBlock() (description/impact/ remediation — a readable paragraph, not a code box). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0129WdYHccPsH27k5GGuwijd
NeuroSploit v4.0.0 — web console
A browser UI for the neurosploit CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
graph, run history, an Auth & Keys menu, and a real REPL — all driven by spawning the actual CLI
binary, never a reimplementation of harness logic.
- Asset — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
- Scope & Auth — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
- Leads — the categorized agent picker (435 agents auto-classified) + custom leads.
- Model & Run — pick a provider/model from the live catalog, API-key vs. subscription auth mode, votes/chain-depth/recon intensity.
- Review — confirm the plan, then
Start Exploitationspawns the real CLI. - Auth & Keys (one menu, 🔑 in the sidebar) — target auth header + named roles for
IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and
an explicit
creds.yamlpath override. - Generative Attack Path Chaining — findings are grouped into kill-chain columns (recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings linked back to their parent, built live as findings stream in.
cd neurosploit-rs && cargo build --release # build the CLI once
node web/server.js # → http://localhost:4173
Zero npm dependencies (Node ≥18, built-ins only: http, child_process, events, fs).
API reference: API.md.
Layout
web/
├── server.js backend: static server + agents_md/runs reader + CLI process manager
├── public/
│ ├── index.html SPA shell
│ ├── style.css lead-board / live-run / REPL drawer styling
│ └── app.js client logic (fetch + EventSource, no framework)
├── API.md
└── package.json