mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-04 23:16:50 +02:00
Spin Kali up for the engagement, run tool-recon in it, let the LLM refine on top, tear it down after. - kali_provision_recon_tools(): installs the recon toolbox (subfinder/httpx/ katana/gau/waybackurls/nuclei/naabu/dnsx/assetfinder/gf/qsreplace/anew via go install + apt) in the Kali sandbox on demand, idempotent, once per run. - kali_tool_recon(): deterministic tool-recon phase — gau/waybackurls/katana URL harvest + targeted nuclei (exposures/misconfig/takeovers, high-signal only) + gf-flagged candidate URLs by class — over the live hosts, then folded into the recon context so the LLM works on top of the tool output and confirms each. Runs in the sandbox (--sandbox) or on host tools via recon_tool(). - Engine autostart: if the container engine is installed but not running, start it automatically (colima start / open -a Docker / systemctl start docker / podman machine start) and poll until up — a --sandbox run no longer fails just because the daemon wasn't started. Clear guidance if it can't be started. - Teardown: the Kali container is removed at the end of the run (override with NEUROSPLOIT_KEEP_SANDBOX=1). Version 4.2.4 across CLI/clap/web/README/TUTORIAL. 423 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
NeuroSploit v4.2.0 — web console
A browser UI for the neurosploit CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual
CLI binary, never a reimplementation of harness logic.
- Asset — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
- Scope & Auth — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
- Leads — the categorized agent picker (435 agents auto-classified) + custom leads.
- Model & Run — pick a provider/model from the live catalog, API-key vs. subscription auth mode, votes/chain-depth/recon intensity.
- Review — confirm the plan, then
Start Exploitationspawns the real CLI. - Auth & Keys (one menu, 🔑 in the sidebar) — target auth header + named roles for
IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and
an explicit
creds.yamlpath override. - Generative Attack Path Chaining — findings are grouped into kill-chain columns (recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings linked back to their parent, built live as findings stream in.
- Terminal dock (xterm.js) —
❭_in the sidebar, the topbar button, orCtrl+\`` opens a docked terminal running a realneurosploitREPL session. Its stdout is streamed **unstripped**, so the harness's own colour and box-drawn panels render as they do in a local shell. Line editing (echo, ←/→, history,Tabslash-command completion,Ctrl+C/L/U/A/E`) is local because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target picker in its header switches between a standalone session and the running engagement, so mid-run instructions go to the same process that is doing the testing. - Real REPL underneath run/whitebox/greybox — the wizard scripts an actual interactive
neurosploitsession instead of a one-shot CLI call, so it keeps reading stdin while the engagement streams. The Activity log tab grows a❭prompt box to send/status,/stop,/continue, or a plain-language instruction mid-run.host/aitest/skillsstay one-shot (their onboarding scope picker can't be scripted over piped stdin).
cd neurosploit-rs && cargo build --release # build the CLI once
node web/server.js # → http://localhost:4173
Zero npm dependencies (Node ≥18, built-ins only: http, child_process, events, fs).
API reference: API.md.
Layout
web/
├── server.js backend: static server + agents_md/runs reader + CLI process manager
├── public/
│ ├── index.html SPA shell
│ ├── style.css lead-board / live-run / terminal-dock styling
│ ├── app.js client logic (fetch + EventSource + terminal, no framework)
│ └── vendor/ xterm.js + fit addon (vendored; nothing is fetched at runtime)
├── API.md
└── package.json