mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
transport.rs — internal engagements happen through a VPN, a bastion or a tunnel, and the dangerous failure is silent: with the VPN down, 10.20.0.15 is a machine on the operator's own network and the scan succeeds against the wrong host. So an internal target with no transport is refused before any traffic leaves, and a transport that is up must prove it (the apparent source address has to change) rather than be assumed. Supports SOCKS, HTTP proxy, OpenVPN, SSH bastion (dynamic or single-host forward) and cloudflared. oob.rs — our own Collaborator, self-hosted by default because callbacks are engagement data (internal hostnames, resolver addresses, sometimes the exfiltrated value). HTTP and DNS listeners written on tokio directly, no new dependency. The two levels of proof are separated in code: an HTTP callback proves egress, a DNS query proves only that a resolver saw the name — the overclaim this channel otherwise invites. inbox.rs — mail.tm and inbound SMS (Twilio or webhook). extract_code() scores candidates by surrounding text and returns nothing rather than a guess, so a copyright year never gets submitted as an OTP. A throttling claim requires delivered messages carrying DISTINCT codes, not HTTP 200s. Wired through RunConfig, the CLI (global flags, so a session cannot re-route itself mid-engagement), the REPL and the web console's Authorization tab. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
NeuroSploit v4.0.0 — web console
A browser UI for the neurosploit CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual
CLI binary, never a reimplementation of harness logic.
- Asset — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
- Scope & Auth — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
- Leads — the categorized agent picker (435 agents auto-classified) + custom leads.
- Model & Run — pick a provider/model from the live catalog, API-key vs. subscription auth mode, votes/chain-depth/recon intensity.
- Review — confirm the plan, then
Start Exploitationspawns the real CLI. - Auth & Keys (one menu, 🔑 in the sidebar) — target auth header + named roles for
IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and
an explicit
creds.yamlpath override. - Generative Attack Path Chaining — findings are grouped into kill-chain columns (recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings linked back to their parent, built live as findings stream in.
- Terminal dock (xterm.js) —
❭_in the sidebar, the topbar button, orCtrl+\`` opens a docked terminal running a realneurosploitREPL session. Its stdout is streamed **unstripped**, so the harness's own colour and box-drawn panels render as they do in a local shell. Line editing (echo, ←/→, history,Tabslash-command completion,Ctrl+C/L/U/A/E`) is local because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target picker in its header switches between a standalone session and the running engagement, so mid-run instructions go to the same process that is doing the testing. - Real REPL underneath run/whitebox/greybox — the wizard scripts an actual interactive
neurosploitsession instead of a one-shot CLI call, so it keeps reading stdin while the engagement streams. The Activity log tab grows a❭prompt box to send/status,/stop,/continue, or a plain-language instruction mid-run.host/aitest/skillsstay one-shot (their onboarding scope picker can't be scripted over piped stdin).
cd neurosploit-rs && cargo build --release # build the CLI once
node web/server.js # → http://localhost:4173
Zero npm dependencies (Node ≥18, built-ins only: http, child_process, events, fs).
API reference: API.md.
Layout
web/
├── server.js backend: static server + agents_md/runs reader + CLI process manager
├── public/
│ ├── index.html SPA shell
│ ├── style.css lead-board / live-run / terminal-dock styling
│ ├── app.js client logic (fetch + EventSource + terminal, no framework)
│ └── vendor/ xterm.js + fit addon (vendored; nothing is fetched at runtime)
├── API.md
└── package.json